Security & Privacy
Intercessor is designed to keep prayer-request administration inside WordPress while providing controls for public visibility, moderation, and sensitive data.
Public visibility
Only requests intended for public display should be exposed through the Prayer Wall or public REST responses. Private requests are excluded from public presentation.
Anonymous vs. private
- Anonymous hides the requester identity while allowing an approved request to be displayed publicly.
- Private keeps the request itself out of public displays.
These settings solve different privacy requirements and should not be treated as interchangeable.
Administrative access
Use Intercessor capabilities and WordPress roles to limit access to sensitive request data. Give private-prayer access only to people who genuinely need it.
Exported data
CSV exports may contain names, email addresses, prayer content, status information, or interaction data depending on the export. Treat exported files as sensitive administrative data.
Recommended practices:
- Export only when necessary.
- Store exports in a restricted location.
- Avoid sending exports through unsecured channels.
- Delete temporary exports when they are no longer required.
reCAPTCHA
When enabled, Google reCAPTCHA is used as an external anti-spam service. The reCAPTCHA secret key must remain server-side and must never be published in documentation, client-side code, or screenshots.
WordPress email
Intercessor sends notifications through WordPress wp_mail(). Email delivery therefore depends on the site's mail configuration and any SMTP or transactional-email service used by the site.
WARNING
Prayer requests can contain highly personal pastoral information. Configure access, exports, backups, and retention policies accordingly.