Luis Rita AI Blog Writer with Sources is a draft-first AI blog writer. It creates normal WordPress block content from your brief and selected sources, and never publishes automatically.
This plugin is bring-your-own-key only. There is no bundled account, subscription, or upsell.
Generated content can contain errors, unsupported claims, or bias. Human review is required before publication. No ranking, traffic, accuracy, or legal-safety guarantee is made.
This plugin sends data to two kinds of external destinations. Both happen only after an administrator configures an API key or a user supplies URLs. Nothing is sent during installation, activation, or idle time.
1. Your selected AI provider
Requests go to the provider matching the configured API key:
https://api.openai.com/v1/models, https://api.openai.com/v1/responseshttps://api.anthropic.com/v1/models, https://api.anthropic.com/v1/messageshttps://generativelanguage.googleapis.com/v1beta/models, .../v1beta/models/{model}:generateContenthttps://api.x.ai/v1/models, https://api.x.ai/v1/chat/completionsWhat is sent, and when:
Never sent: WordPress credentials, other database contents, visitor data, or payment data. API keys stay server-side and are never exposed to the browser or the REST API.
Provider terms and data policies apply to everything sent:
2. Source URLs you supply
During research, your server fetches each URL in the brief with a plain HTTP request identified as Luis-Rita-AI-Blog-Writer/<version>; <your site URL>. No brief content, key, or user data is sent. Private addresses are rejected, redirects are limited to three, and responses are capped at 1 MB.
In your own database only: jobs (brief, status, settings snapshot, owner, linked post), sources and extracted notes, generated outline and draft versions, usage and estimated cost per request, writer profiles, post meta on generated drafts (job ID, provenance, SEO suggestions, warnings), the risk acknowledgement in user meta, and settings plus encrypted API keys in options.
Nothing is sent to the plugin author. The plugin contains no analytics, tracking, or phone-home code.
A daily WP-Cron event enforces the Prompt/source/log retention days setting (default 90). For completed jobs older than the cutoff it deletes sources and artifacts and clears the stored brief. Older usage rows are deleted. Generated posts are always kept.
Tools Export Personal Data returns a user’s jobs and writer profiles. Tools Erase Personal Data removes their profiles, sources, artifacts, generated-content post meta, and acknowledgement, and unlinks their jobs and usage. Posts are kept.
Uninstall always removes the plugin capabilities. Define AIBCG_REMOVE_DATA_ON_UNINSTALL as true first to also delete plugin tables, options, encrypted keys, transients, and metadata on every site. Generated posts and linked author accounts are always kept.
Keys are stored per provider: after changing the provider, click Save Changes, then save its key. Keys defined in wp-config.php cannot be edited here. Saving keys requires Sodium.
provider_http_401: key rejected. `provider_http_429`: rate limit or quota. `provider_unreachable`: the server cannot reach the provider over HTTPS. "Selected model is unavailable": choose another model and test the connection again.
WP-Cron is not running. Check AI Blog Writer Diagnostics, schedule wp-cron.php from a server scheduler, then click Retry stage.
Sources must be public HTML or plain-text pages. Replace the URL and start a new job.
Download the JSON report from AI Blog Writer Diagnostics. It excludes API keys, prompts, article text, and source notes.