Privacy Policy
Last updated: 20 June 2026
This Privacy Policy explains how Code Snippets B.V. (“we”, “us”, “our”) collects, uses, shares and protects personal data in connection with the website yolo-plugin.com and the YOLO plugin and related services (together, the “Services”). YOLO is a Code Snippets product.
We aim to comply with data-protection laws wherever our users are, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). Where a specific right or term applies only in your region, we say so.
1. Who we are
The data controller is Code Snippets B.V., a company registered in the Netherlands.
- Registered office: [registered address — to be completed]
- Company (KvK) no.: [to be completed] · VAT no.: [to be completed]
- Privacy contact: [email protected] (or via codesnippets.pro/contact)
2. The personal data we collect, and why
Website visitors & analytics
When you visit yolo-plugin.com our servers and analytics tools may record technical data such as your IP address, browser and device type, referring page, and the pages you view. We use this to keep the site secure and to understand and improve how it is used. Legal basis (GDPR): our legitimate interest in operating and improving the site, and your consent where required for non-essential analytics cookies.
Contact & signup forms
If you contact us or sign up (e.g. for updates or an account), we collect the details you provide — typically your name and email address — to respond to you and to send information you have requested. Legal basis: your consent and/or steps taken at your request prior to a contract; legitimate interest in responding to enquiries.
Purchases & licensing
Payments and licensing for our products are handled by our payment/licensing processor (Freemius, Inc.) and other payment providers. They collect the billing and payment information needed to complete your purchase and manage your licence (such as name, email, billing address, and payment-card details processed securely by the provider). We do not receive or store full payment-card numbers. We receive order and licence records (e.g. product, amount, licence status) to provide support and meet our legal and accounting obligations. Legal basis: performance of a contract; compliance with legal obligations (tax/accounting).
Comments & media (if used)
If commenting or media uploads are enabled and you use them, we collect the comment content, your name/email, your IP address and browser user-agent (to help with spam detection), and any files you upload. An anonymised string created from your email address (a hash) may be provided to the Gravatar service to show your avatar (see Gravatar’s policy at automattic.com/privacy). If you upload images, please avoid embedded location (EXIF GPS) data, as visitors can extract it. Legal basis: consent / legitimate interest in running the site and preventing abuse.
The YOLO plugin & connected AI assistants
YOLO is a self-hosted WordPress plugin. When you connect an AI assistant (for example a Custom GPT in ChatGPT, or an MCP client) to your own WordPress site through YOLO:
- Your API token is generated in your site’s wp-admin and pasted into your AI tool; it authenticates requests to your own site and is a secret you control and can revoke at any time.
- Site content and requests travel directly between your AI tool and your own WordPress site over HTTPS.
- Your conversation is processed by the AI provider you choose (e.g. OpenAI) under that provider’s own privacy policy.
Because YOLO is self-hosted and you bring your own AI, we (Code Snippets B.V.) do not receive, collect, store or have access to your site content, your token, or your AI conversations through your use of the plugin or a connected GPT. Your use of a third-party AI provider and your WordPress host is governed by their respective terms and privacy policies.
3. Cookies
We use cookies and similar technologies to make the site work, remember your preferences, and (with your consent where required) measure traffic. Typical cookies include essential session/login cookies, preference cookies, and analytics cookies. WordPress comment and login cookies, where applicable, persist for short periods (for example, comment cookies up to one year, login cookies around 2 days, or up to 2 weeks if you select “remember me”). You can control or delete cookies in your browser settings; blocking some cookies may affect how the site works.
The cookies currently in use on this site are listed below, including their provider, purpose and how long they last. This table is generated automatically and updates as our cookie scan runs.
| Cookie | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
yolo_consent | This site | Stores your cookie consent choice | 180 days | Essential |
ytr_lang | YOLO Translate | Remembers the visitor’s chosen language | 30 days | Functional |
4. Embedded content from other websites
Pages on this site may include embedded content (e.g. videos, images, articles) from other websites. Embedded content behaves exactly as if you had visited the other website, which may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that content.
5. Who we share your data with
We share personal data only with service providers who help us run the Services, and only as needed:
- Hosting & infrastructure providers that store the website.
- Analytics providers that help us measure site usage.
- Payment & licensing providers (e.g. Freemius, Inc. and payment processors) to take payment and manage licences.
- Spam-prevention services, if comments/forms are enabled.
- AI providers — only in the sense that, when you use the YOLO plugin with an assistant, your conversation goes to the AI provider you chose; it does not pass through us.
We do not sell your personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA.
6. International data transfers
We are based in the Netherlands and our providers may process data in other countries, including outside the EEA/UK. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), or transfers to countries with an adequacy decision.
7. How long we keep your data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it:
- Enquiry/contact data: kept while we handle your request and for a reasonable period afterwards.
- Order, licence and accounting records: kept for the period required by tax and accounting law.
- Comments and their metadata (if enabled): may be kept indefinitely so follow-up comments display in context.
- Analytics data: kept for a limited retention window per our analytics configuration.
8. Your rights
Depending on where you live, you may have some or all of the following rights:
- EU/UK (GDPR): access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing; and the right to withdraw consent at any time. You also have the right to lodge a complaint with your data-protection supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
- California (CCPA/CPRA): the right to know/access, to delete, and to correct your personal information; the right to opt out of the sale or sharing of personal information (note: we do not sell or share it); and the right not to be discriminated against for exercising your rights.
If you have an account or have commented, you can request an exported file of the personal data we hold about you, and ask us to erase it, except data we must keep for administrative, legal or security reasons.
9. How to exercise your rights
Email [email protected] or use codesnippets.pro/contact. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law.
10. Children
The Services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
11. Security
We take reasonable technical and organisational measures to protect personal data. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to it.
12. Changes to this policy
We may update this policy from time to time. We will change the “last updated” date above and, where appropriate, notify you of significant changes.