Acid Studios GET THE PLUGIN

Privacy & external services

What leaves your server (only IndexNow, which you can switch off), what the citation tracker stores, and why no visitor is ever identified.

Updated 2026-10-08 · applies to Acid AEO 1.0.4

Acid AEO talks to one outside service, IndexNow. Everything else stays on your server, and nothing it stores identifies a person.

No visitor tracking

The plugin sets no cookie, loads no third-party script, font or image, and never contacts Acid Studios. It adds no front-end JavaScript unless you switch on the citation beacon, which is off by default.

Two modules are on by default:

  • IndexNow sends your own URLs to a search-engine API when content changes. Module switch: indexnow.enabled.
  • AI citations counts AI crawler visits and visitors arriving from an AI assistant, on the server. Module switch: citations.enabled.

The readiness audit fetches your own pages and files with wp_remote_get(): loopback requests to your own domain.

IndexNow

When a post of a selected type is published, updated, unpublished or trashed, its URL is queued, and a cron job sends the queue about a minute later. The request is an HTTPS POST to https://api.indexnow.org/indexnow with four fields:

  • host, your site's host name;
  • key, the IndexNow key the plugin generated for your site;
  • keyLocation, the URL of the public key file, /{key}.txt;
  • urlList, the URLs being submitted.

A request is also sent when you press Submit, run wp acid-aeo indexnow submit, or finish the wizard with Submit every URL ticked. Automatic submission stops while Discourage search engines is set in WordPress. No visitor data and no content is sent. The plugin keeps a log of the last 50 submissions: time, URL count, HTTP status and error message.

Turn indexnow.auto_submit off and nothing is sent when you publish; an explicit wp acid-aeo indexnow submit or POST /indexnow/submit still sends, because you asked for it. Switch the whole module off and nothing is sent at all: since 1.0.4 the command exits with an error and the route answers 409 instead of sending. The acid_aeo_indexnow_endpoint filter changes the address. IndexNow terms: https://www.indexnow.org/terms. It is operated by Microsoft; privacy statement: https://privacy.microsoft.com/privacystatement.

AI citation tracking

Counting happens in PHP, on page views that reach WordPress; editors, the admin, feeds, REST, cron, previews and 404s are skipped. Two events are recorded:

  • Crawl: the user agent matches a known AI crawler. Stored as the crawler's name, at most once a minute per crawler and URL.
  • Referral: the Referer or the utm_source parameter matches one of 15 known AI assistants (ChatGPT, Perplexity, Claude, Gemini and others) or a host you added in citations.engines_extra. Stored as the assistant's name, at most once a minute per visitor and URL.

Each event is one row: the type, the crawler or assistant name, the page URL, the post ID, the time, and a 16-character hash. The hash is the start of a SHA-256 of the visitor's IP address, salted with your site's own nonce salt and the current UTC date. It cannot be reversed and changes daily, so it cannot follow anyone across days. It exists only for rate limiting. The IP address, the full user agent and the referring URL are never stored.

The beacon (citations.beacon, off by default) counts referrals behind a page cache, where PHP never runs. It is a small first-party script, not loaded for editors, that reports only when the referrer or utm_source already matches a known assistant, once per URL per browser session (kept in sessionStorage, not a cookie). It sends the page URL, the referrer and utm_source to your own /wp-json/acid-aeo/v1/beacon. The server accepts only your own URLs and known assistants, and answers 429 after 30 calls a minute from one hash.

Events are deleted after citations.retention_days (default 90, from 7 to 730) by a daily task. To delete them yourself, run wp acid-aeo citations purge, or wp acid-aeo citations purge --older-than=30 to keep the last 30 days. The plugin also adds a paragraph describing all this to the WordPress privacy policy guide, under Settings → Privacy.

Fonts and assets

The admin screens use Inter and Space Mono (SIL Open Font License 1.1). The files ship in assets/fonts/, are served from your own site and load only on Acid AEO's admin screens. Nothing comes from Google Fonts or another CDN.

The per-crawler table in the AI policy settings links each vendor to its own crawler documentation, for example https://platform.openai.com/docs/bots. There are 23 such links in the source. They are for you to open in your browser; the plugin never requests, parses or caches them. The same goes for the schema URL written into ai-context.json.

What is stored in your database

  • Options: acid_aeo_settings (all settings), plus acid_aeo_cache_ver, acid_aeo_db_version, acid_aeo_flush_needed, acid_aeo_indexnow_queue, acid_aeo_indexnow_log, acid_aeo_static_files_active, acid_aeo_loop_ver and acid_aeo_sitemap_url.
  • One table, {prefix}acid_aeo_events, holding the citation events described above.
  • Transients starting with acid_aeo_: cached files, audit results and the short rate-limit counters.
  • Post meta added from the editor: _acid_aeo_summary, _acid_aeo_faq, _acid_aeo_exclude, _acid_aeo_noai, _acid_aeo_schema_type, _acid_aeo_license, _acid_aeo_credit, _acid_aeo_creator and _acid_aeo_hide_updated, the flag that hides the "Updated on" line on one post.
  • User meta added on profiles: acid_aeo_job_title, acid_aeo_same_as, acid_aeo_knows_about, acid_aeo_alumni_of and acid_aeo_notice_dismissed.

What uninstall removes

Deleting the plugin removes all of the above, its scheduled tasks, and any file in the web root that carries the plugin's own marker. Files it did not write are left alone. Tick Keep my data when the plugin is deleted under Acid AEO → Settings → Advanced first if you want to keep everything. Details: Uninstalling.

GDPR note

No cookies are set and the IP address is never stored. The only per-visitor value is a truncated hash salted with the site salt and the UTC date, kept for rate limiting; it rotates daily and the rows are deleted after the retention period you choose. User agents are reduced to a bot name. Whether that meets your legal basis is your call as the site owner. The paragraph the plugin adds to the privacy policy guide describes exactly this, ready to copy into your own policy.

Found a mistake or something missing? Write to [email protected].

GET THE PLUGIN