Synth Antispam connects your site to Synth for WordPress, the hosted AI spam-checking service
built on Synth — the same platform that already reads more than three million messages a year.
Every comment is judged on what it is trying to sell, not matched against a keyword list you have
to keep current, and not scored by code running on your site. To get started: install the plugin,
open Settings Synth Antispam and press Get a site key — there is nothing to copy by hand.
The visitor never waits: the verdict comes back a moment after the comment is submitted, not in the
middle of the request. Spam lands in the Spam folder, or in the moderation queue in strict mode.
Nothing is ever deleted. The plugin never removes a comment and never puts one in Trash, so a
comment filed as spam by mistake stays recoverable for as long as you keep it. WordPress’s
scheduled cleanup empties Trash, not Spam.
You supply one thing: a site key. Until a key is entered the plugin sends no request at all, and
comments publish exactly as they would without it.
This plugin is a thin client for the Synth Antispam classification service, an external,
cloud-hosted processor. It sends each new comment (and pingback or trackback) to that service to
obtain a spam verdict, and applies the verdict using WordPress’s own moderation tools (Spam folder
or moderation queue — see “Description” above). It also asks that same service for this site’s key
when you press Get a site key. No request serves any other purpose; the full list is below.
The service is operated by LightApps OÜ (Estonia). Its terms and its privacy policy for this
plugin — including the controller/processor split described below, where the data is processed, and
who else it reaches — are published here:
Both legal documents cover the WordPress service specifically. Synth also operates a Telegram
service under separate general documents, which do not apply to this plugin.
This is a paid, cloud-hosted service. Every site that registers is given a starting allotment
of checks at no charge, and higher volumes are available on paid subscription tiers above it.
Every paid tier applies to one site — a site’s key covers checks made for that site, not a group of
sites. Current check volumes and prices are on the pricing page linked above, not in this file:
this file ships frozen inside the build and is not corrected between releases, while they change.
Running out of checks does not turn off anything this plugin does. When a site has used its
checks for the current period, the classification service simply stops answering new requests for
that site until the period resets — the plugin does not lock, gate, or disable any of its own
functionality in response, and it never has: no feature, mode, or setting in this plugin is gated
behind a tier or a payment state, at any usage level. Comments continue to be handled by
WordPress’s own native moderation tools, the same as whenever the service is briefly unreachable
for any other reason.
Every request this plugin can make, in full. Each one goes to the one service named above and to
nothing else — see “Payments” below for the single case where your browser, rather than this plugin,
is sent somewhere else:
synth_wp_send_feedback filter, which shipsfalse; with no code added to your site, this request never happens.Payments — the only time your browser leaves your site, and only if you press an upgrade button.
Payment is taken by Stripe (Stripe Payments Europe, Ltd.), not by us. This plugin sends nothing
to Stripe: it asks the Synth Antispam service for a payment page address, checks that the address
really is Stripe’s checkout page, then opens it in your browser. What you type there, card details
included, goes from your browser to Stripe and reaches neither your site, nor this plugin, nor the
Synth Antispam service. Stripe’s own documents govern that page:
Press no upgrade button and Stripe is never involved.
Entering a site key is not a subscription step and does not put your site on a plan: no feature,
mode, or setting in this plugin is gated behind a tier, a payment state, or a trial. Everything the
plugin can do, it does for every configured site.
Nothing is sent until you opt in. The plugin attaches no comment-checking hooks until both a
service address and a site key are set; with either missing it behaves as with no key at all, and
the service is never contacted for any comment. Setting that pair — on the Settings Synth
Antispam screen, or at network level on multisite — is the act of opting in and is the consent
gate; there is no separate checkbox.
Exactly what is sent, field by field. This list matches the plugin’s request builder field for
field — nothing beyond it leaves your site:
schema_version — the version of the request format, so the service stays compatible with older and newer plugin versions at once.plugin_version — the installed plugin version, for the same compatibility reason.surface — a fixed label saying the request comes from the comment form (wp_comment in this version; a hook for future integrations such as forms outside comments).object_type — comment, pingback, or trackback: the latter two are machine-submitted and the service weighs them differently.content.body — the comment text as submitted, before any of WordPress’s own HTML filtering runs, so a link the filtering would otherwise strip is still visible to the classifier.content.author_name — the display name the commenter typed into the comment form.content.author_url — the website URL the commenter typed into the comment form. On the traffic this plugin was built against, this field carries a very strong share of the spam signal — most of it is not visible in the comment text at all.content.author_email_domain — only the domain part of the commenter’s email address (for example gmail.com), used to recognise disposable or throwaway email patterns. The email address itself is never sent — see “What is never sent” below.content.author_id_hash — a one-way SHA-256 hash of the commenter’s email address combined with a secret value generated for your site alone (your site’s own “salt”). It lets the service recognise that two comments on your site came from the same email address without ever receiving that address. Because the salt is unique to your site and known only to it, the same commenter cannot be linked across two sites using this plugin — impossible by construction, not merely disabled. It is a per-site pseudonym, not an anonymised identifier: uninstalling the plugin destroys the salt (see “Retention” below), after which even this site can no longer connect a previously sent hash back to an email address.context.author_status — either registered (a logged-in registered user of your site) or anonymous (everyone else). Only these two values are ever sent: a commenter who already has an approved comment on your site is trusted and skipped before any request is built, so their comment is never sent at all and no status is transmitted for them.context.is_reply — whether the comment is a reply to another comment.context.site_locale — your site’s configured language (for example en_US), used as a hint for language-specific handling.context.client_ip_status — absent if the request carried no IP address, or direct if it did. This tells the service only whether one was present — the address itself is never sent, in either case — see “What is never sent” below. The plugin never reconstructs a “real” visitor IP from proxy or CDN forwarding headers: those are only as trustworthy as whoever sent the request, and a site behind a proxy cannot tell the difference.context.has_user_agent — true or false, whether the browser sent a User-Agent string at all. The User-Agent string itself is never sent — see “What is never sent” below.What is never sent, under any circumstances:
content.author_email_domain) and a salted one-way hash (content.author_id_hash) ever leave your site.context.client_ip_status) leaves your site; the address itself never does.context.has_user_agent) leaves your site.Retention. Two separate things are kept, for two different lengths of time.
The verdict record. The verdict for each comment is retained by the Synth Antispam service for 24
hours and then expires automatically. That is the record your site collects its verdict from.
The training record. Separately, the service keeps its own copy of each request your site sends —
the comment text and the commenter fields listed above, exactly as sent — together with the verdict
its classifier produced and any later correction you make with the Not spam / Spam buttons in
your Comments list. It uses those copies to train and improve the Synth spam-classification models. These copies
are kept indefinitely: they have no expiry date. They are stored as sent — not anonymised, not
aggregated, and not reduced to statistics. This applies to every site that uses the service; there is
no setting, on this screen or anywhere else, that turns it off. If that is not acceptable for your
site, the choice available to you is not to install the plugin.
Deletion on request. To have your site’s stored copies deleted, write to support@synth.locker with
your site’s address. The service can delete them by site key, so a request covers every copy taken
from your site rather than one comment at a time. An operator tool for this deletion is being built
alongside this release; until it is in place the deletion is performed by hand on request, and the
address above is the route either way.
Uninstalling this plugin permanently deletes your site’s secret salt; after that, no
author_id_hash it previously sent can be linked back to an email address, by this site or by the
service. Uninstalling does not by itself delete copies already taken — use the address above for
that. Your site key is the one thing deliberately left behind, so that reinstalling the plugin
does not cost you the checks attached to it. Tick
Delete the site key when the plugin is deleted on the settings screen if you want it removed too.
Your own obligations under privacy law — see “For site owners: your obligations under GDPR
and similar privacy laws” in the Frequently Asked Questions above.
A search of this plugin’s files finds these addresses and no others:
wp-api.synth.locker — the Synth Antispam service above. The shipped default; changeable on thewp-config.php. The only address this plugin sends a request to.checkout.stripe.com — Stripe’s payment page. No request is sent there; the address is presentsynth.locker and wordpress.synth.locker — the terms, privacy, pricing and plugin home pageswww.gnu.org — the GPL licence text.your-synth-endpoint.example and https://x — not addresses: a greyed-out example in the empty