Privacy Policy

Version 7, last updated 4 September 2026

WP-AllBackup (Okleone Backups) is made by Fixit d.o.o. (“we”, “us”). This policy explains what data our website, licence portal and OAuth relay handle and, just as importantly, what they don’t.

The short version

By default your backups never touch our servers: they go from your WordPress site directly to storage you own (your Dropbox, Google Drive, S3 bucket, server). The one exception is WP-AllBackup Storage, which is optional and off until you switch it on. If you use it, your backup archives are held by us, in Germany, and the section below says exactly what that means. Apart from that we store only what’s needed to run your licence.

What we collect

Licence portal (portal.fixit.biz). When you buy a premium licence we store your email address, your licence key, your subscription and order history, and, for each activated site, its URL, an anonymous install identifier, the plugin version it runs and when it last checked in. This is the minimum needed to operate licensing, your account dashboard, and support. If you switch on "Keep recovery details in my portal account" in the plugin, the portal also holds that site's Rescue Protection console address and key, encrypted at rest, shown to you only after you re-enter your password, and removed when you switch the setting off or revoke the key from your dashboard.

Signing in to the portal. The login and forgot-password forms carry a human check, Cloudflare Turnstile. When either page loads, Cloudflare receives your IP address and technical characteristics of your browser in order to tell a person from a script, under Cloudflare’s privacy policy; what reaches us is a pass or a fail, which we may log with the IP address for abuse prevention. If you choose Sign in with Google, Google confirms who you are and sends us your Google account id, name and email address, which we match to the portal account that already exists for that address; Google learns that you signed in to our portal, under Google’s privacy policy. Google sign-in never creates an account, and you can disconnect it from your Account page at any time.

Payments. Checkout is operated by Paddle.com Market Ltd as merchant of record. Paddle collects and processes your payment details under Paddle’s privacy policy; we never see your card number.

OAuth relay (relay.fixit.biz). When you connect Dropbox, OneDrive or Google Drive, the relay brokers the authorization handshake with the provider. The resulting access token is held only briefly (minutes) until your own site collects it, then removed. Tokens live in your WordPress database, not with us. The relay keeps short-lived rate-limiting counters and minimal operational logs.

Site registration. To operate and protect that shared relay, and to enforce which storage providers your plan includes, connecting cloud storage registers your site’s URL and an anonymous install identifier with our licence service. No account is required for this, and it lets us rate-limit abuse and revoke misuse per site. It does not identify you personally beyond the site address you already connect from.

WP-AllBackup Storage (optional). If you switch this on, your backup archives are uploaded from your site to storage we operate. They are held in Germany, on infrastructure rented from Hetzner Online GmbH, who act as our processor and have no separate use for the data. Each licence gets its own isolated account and directory; no customer can reach another customer’s. The credentials your site uses are issued by us, short-lived, and scoped to that directory alone.

Your archives are your site’s files and database, so their contents are whatever your site contains, including any personal data of your own users. We do not open, read, index or scan them. What we do look at is how much space each licence is using, measured as a directory size, because that is what the allowance is enforced against and what a paid package is billed on. If you would rather we could not read an archive even in principle, switch on Encryption in the plugin (Settings → Encryption): every backup is then encrypted on your server before it reaches us, and what we hold is ciphertext under a key that only you have.

How long we keep it. While your licence is active, until you delete it. If your licence lapses or you disconnect the storage, the archives are kept for 60 days and then deleted, with warning emails during that period and one when the deletion has happened. You can ask us to delete them sooner at any time. One detail on top of that: the storage server takes a daily snapshot of itself and keeps the last seven, so that a stolen credential or a mistaken delete cannot destroy your archives; a deleted archive can therefore linger in a snapshot for up to seven days after any deletion above, readable only by us and only from the server itself, before it is gone entirely.

Failure diagnostics (optional). If a backup, a restore or a staging build fails, the plugin can send us a diagnostic report so support can see what went wrong and we can fix the underlying bug. This never happens on its own: a report is sent only when you click “Send diagnostic report” on a specific failure, or if you switch on automatic sharing in the plugin settings (it ships switched off). A report contains technical data about that failure only: the plugin’s own log entries for the failed job or build, the error classification, plugin/WordPress/PHP versions, the names and versions of your active plugins, and server limits such as memory and free disk space. Reports never contain your files, your database contents, credentials or backup archives, and absolute server paths are removed before anything is sent. Reports are deleted automatically after 90 days; email us to have them removed sooner.

This website. No analytics, no tracking scripts, no cookies, no external requests. Standard web-server access logs (IP address, request path) are kept briefly for security and abuse prevention.

What we never collect

Your cloud-storage credentials. Your card details. Your site’s files and database contents, unless you choose WP-AllBackup Storage, in which case we hold the archives containing them, as described above, and still never look inside them.

Emails

We send transactional email only: account invitations, password resets, refund notices, WP-AllBackup Storage warnings when space or a licence is running out, renewal reminders if you have asked for them, and (if you enable them in the plugin) backup reports sent by your own site to your own address. No marketing lists.

Data retention & your rights

Licence and order records are kept while your account exists and as long as tax and accounting rules require. You can ask us to export or delete your account data at any time by emailing wp-allbackup-support@fixit.biz. Deleting your account deactivates any remaining licences.

Sharing

We share data only with Paddle (payments, as described above); the infrastructure providers that host the portal, the relay and WP-AllBackup Storage: currently Microsoft Azure (Ireland) for the portal and relay, Hetzner Online GmbH in Germany for WP-AllBackup Storage, and SMTP2GO for transactional email; and, for signing in to the portal, Cloudflare (the human check on the login and forgot-password forms) and Google (only if you choose Sign in with Google). The full list, with what each one sees and where it is, is the subprocessor table in our Data Processing Agreement. We don’t sell or rent personal data to anyone.

Changes

If this policy changes materially, we’ll note it here with a new version and date. Questions: wp-allbackup-support@fixit.biz.