Security & trust

Is Which AI Sent safe to install?

Short answer: yes, and you don’t have to take our word for it. Here is what we do, what we don’t do, and which parts have been checked by others. Last updated September 29, 2026.

Checked by others

  • Google-verified access. Our Google Tag Manager connection passed Google’s OAuth app verification. It asks for one permission (to add a tag to a container), never publishes, and gives the access back to Google straight after adding the tag.
  • WordPress.org-reviewed plugin. Our WordPress plugin is listed in the official WordPress.org plugin directory after WordPress’s manual code review.
  • Payments by Paddle. Paddle is our merchant of record and handles all payments. We never see or store card details.

What our script does on your website

  • It’s one small analytics script that loads asynchronously, so it doesn’t slow your pages down.
  • It records where each visit came from (for example ChatGPT or Google), the pages viewed and phone or computer, with random IDs. Everything it collects is listed, with how long we keep it.
  • When a visitor sends a contact or quote form, it records the name, email and phone they typed, so the lead can be matched to the visit.
  • It never reads passwords or hidden fields, ignores login, search, checkout and newsletter forms, and doesn’t record keystrokes or screens.
  • It stores no IP addresses and sets no advertising cookies. It respects Global Privacy Control if you turn that option on, and can wait for your cookie banner.
  • It doesn’t change your pages, with one optional exception you control: a “How did you first hear about us?” question on contact forms, off unless you switch it on.
  • On Webflow, the script is a fixed, versioned file with an integrity hash, so browsers refuse it if a single byte changes.

Access to your accounts

  • Google Tag Manager: one permission, used once to add our tag to a new workspace, then handed back. We never publish: you review the tag and click Submit.
  • WordPress: you approve on your own WordPress screen. We install and set up the plugin, then remove our access automatically.
  • Webflow: read sites and edit custom code only. The token is stored encrypted, used only to remove our script if you disconnect, and deleted when you do. We never publish your site.
  • Wix and Shopify: installed through the platform’s own approval screen, and removable there at any time.

How we protect data

  • All traffic is encrypted (HTTPS only, with HSTS).
  • Passwords are stored only as salted one-way hashes with a secret kept outside the database. Platform tokens are encrypted.
  • Each customer’s dashboard can only see that customer’s data. View-only share links can be turned off at any time.
  • We don’t sell data, use it for advertising, or combine it across customers.
  • You can stop tracking any time, and remove a website and all its data from Settings (confirmed by email).

Who is behind it

Which AI Sent is built and operated by Tamitechs, a digital agency. See About and Legal info for company details, and our Privacy policy, Terms and Data processing agreement.

Report a security issue

If you think you’ve found a vulnerability, email info@whichaisent.com with “Security” in the subject. We aim to reply within 2 business days and won’t take action against good-faith research. Our security.txt has the same details.