Contents

Privacy and uninstall - Plugixa Easy Social Share Buttons

This page lists what the plugin stores, what it sends to outside services and when, and what is removed when you deactivate or uninstall it.

The short version: showing share buttons contacts nobody. The plugin sets no cookies, loads no third-party scripts, and stores nothing that identifies a visitor.

What a visitor’s browser does

  • Share links point straight at each network’s own share address. Nothing is requested from a network until a visitor clicks a button.
  • No cookies are set by the plugin.
  • No third-party scripts are loaded. Icons are part of the page itself.
  • Counts are fetched from your own site, not from the networks.
  • A click on a share button is reported to your own site, as the network, the placement and the post. Nothing else is sent.

What is kept in the visitor’s browser

What Where When
The Mastodon or Lemmy server the visitor typed The browser’s local storage When they share to Mastodon or Lemmy for the first time
That a popup or fly-in was already shown, and when PRO The browser’s local storage, or session storage for “Once per visit” When a popup or fly-in opens

These never leave the browser. Where a browser blocks storage, the visitor is simply asked, or shown the box, again.

What is kept in an administrator’s browser

The admin screens remember three small things in the browser’s local storage of the person using them. None is sent anywhere, and none is about a visitor.

What Storage key
Which sidebar sections are folded away plugixa_social_share_nav_collapsed
Which alerts under the bell were already seen plugixa-social-share-seen-alerts
The colour theme of the admin screens, if one is ever stored plugixa-social-share-theme

Where a browser blocks storage, such as some private windows, the screens still work: the sidebar opens unfolded and every alert counts as new.

The account menu in the header draws your initial, not your profile picture, so the admin screens request nothing from an avatar service.

What is stored on your site

Database tables

Table Holds
{prefix}plugixasocialshare_counts For each post and network: the last count a service reported, when it was checked, and how many checks failed in a row
{prefix}plugixasocialshare_clicks For each post, network, placement and day: how many clicks

The click table holds a daily tally, not a row per click. It stores no IP address, no user agent and no identifier of any kind.

When a post is deleted, its rows in both tables are deleted with it.

Options

Option Holds
plugixa_social_share_settings Everything on the Settings screen, including any tokens and API keys you saved
plugixa_social_share_sets Your share sets
plugixa_social_share_follow Your follow profiles and the row’s look
plugixa_social_share_imports When each other plugin was imported, and the sets that made
plugixa_social_share_apps Which of the plugin’s features are switched on
plugixa_social_share_db_version, plugixa_social_share_module_set, plugixa_social_share_caps_backfilled Housekeeping for updates

Tokens and keys are stored with the settings and are never sent back to a browser. The settings screen is told only whether each one is set.

Custom fields on posts

Field Holds Edition
_plugixa_share_hide The post hides its automatic buttons Free
_plugixa_share_off The spots the post drops Free
_plugixa_share_set The share set the post chose Pro PRO
_plugixa_share_pin_image, _plugixa_share_pin_description, _plugixa_share_pin_nohover The post’s Pinterest choices Pro PRO
_plugixa_share_short_links, _plugixa_share_short_queue The post’s short links, and addresses waiting for one Pro PRO

Short-lived records

Record Kept for Purpose
A salted, one-way hash of a visitor’s IP address One minute Limits click reports to 60 a minute per caller
A marker per post One hour Stops a post being registered for counting on every page view
A salted, one-way hash of a visitor’s IP address PRO Ten minutes Limits the email form to five sends per caller
A marker per post PRO One hour Stops short link requests being queued on every page view

The hashes cannot be turned back into an address and are useless on any other site.

Capabilities

On activation the Administrator role is given the plugin’s capabilities: plugixa_social_share_view, plugixa_social_share_edit, plugixa_social_share_manage_settings, plugixa_social_share_export and plugixa_social_share_manage.

What is sent to outside services

Share counts, when switched on

Only while Show share counts or Show the combined total is on in at least one share set, your site’s server asks these services how often a published address was shared.

Service Address contacted Condition
Reddit https://www.reddit.com/api/info.json Counts are on
Tumblr https://api.tumblr.com/v2/share/stats Counts are on
VK https://vk.com/share.php Counts are on
Odnoklassniki https://connect.ok.ru/dk Counts are on
Facebook https://graph.facebook.com/ Counts are on and you entered a Facebook app token
  • Each request sends the public address of the post, and a User-Agent naming this plugin, its version and your site’s address.
  • With count recovery on, the post’s old address is asked about too.
  • The Facebook app token is sent only to Facebook.
  • Requests are made by a scheduled background job, never by a visitor’s browser.
  • No visitor data and no personal data are sent.

Switch both options off in every share set and all five stop. The scheduled job is removed.

Google Analytics 4, when switched on

With Report share clicks to Google Analytics 4 on, each share click is handed to the Google tag or Tag Manager already on your site, as a share event with the network, the post’s ID or the page’s path, and the placement. Your own tag sends it to Google under your own consent settings. The plugin loads no Google script and sends Google nothing itself.

Freemius, if you opt in

The plugin includes the Freemius SDK, which handles the opt-in and, for Pro, licences and updates. After activation it asks once whether you want to share diagnostic data. You can skip it, and nothing is sent unless you agree.

If you opt in, it sends your site’s address, its WordPress and PHP versions, the plugin’s version and language, and your name and email address, and, only with your permission, the list of active plugins and themes. Nothing about your visitors is sent.

With a short link service chosen, each address your buttons share is sent once, from your server, to that service: api-ssl.bitly.com, api.rebrandly.com, or your own YOURLS address. Your token or key for that service is sent with it. Nothing about a visitor is sent.

Email capture PRO

When a reader submits the “Save this post” form:

  • Their email address is used to email them the post, through your site’s own mail.
  • Only if they ticked the box, their address is sent from your server to the service you chose: Mailchimp, Brevo, MailerLite or Kit.
  • Their address is not stored on your site.

The plugin adds suggested wording for this to WordPress’s privacy policy guide.

The Open Graph and X card tags describe the page to whoever fetches it. They send nothing anywhere.

Deactivating

Deactivating stops the background work and destroys nothing:

  • the scheduled count refresh is removed
  • the scheduled short link job is removed PRO
  • every setting, share set, count and click is kept

Reactivating picks up where it left off.

Uninstalling

Deleting the plugin from the Plugins screen removes its configuration, and keeps your counts and click history unless you asked for them to go.

Data Default With Delete all data when the plugin is uninstalled ticked
Settings, including saved tokens and keys Removed Removed
Share sets Removed Removed
Follow profiles Removed Removed
The import record and feature switches Removed Removed
Every post’s own choices: all custom fields starting _plugixa_share_, including Pro’s Removed Removed
The plugin’s capabilities, on every role and user Removed Removed
The plugin’s short-lived records Removed Removed
The share count table Kept Removed
The click history table Kept Removed

The setting is under Settings -> Advanced -> Data and is off by default. “Share counts and click history cannot be recovered once deleted.”

Counts and clicks are kept by default because they are months of numbers that cannot be recreated. If you reinstall the plugin later, the tables are found again.

On a multisite network, uninstalling cleans up every site.

What uninstalling does not touch

  • Shortcodes and blocks in your content. Remove those by hand.
  • plugixa_share() and plugixa_follow() calls in theme templates. Wrap them in function_exists() so the theme keeps working.
  • Anything already sent to an outside service, such as subscribers added to your email list or short links created at Bitly.

What to do next

Quick Links