Privacy policy for WordPress websites

Even a small WordPress blog collects personal data through comments, contact forms, analytics and embedded content. Here is what your policy should disclose and how to link it from your site.

Last reviewed September 2026. General information, not legal advice.

Start with the built-in privacy page

WordPress has a privacy settings screen under Settings > Privacy. It can create a draft Privacy Policy page and includes a guide with suggested text from WordPress and from plugins that support it. That draft is a helpful starting point, but it only covers what WordPress and your plugins know about. You still need to describe your own tools, such as analytics, newsletters and ads, and your contact details.

Once your policy is ready, select it on the same settings screen so WordPress can link it from places like the login page, and add it to your footer menu.

Comments and Gravatar

If comments are enabled, WordPress stores the name, email address and website that commenters enter, along with their IP address and browser user agent, which help with spam detection. An anonymized version of the email address, a hash, may be sent to the Gravatar service to show the commenter's profile picture. If you use a spam filter such as Akismet, comment data is also sent to that service. Your policy should mention all of this, or say that comments are turned off.

Cookies set by WordPress

WordPress sets a few cookies of its own. When someone leaves a comment, it can save their name, email and website in cookies so they don't have to type them again; these last for a year. Logged-in users get login cookies, which last for two days, or two weeks if they choose "Remember Me". Plugins, analytics and embedded content often add more, so check what your site actually sets with your browser's developer tools.

Plugins, contact forms and analytics

  • Contact forms: say what the form collects, where submissions are stored (in the database, by email, or both) and for how long
  • Analytics: name the tool, for example Google Analytics through Site Kit, Jetpack Stats or a privacy-focused alternative, and explain what it measures
  • Newsletters: name the email provider and explain how to unsubscribe
  • Ecommerce: WooCommerce stores order, address and payment details; describe them and your payment gateways
  • Security and caching: security plugins and CDNs such as Cloudflare often log IP addresses

Embedded content

Videos, posts and maps embedded from other sites, such as YouTube, Vimeo, X or Google Maps, behave as if the visitor had opened that site directly. Those services may set cookies, use tracking and collect data about the visitor. Mention embedded content in your policy, and consider privacy-enhanced embed modes where they exist.

Checklist for your WordPress site

  1. Comments, Gravatar and spam filtering are covered, or you say comments are off.
  2. Every plugin that collects data is described.
  3. Analytics, newsletter and ad tools are named.
  4. Cookies and embedded content are explained, with a consent banner for EU and UK visitors if you use non-essential cookies.
  5. The page is selected under Settings > Privacy and linked in your footer.

Frequently asked questions

Does a personal blog need a privacy policy?

If it collects any personal data, such as comments, contact form messages or analytics, it's a good idea, and it's legally required in many places, including for visitors from the EU.

Is the WordPress default privacy page enough?

Usually not on its own. It's a draft with suggestions. You need to edit it to match your plugins, tools and contact details.

Can I host the policy outside WordPress?

Yes. You can write and host it on Legiflare and link to it from your footer menu, or copy the text into a WordPress page if you prefer to keep everything on your site.

Write your website privacy policy

Start from the template, add your plugins and tools, and publish it. Free.