WPML
wpml.orgWPML is a WordPress multilingual plugin that collects minimal personal data and provides reasonable privacy protections. While they claim GDPR compliance and offer data rights, the policy lacks clarity on AI-specific concerns, model training, and detailed security practices. The service appears designed for website translation rather than AI functionality, making many AI-related categories not applicable.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The policy establishes a data processor/controller relationship where users retain ownership as data controllers, but lacks explicit statements about ownership of user inputs. The policy focuses on personal data rather than content or prompts submitted to the service.
Output Data Ownership
The policy does not address ownership of outputs or generated content. Since WPML is a translation plugin rather than an AI content generator, this category may not be applicable to their service model.
Training Data Usage
The policy explicitly states they do not use personal information for purposes beyond service provision without consent. There's no mention of using user data for model training, and they commit to not selling or sharing personal information.
Data Retention & Deletion
Data is retained for the duration of the account relationship, with deletion available upon request. However, specific retention schedules, deletion SLAs, and backup archive handling are vague, creating uncertainty about complete data removal timelines.
Third-Party Data Sharing
WPML has strong restrictions on third-party data sharing, explicitly stating they don't sell data and only share with service providers under written contracts. The only named third parties are payment processors (PayPal and Stripe) and Google Analytics.
Opt-Out Rights
Users have multiple opt-out mechanisms including marketing communications, cookies, location data, and Google Analytics tracking. The policy provides specific instructions and links for exercising these rights.
Compliance & Certifications
WPML claims GDPR compliance and mentions UK GDPR, but provides no evidence of third-party certifications, audits, or other compliance frameworks like SOC 2 or ISO 27001. They offer a Data Processing Agreement upon request.
Model Explainability & Auditability
The policy does not address model behavior, AI decision-making, or audit capabilities. As WPML appears to be a translation plugin rather than an AI service, this category may not be applicable.
Security Practices & Breach History
Generic security commitments are made but no specific controls, encryption standards, or security certifications are detailed. No breach history is disclosed, but the policy includes standard disclaimers about inability to guarantee 100% security.
Enterprise vs. Consumer Risk Delta
The policy applies uniformly to all users with no mentioned differences between free and paid tiers. Enterprise users can request a Data Processing Agreement for additional protections.
Human Review of User Inputs
The policy does not explicitly address whether staff can access user content or prompts. While they process data as a data processor under user control, the scope of potential human access is unclear.
Regulatory & Litigation Exposure
Standard legal compliance language is included for subpoenas and court orders, but no specific litigation, government requests, or law enforcement cooperation issues are disclosed.
PII & SPI Data Inventory
WPML collects minimal PII (names, emails, usernames, passwords, billing addresses, IP addresses) and explicitly states they do not process sensitive personal information. Payment data is handled by third-party processors.
You've read all 15 risk ratings for WPML. Create a free account to see the exact policy wording behind each rating.