AI assistants: security and data handling
Who this is for
Agencies manage sites on behalf of their own clients, so connecting an AI assistant to Glow is a decision made on someone else's behalf. This page sets out precisely what a connection can see and do, so that decision can be made on facts rather than assurances. It is deliberately specific where our privacy policy is necessarily general.
A connection is opt-in, per person
No assistant has access to any Glow account unless somebody connects one. Connecting is done from inside the assistant, and it sends you to Glow to sign in and approve a named list of permissions. Nothing is granted implicitly, and nothing is granted account-wide by default: a connection belongs to the individual who authorised it.
What a connection can see
A connection sees exactly what the person who authorised it sees, and no more. Glow already restricts users to specific websites; a team member limited to three sites gets an assistant limited to the same three. If you cannot open a site in the Glow dashboard, an assistant connected with your account cannot read it either.
Within that boundary, the data that can be read is:
- Website names, domains and connection status
- Plugin, theme and WordPress core inventories, with version numbers
- Outstanding updates
- Published vulnerabilities affecting those versions
- Uptime and SSL certificate history
- Backup history
- Page speed and Core Web Vitals results
- Report schedules and delivery history
- Support ticket time and stopwatch entries, and the client each belongs to
What is never sent
- Passwords, for Glow or for any connected website
- Connection keys, API keys or anything else that would let an assistant reach one of your sites directly
- The contents of your clients' websites
- Ticket message bodies
Data is sent to the assistant only in response to a question you ask, at the moment you ask it. There is no bulk export, no background synchronisation and no standing copy of your account held by the assistant.
What a connection can change
Reading is the default. A new connection can read the data above and change nothing.
Running updates is a separate permission, presented by name on the approval screen, and you can decline it and still use everything else. When it is granted:
- Updates run through Safe Updates: a backup and a screenshot are taken first, the site is checked afterwards, and the update can be rolled back
- Plugins must be named explicitly. There is no "update everything" instruction
- Updates are capped per request, so a single instruction cannot reach an entire fleet
Deleting or deactivating anything is not possible at any permission level. That capability is not exposed to assistants at all, so no combination of permissions or instructions can reach it.
Who can authorise a connection
Only a signed-in user of an agency, acting as themselves. Glow staff cannot create a connection on your behalf: an administrator signed in as your account through support impersonation is refused, because a connection made that way would grant access to data you had never seen a request for.
Tokens and revocation
- Access tokens last one hour
- Refresh tokens last thirty days, and are replaced as they are used
- Revoking a connection invalidates both immediately
Every connection is listed under Settings, Integrations, AI assistants, showing which assistant it is, who connected it, which permissions it holds, and when it was last used. Disconnecting takes effect at once. Account owners can also see and end connections made by anyone else on their team, so a colleague's forgotten connection is never invisible.
Logging
Every request an assistant makes is recorded against the connection that made it, including which capability was used and when. That record is what makes the "last used" date on the connections screen meaningful, and it means a connection's activity can be reviewed rather than assumed.
Sub-processors
Connecting an assistant means the provider of that assistant processes the data you ask about. Anthropic (for Claude) and OpenAI (for ChatGPT) act as optional sub-processors, engaged only if and when you connect one of them. If you never connect an assistant, neither receives anything.
For our full sub-processor list, or a data processing agreement, contact us.
Beta
This feature is in beta. The security properties described on this page are not provisional: the permission model, the restriction to Safe Updates and the absence of any delete capability are structural. What may still change during beta is which capabilities exist and how they are grouped. Material changes will be reflected here.