GDPR-Friendly Logging: Retention Windows and IP Anonymisation
Anti-spam plugins log submissions by nature — which means they hold personal data. Spamify’s retention window and IP anonymisation keep that logging on the right side of GDPR.
Any anti-spam tool has to remember something about submissions to do its job — and the moment it stores an email address or IP, it’s handling personal data. Spamify is built so that logging stays useful without becoming a compliance liability.
Automatic purge by retention window
The log_retention_days setting defines how long log records live. A daily job purges anything older than the window automatically — you don’t have to remember to clean up. This directly serves the GDPR principle of storage limitation: don’t keep personal data longer than you need it.
Choosing a window is a trade-off:
- Shorter (e.g. a couple of weeks) — minimal data at rest, strong privacy posture. Enough history to tune settings and spot attacks.
- Longer — more history for investigating patterns, but more personal data held. Only keep what you’ll actually use.
IP anonymisation
Spamify can optionally anonymise the IP addresses it stores. When enabled, records keep enough to be useful for rate-limiting patterns without retaining a full, personally-identifiable address indefinitely. If your privacy policy commits to minimising IP retention, turn this on.
Nothing leaves your server
The bigger privacy story is what doesn’t happen: Spamify never phones home. Your logs live in your own database, and no submission data is sent to the plugin author or any analytics service. The only outbound connections that can ever exist are the opt-in SMTP verification and CAPTCHA features — both off by default. See why self-contained beats cloud filters for the full argument.
Stop spam at the source with Spamify
Self-contained email validation and bot protection for WordPress — syntax checks, honeypot, rate limiting and optional SMTP verification, all on your own server.
Get the free plugin