{"id":335220,"date":"2026-07-13T11:55:16","date_gmt":"2026-07-13T11:55:16","guid":{"rendered":"https:\/\/br.wordpress.org\/plugins\/consentguard\/"},"modified":"2026-07-13T12:42:26","modified_gmt":"2026-07-13T12:42:26","slug":"privatto","status":"publish","type":"plugin","link":"https:\/\/pcd.wordpress.org\/plugins\/privatto\/","author":21064875,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.4.0","stable_tag":"2.1.0","tested":"7.0.4","requires":"6.2","requires_php":"7.4","requires_plugins":null,"header_name":"Privatto","header_author":"Interativus","header_description":"CMP pr\u00f3pria para LGPD\/GDPR: banner de consentimento granular, bloqueio autom\u00e1tico de tags de terceiros, Google Consent Mode v2 e prova de consentimento em banco de dados pr\u00f3prio.","assets_banners_color":"fafbfa","last_updated":"2026-07-13 12:42:26","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/interativus.com.br\/privatto","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":318,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.4.0":{"tag":"1.4.0","author":"sergioinglez","date":"2026-07-13 12:42:26"},"2.0.0":{"tag":"2.0.0","author":"sergioinglez","date":"2026-07-17 13:13:35"},"2.1.0":{"tag":"2.1.0","author":"sergioinglez","date":"2026-08-12 18:18:13"}},"upgrade_notice":{"1.4.0":"<p>Security and standards-compliance release. WordPress 6.2 or later is now required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3605989,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3605989,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3605989,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3605989,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.4.0","2.0.0","2.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[223629,16626,131785,160853,396],"plugin_category":[54],"plugin_contributors":[271352],"plugin_business_model":[],"class_list":["post-335220","plugin","type-plugin","status-publish","hentry","plugin_tags-consent-mode","plugin_tags-cookie-consent","plugin_tags-gdpr","plugin_tags-lgpd","plugin_tags-privacy","plugin_category-security-and-spam-protection","plugin_contributors-sergioinglez","plugin_committers-sergioinglez"],"banners":{"banner":"https:\/\/ps.w.org\/privatto\/assets\/banner-772x250.png?rev=3605989","banner_2x":"https:\/\/ps.w.org\/privatto\/assets\/banner-1544x500.png?rev=3605989","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/privatto\/assets\/icon-128x128.png?rev=3605989","icon_2x":"https:\/\/ps.w.org\/privatto\/assets\/icon-256x256.png?rev=3605989","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Privatto is a self-hosted consent management platform (CMP) for WordPress, built with Brazil's LGPD and the GDPR in mind. It requires no external service.<\/p>\n\n<p><strong>Main features:<\/strong><\/p>\n\n<ul>\n<li>Granular consent banner with per-category preferences (necessary, analytics, marketing, embeds).<\/li>\n<li>Automatic blocking of third-party scripts and iframes via output buffering: matching <code>&lt;script&gt;<\/code> tags are switched to <code>type=\"text\/plain\"<\/code> before the page reaches the browser, so nothing runs before consent.<\/li>\n<li>Google Consent Mode v2 injected with everything denied by default, updated when the visitor decides.<\/li>\n<li>Proof of consent stored in your own database table: unique consent ID, action, categories (JSON), policy version, hashed IP (optional), country, user agent, page URL, and UTC timestamp. Exportable to CSV for audits.<\/li>\n<li>LGPD document generator: privacy policy, terms of use, cookie policy, returns policy, and a plain-language summary, built from a guided form. Optional AI text refinement (Groq API) for the business description only \u2014 mandatory legal clauses never go through AI.<\/li>\n<li>Data subject rights form (LGPD art. 18) with tracked protocols, 15-day response deadline monitoring, and an admin queue.<\/li>\n<li>Simplified record of processing activities (ROPA) export, as required by ANPD Resolution CD\/ANPD No. 2\/2022, including for small-scale processing agents.<\/li>\n<li>\"Cookie preferences\" reopen link so visitors can change or revoke consent at any time.<\/li>\n<\/ul>\n\n<p><strong>Important notice:<\/strong> the generated documents are a structured starting point aligned with the LGPD; they are not legal advice. Review by a lawyer is recommended, especially for complex operations.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects to one optional third-party service:<\/p>\n\n<p>Groq API \u2014 used only if you paste a Groq API key in Privatto \u2192 LGPD Documents. It is used to (1) rewrite, in more natural language, the free-text description of your site\/business that you typed into the document form, and (2) generate a plain-language summary of your privacy policy for the same document. Only that free text (and the derived facts needed to build the summary) is sent; the mandatory legal clauses are always generated locally and never sent to the API. This call happens only when you click the \"Refine with AI\" \/ \"Generate summary with AI\" buttons \u2014 never automatically and never on the public-facing site. If no key is configured, these buttons are disabled and everything works normally without any external call.\nService: Groq ( https:\/\/groq.com ). Terms of Service: https:\/\/groq.com\/terms-of-use \u00b7 Privacy Policy: https:\/\/groq.com\/privacy-policy<\/p>\n\n<p>Note: the plugin also ships a static reference catalog (service name, vendor, and known script\/domain signatures) used only to help the document generator recognize and describe third-party services <em>that your own site may already be using<\/em> (e.g. Google Analytics, Meta Pixel, Stripe) when writing your cookie policy. This catalog does not make any outbound request to those services \u2014 it is local, offline pattern-matching against your own site's HTML.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin through Plugins \u2192 Add New \u2192 Upload Plugin, or copy the <code>privatto<\/code> folder to <code>\/wp-content\/plugins\/<\/code>.<\/li>\n<li>Activate the plugin. The consent table and default options are created on activation.<\/li>\n<li>Follow the onboarding wizard, then fine-tune under <strong>Privatto \u2192 Settings<\/strong>.<\/li>\n<li>Generate your legal documents under <strong>Privatto \u2192 LGPD Documents<\/strong>.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20depend%20on%20any%20external%20service%3F\"><h3>Does it depend on any external service?<\/h3><\/dt>\n<dd><p>No. Banner, blocking, consent records, and document generation all run on your own site. The only optional external call is the Groq API, used exclusively to refine free-text descriptions if you provide an API key.<\/p><\/dd>\n<dt id=\"how%20does%20the%20tag%20blocking%20work%3F\"><h3>How does the tag blocking work?<\/h3><\/dt>\n<dd><p>The plugin buffers the full page output on <code>template_redirect<\/code>, injects Google Consent Mode v2 (all denied) right after <code>&lt;head&gt;<\/code>, and rewrites any <code>&lt;script&gt;<\/code> whose <code>src<\/code> or body matches the configured patterns. When the visitor consents, the allowed scripts are restored and executed.<\/p><\/dd>\n<dt id=\"where%20is%20the%20proof%20of%20consent%20stored%3F\"><h3>Where is the proof of consent stored?<\/h3><\/dt>\n<dd><p>In a dedicated table (<code>wp_pvto_consents<\/code>). Each decision records a UUID, action, categories, policy version, optional irreversible IP hash, country, user agent, URL, and UTC date\/time. You can view it under <strong>Privatto \u2192 Logs<\/strong> and export it to CSV.<\/p><\/dd>\n<dt id=\"is%20uninstall%20data%20removal%20opt-in%3F\"><h3>Is uninstall data removal opt-in?<\/h3><\/dt>\n<dd><p>Yes. By default, uninstalling keeps the consent tables (they are your audit evidence) and only removes settings. To delete everything, define <code>PVTO_DELETE_DATA<\/code> as <code>true<\/code> in <code>wp-config.php<\/code> before removing the plugin.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.4.0<\/h4>\n\n<ul>\n<li>Security hardening: prepared statements with the <code>%i<\/code> identifier placeholder, input unslashing\/sanitization, output escaping.<\/li>\n<li>Internationalization: translators comments and ordered placeholders.<\/li>\n<li>Readme rewritten to WordPress.org standards.<\/li>\n<\/ul>","raw_excerpt":"LGPD\/GDPR consent banner with automatic third-party tag blocking, Google Consent Mode v2, and consent records stored in your own database.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/335220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=335220"}],"author":[{"embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sergioinglez"}],"wp:attachment":[{"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=335220"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=335220"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=335220"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=335220"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=335220"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/pcd.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=335220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}