Privacy Policy
Last updated July 26, 2026
BlockStorm is a WordPress firewall plugin and a companion cloud service. This policy explains what we collect and why. In short: we collect the minimum needed to run the service, and the community blocklist never carries data that identifies your site or your visitors.
Account data
When you register for a license we store your first and last name, email address, and phone number (with country code). We use these to operate your account, send license and billing notices, and provide support. Passwords are stored only as a salted bcrypt hash — we can never see them.
Site connection data
When you activate the plugin on a site, we store a site fingerprint, the site URL, and the plugin and WordPress versions, so we can manage your activations and support you. Heartbeats record only a last-seen timestamp.
Attack signals (opt-in)
If — and only if — you enable "Contribute anonymized attack data" in the plugin, your site reports attack signals to the community blocklist. Each signal contains exactly three fields:
- the attacker's IP address
- the scenario name (e.g. login_bruteforce)
- a timestamp
Signals never include your visitors' data, your content, request bodies, user agents, or anything identifying your site. The published community blocklist is a derived aggregate with no link back to any reporting site.
Payment data
Payments are processed by Waychit. We never receive or store your card or mobile-money details — only a payment reference and status so we can activate your plan.
Retention & your rights
Raw attack signals are pruned on a rolling retention schedule. You can delete your account and its data, or ask what we hold, by emailing support@wpblockstorm.com. Deactivating a site removes its activation record.