=== ProxyAI Chat Assistant ===
Contributors: proxyai
Tags: chatbot, ai, customer support, woocommerce, live chat
Requires at least: 6.6
Tested up to: 7.1
Requires PHP: 8.1
Stable tag: 2.0.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

AI chat assistant that answers from your own content, hands off to a human, and adds to the cart in the shopper's browser.

== Description ==

ProxyAI answers visitor questions from your published content, hands conversations
to a human, and provides support tickets. WooCommerce stores can also offer cart,
checkout and order-status assistance.

Connect from the ProxyAI screen in wp-admin. Your site must be publicly reachable
over HTTPS; WooCommerce is optional. Manage setup, inbox, tickets, usage and
settings from the plugin dashboard.

== External services ==

This plugin is a client for ProxyAI, a hosted service. It cannot function
without it, and it contacts ProxyAI in the ways described below. The service is
operated by ProxyAI at https://www.proxyai.app.

* Terms of Service: https://www.proxyai.app/terms
* Privacy Policy: https://www.proxyai.app/privacy
* Service Agreement: https://www.proxyai.app/service-agreement

**When you press "Connect to ProxyAI"**, the plugin sends this site's address,
its name, the administration email address, its WordPress version, its
WooCommerce version if installed, whether pretty permalinks are enabled, and
the plugin version. This creates an account for this domain. Nothing is sent
before you press that button.

**Every six hours while connected**, the plugin reports the same site name,
WordPress version, WooCommerce version, permalink setting and plugin version.
This is how the service knows the install is alive and which features it can
offer.

**While you use the ProxyAI screen in wp-admin**, the dashboard there — setup,
add-ons, inbox, tickets, usage, rates, settings — reads and writes through
this site's own REST API. Your server forwards each request to ProxyAI signed
with the site's secret; your browser talks only to your own site and holds no
ProxyAI credential. Nothing from the service is embedded inside wp-admin.

**When you pay by card**, your browser loads Stripe's payment form from
`https://js.stripe.com` — a PCI-compliant payment provider — and your card
details go to Stripe alone; they never touch this site or ProxyAI's servers.
Stripe receives the amount, the currency, and the email address of the
WordPress user paying. Stripe is operated by Stripe, Inc.:
Terms of Service https://stripe.com/legal/consumer, Privacy Policy
https://stripe.com/privacy. Nothing from Stripe loads until you press
"Pay by card".

**When you connect WhatsApp with Meta's one-click signup**, your browser
loads Meta's JavaScript SDK from `https://connect.facebook.net` and opens
Meta's own signup window, where you sign in to Facebook and choose the
WhatsApp Business account to connect. Meta receives what you enter there;
this plugin and ProxyAI receive only the resulting connection. Nothing from
Meta loads until you open WhatsApp's connect window in the Channels screen. Meta is operated by
Meta Platforms, Inc.: Terms https://www.facebook.com/legal/terms, Privacy
Policy https://www.facebook.com/privacy/policy.

**When you pick a Google Sheets or Drive file for an Agent Tasks agent**, your
browser loads Google's file picker from `https://apis.google.com` and shows
the files of the Google account you already connected to Agent Tasks; the
file you choose is passed to ProxyAI so the agent can use it. Nothing from
Google loads until you press the button to choose a file. Google is operated
by Google LLC: Terms of Service https://policies.google.com/terms, Privacy
Policy https://policies.google.com/privacy.

**When you pay with PayPal**, PayPal's own checkout page opens in a new tab
with the amount and currency; the plugin loads no PayPal script and sees no
PayPal login. PayPal is operated by PayPal Holdings, Inc.:
User Agreement https://www.paypal.com/legalhub/useragreement-full,
Privacy Statement https://www.paypal.com/legalhub/privacy-full.

**When you upload files in wp-admin** — knowledge documents for the Knowledge
add-on, a chat-widget icon, or a support-ticket attachment — the file goes from
your server to a storage address that ProxyAI issues for that upload; your
browser talks only to your own site. These files are stored by ProxyAI under
its Privacy Policy above.

**When you open the hosted dashboard on proxyai.app** (an optional link — the
wp-admin screen covers day-to-day work), the plugin asks the service for a
one-time sign-in code over the same signed server-to-server channel, and your
browser redeems it in a new tab. The code works once and expires after a
minute.

**When the Knowledge add-on is active**, the plugin sends the URL, title and
plain-text content of your published posts, pages and products, so the
assistant can answer from them. Drafts, private posts, password-protected posts
and trashed posts are never sent. Without that add-on, no content is sent. You
can filter or exclude individual documents with the `proxyai_sync_document`
hook, or switch automatic sync off entirely under Store actions in the
ProxyAI screen.

**On every front-end page view**, visitors' browsers load the chat widget from
`https://www.proxyai.app/embed.js`, and on WooCommerce stores also
`woo-cart.js`. On a page carrying the support-ticket form, they additionally
load `ticket-embed.js` from the same host. Chat messages your visitors type go
to ProxyAI to be answered. These scripts are served by the service itself and
are not bundled, because the widget and the service it talks to are versioned
together. `embed.js` and `woo-cart.js` are minified for visitors' page speed;
their readable sources are served alongside them at
`https://www.proxyai.app/embed.src.js` and
`https://www.proxyai.app/woo-cart.src.js`, and kept with the plugin source at
https://github.com/Proxyai-team/wordpress/tree/main/widget. `ticket-embed.js`
is served unminified.

**When a logged-in user views a page with the assistant or the ticket form**,
the plugin places a signed token on the page carrying that user's WordPress
user ID, email address and display name, which their browser passes to ProxyAI.
This is what lets the service recognise a returning customer and tie a ticket to
their account's own email rather than one typed into a chat box. The token is
signed with a secret held by this site, so a visitor cannot forge one, and it is
issued only while the Helpdesk add-on is active. Logged-out visitors get no
token and stay anonymous.

**When a visitor asks about an order**, ProxyAI calls this site back with an
order number and a billing email address. The plugin answers only if the two
match an order here, and returns only that order's number, status, date, total,
currency, line items and tracking details. Requests must be signed with this
site's secret, and repeated failures from one address are rate limited.

== Source code ==

The dashboard script, `admin/dist/dashboard.js` with `admin/dist/dashboard.css`,
is built from source and shipped unminified and unmangled, so it reads as the
code it was built from. It includes its own copy of React 19, used on the
ProxyAI screen only. The source is the ProxyAI web dashboard's own components together with
the plugin build in `proxyai-admin/`, published with its build instructions at
https://github.com/Proxyai-team/wordpress — read, fork, rebuild, or diff the
output against the plugin zip there.

`admin/js/tickets-block.js`, `admin/css/admin.css` and every PHP file are plain,
hand-written files with no build step.

The dashboard bundles open-source libraries (React, Radix UI, Stripe.js's loader,
PDF.js, mammoth, SheetJS, JSZip and others), all under GPL-compatible licences;
`admin/dist/THIRD-PARTY-LICENSES.txt` lists every one with its version and
licence, generated at build time from what the bundle actually contains. PDF.js
runs its worker from `admin/dist/public/pdf.worker.mjs`. The only scripts the
dashboard loads from elsewhere are Stripe's (when the payment dialog opens),
Meta's (when you open WhatsApp's connect window) and Google's file picker
(when you choose a file for an agent), each described under External services.

== Frequently Asked Questions ==

= Is WooCommerce required? =
No. Cart and order features require WooCommerce; content chat does not.

= Can I control content syncing? =
Yes. Turn automatic syncing off in Store actions, or filter documents with
`proxyai_sync_document`. Private, draft and password-protected content is excluded.

== Installation ==

1. Install and activate the plugin.
2. Open **ProxyAI** in the admin menu (under **WooCommerce** if it is installed).
3. Read what connecting sends, then press **Connect to ProxyAI**.
4. Add credit from the **Add-ons & credits** tab, and the assistant starts
   answering.

== Screenshots ==

1. The assistant answering on a storefront, with suggested questions.
2. The assistant adds an item to the shopper's cart from the conversation.
3. The cart page after the assistant added the item — same browser session, ready for checkout.
4. Human hand-off: the agent inbox in wp-admin, with an AI briefing of the conversation so far.
5. Support tickets on a kanban board — open, pending and resolved, straight from wp-admin.
6. Chatbot setup — name, model, intro message and spend at a glance.
7. Channels: web, WhatsApp, Telegram, LINE, Messenger, Instagram and Discord from one bot.

== Changelog ==

= 2.0.1 =
* Save buttons enable only after changes; drafts survive dashboard navigation until the page closes.
* Align dashboard profile and spending cards with the shared app layout.
* Use platform-specific ticket guidance and link chat agents to the task library.
* Fix WordPress Plugin Check issues and keep notification toasts below the admin toolbar.

= 2.0.0 =
* Shared build version across the web and platform dashboards.
* Dashboard build identity includes the source commit; plugin versions use numbers only.
* Shortened documentation while retaining service and source disclosures.

= 1.1.0 =
* A new dashboard, the same one ProxyAI's web dashboard, Shopify app and Wix app use: a sidebar for every screen, and every screen the hosted dashboard has, kept in step with it from now on.
* Bot Knowledge reads PDF, Word, Excel and PowerPoint files as well as plain text, in your browser, before anything is uploaded.
* The dashboard opens on a Dashboard screen: your account, credits, spend, and questions about your data answered with charts.
* Choose a plan in setup: Free, with every add-on and a "Powered by ProxyAI" badge, or the $69 Deal, with every add-on and $69 of AI credits.
* Your site's widget switch and automatic content sync move to the Store actions screen.
* Requires WordPress 6.6 or later.

== Upgrade Notice ==

= 2.0.1 =
Updated dashboard save behavior, platform guidance and WordPress compatibility fixes.
