What’s sent, and where

When you use Paste & Parse with AI, the text you pasted is sent from your site directly to the AI provider you chose, with instructions for reading it as a recipe. Nothing else from your site is sent: no other posts, no visitor data, no user details.

When you click Suggest with AI (or import a link that has no course, cuisine or diet), the recipe’s title, summary, ingredients, method (first 1,500 characters) and notes are sent, along with the names of your existing courses, cuisines and diets so the AI can reuse them.

Nothing goes to ScrumptiousWP. We never see your key, your text or the result.

Your provider’s own terms decide how they handle the text. See their policies:

AI only runs when an editor clicks Parse recipe. Visitors never trigger AI requests.

How your key is stored

  • Keys are encrypted in your WordPress database (AES-256), using your site’s own secret keys from wp-config.php.
  • Keys are never sent to the browser. The settings screen only shows the first and last few characters.
  • Keys are deleted when you delete the plugin, whatever your other uninstall settings.

Note: If your site’s secret keys in wp-config.php change (for example after a security reset), saved AI keys can no longer be read. Just reconnect OpenRouter or paste your key again.

Who can do what

ActionWho
Connect OpenRouter, save or remove keys, test the connectionAdministrators
Use Paste & Parse (with or without AI)Anyone who can edit posts (Authors, Editors, Administrators)

Keeping costs safe

  • Set a monthly spending limit in your provider’s dashboard.
  • OpenRouter lets you set a credit limit on the key created for your site.
  • Remove the key in Scrumptious and in the provider dashboard if you stop using AI.