=== Privatto ===
Contributors: interativus, sergioinglez
Tags: lgpd, gdpr, cookie consent, consent mode, privacy
Requires at least: 6.2
Tested up to: 7.0
Requires PHP: 7.4
Stable tag: 1.4.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

LGPD/GDPR consent banner with automatic third-party tag blocking, Google Consent Mode v2, and consent records stored in your own database.

== Description ==

Privatto is a self-hosted consent management platform (CMP) for WordPress, built with Brazil's LGPD and the GDPR in mind. It requires no external service.

**Main features:**

* Granular consent banner with per-category preferences (necessary, analytics, marketing, embeds).
* Automatic blocking of third-party scripts and iframes via output buffering: matching `<script>` tags are switched to `type="text/plain"` before the page reaches the browser, so nothing runs before consent.
* Google Consent Mode v2 injected with everything denied by default, updated when the visitor decides.
* Proof of consent stored in your own database table: unique consent ID, action, categories (JSON), policy version, hashed IP (optional), country, user agent, page URL, and UTC timestamp. Exportable to CSV for audits.
* LGPD document generator: privacy policy, terms of use, cookie policy, returns policy, and a plain-language summary, built from a guided form. Optional AI text refinement (Groq API) for the business description only — mandatory legal clauses never go through AI.
* Data subject rights form (LGPD art. 18) with tracked protocols, 15-day response deadline monitoring, and an admin queue.
* Simplified record of processing activities (ROPA) export, as required by ANPD Resolution CD/ANPD No. 2/2022, including for small-scale processing agents.
* "Cookie preferences" reopen link so visitors can change or revoke consent at any time.

**Important notice:** the generated documents are a structured starting point aligned with the LGPD; they are not legal advice. Review by a lawyer is recommended, especially for complex operations.

== Installation ==

1. Upload the plugin through Plugins → Add New → Upload Plugin, or copy the `privatto` folder to `/wp-content/plugins/`.
2. Activate the plugin. The consent table and default options are created on activation.
3. Follow the onboarding wizard, then fine-tune under **Privatto → Settings**.
4. Generate your legal documents under **Privatto → LGPD Documents**.

== Frequently Asked Questions ==

= Does it depend on any external service? =

No. Banner, blocking, consent records, and document generation all run on your own site. The only optional external call is the Groq API, used exclusively to refine free-text descriptions if you provide an API key.

= How does the tag blocking work? =

The plugin buffers the full page output on `template_redirect`, injects Google Consent Mode v2 (all denied) right after `<head>`, and rewrites any `<script>` whose `src` or body matches the configured patterns. When the visitor consents, the allowed scripts are restored and executed.

= Where is the proof of consent stored? =

In a dedicated table (`wp_pvto_consents`). Each decision records a UUID, action, categories, policy version, optional irreversible IP hash, country, user agent, URL, and UTC date/time. You can view it under **Privatto → Logs** and export it to CSV.

= Is uninstall data removal opt-in? =

Yes. By default, uninstalling keeps the consent tables (they are your audit evidence) and only removes settings. To delete everything, define `PVTO_DELETE_DATA` as `true` in `wp-config.php` before removing the plugin.

== External services ==

This plugin connects to one optional third-party service:

Groq API — used only if you paste a Groq API key in Privatto → LGPD Documents. It is used to (1) rewrite, in more natural language, the free-text description of your site/business that you typed into the document form, and (2) generate a plain-language summary of your privacy policy for the same document. Only that free text (and the derived facts needed to build the summary) is sent; the mandatory legal clauses are always generated locally and never sent to the API. This call happens only when you click the "Refine with AI" / "Generate summary with AI" buttons — never automatically and never on the public-facing site. If no key is configured, these buttons are disabled and everything works normally without any external call.
Service: Groq ( https://groq.com ). Terms of Service: https://groq.com/terms-of-use · Privacy Policy: https://groq.com/privacy-policy

Note: the plugin also ships a static reference catalog (service name, vendor, and known script/domain signatures) used only to help the document generator recognize and describe third-party services *that your own site may already be using* (e.g. Google Analytics, Meta Pixel, Stripe) when writing your cookie policy. This catalog does not make any outbound request to those services — it is local, offline pattern-matching against your own site's HTML.

== Changelog ==

= 1.4.0 =
* Security hardening: prepared statements with the `%i` identifier placeholder, input unslashing/sanitization, output escaping.
* Internationalization: translators comments and ordered placeholders.
* Readme rewritten to WordPress.org standards.

== Upgrade Notice ==

= 1.4.0 =
Security and standards-compliance release. WordPress 6.2 or later is now required.
