In short
- Scans stay on your server: no code, file names, findings or reports are sent anywhere.
- Pro talks to our license service for license and update checks, and, only if you turn them on, to wordpress.org and your own chat webhooks.
- No analytics, no tracking, no usage data.
The scans stay on your server, as with the free plugin: no code, file names, findings or reports are sent anywhere. CompatNav Pro makes only these requests:
- License: when you activate or deactivate a license, when you click “Check again”, and once a week, the license key, your site’s address and the CompatNav Pro version go to CompatNav’s license service at api.compatnav.com.
- Updates: when WordPress checks for plugin updates (only with a license key saved), the same three items go to api.compatnav.com. When you install an update, WordPress downloads it from there itself, with WordPress’s usual user agent (which includes your site’s address and the WordPress version).
- “Does updating fix it?” (opt-in, off by default): update packages and their checksums are downloaded from downloads.wordpress.org. The request says nothing about your site; like any download, wordpress.org sees your server’s IP address.
- Chat alerts (opt-in, off until you add a webhook address): posts to the Slack, Microsoft Teams or Discord incoming webhook you set (only https addresses on those services’ official webhook hosts are accepted), when something new will break and, if turned on, as a weekly summary. A post carries the site’s name and address, the names of the plugins and themes concerned, counts, the problem in plain words and a link to the site’s report; never code, file contents or file paths. Slack, Microsoft or Discord receive the post under their own terms.
Nothing else: no analytics, no tracking, no usage data. (While a scan runs, CompatNav Pro also asks your site’s own WP-Cron to continue it: a request from your server to itself, which leaves nothing outside.) Alert emails are sent by your own site through its own email setup, to the addresses you choose; they don’t pass through CompatNav.
Runtime notices (opt-in, off by default; started by you for 1–30 days, then it stops by itself): CompatNav Pro counts the deprecations, warnings and notices PHP reports during the site’s own requests, and keeps them only in this site’s database: the kind of message with values removed, the file and line, the plugin or theme, how often and when, the PHP version and the kind of request. Never web addresses, form data, users, IP addresses or cookies. Nothing is sent anywhere. The results are deleted 30 days after the capture ends (a setting), at once with “Delete all captured results now”, and on uninstall.
Share link and scheduled client report (both off by default; no external request):
- The share link opens a read-only summary page served by your own site (verdict, counts, what to fix first, trend, the date of the last scan, your agency’s name); never file paths, versions or server details. It is valid for 1–90 days and can be revoked at once. Only a fingerprint of the link is stored; views are counted as a number and a date. To limit guessing, a keyed hash of the visitor’s IP address is kept for at most an hour. Search engines are told not to index the page.
- The scheduled client report email is sent by your own site, through its own email setup, to the addresses you set; the attached file is deleted from the server right after sending.
Requests 1–3 use CompatNav Pro’s own user agent, no cookies and no referrer. Every server you connect to sees your server’s IP address.
What the license service stores
- Per license: a keyed hash of the license key and its last 4 characters (for support), the plan, the number of sites, the status (active or refunded), the expiry date, whether it renews, and the payment provider’s reference numbers for the customer, subscription and order.
- Per activated site: the site’s address, the CompatNav Pro version, when it was activated and when it last checked in. Deactivating a site deletes this at once.
- Not stored: names, email addresses, IP addresses, scan results, plugin lists or anything else about your site. Rate limiting counts requests under a keyed hash of the IP address that can’t be turned back into the address, and deletes the counts after a day.
How long
- A license and its sites: until 12 months after the license expired or was refunded, then deleted automatically. Until then, a renewal keeps the same key.
- Payment notification IDs (to avoid handling one twice): 90 days.
- Rate-limit counts: at most a day.
Who can see it
CompatNav’s operator, through the service’s Cloudflare account. Cloudflare runs the service and processes the requests, including IP addresses, as its host.
Payments and your license email
Orders are processed by our online reseller Paddle.com, the Merchant of Record, which handles payment, tax, invoices and refunds. We never see or store your card details. Your name, email and billing address and the payment are handled and kept by the payment provider, under its own privacy policy. The license service keeps only the references, plan, status and dates listed above. To send your license key, it looks up your email address with the payment provider and sends the email through Brevo, an email service; the address is not stored by the license service.
The free plugin
The free plugin, CompatNav – PHP Upgrade Checker, makes no external requests at all. Everything on this page is about the Pro add-on.
Your data
To have your license and its site addresses deleted earlier, or to ask what is stored for your license, write to hello@compatnav.com. Deleting a license ends its updates and support; CompatNav Pro keeps working on your sites.