=== GoTrace Analytics ===
Contributors: gotrace
Tags: analytics, statistics, privacy, ai, heatmaps
Requires at least: 6.0
Tested up to: 7.1
Requires PHP: 7.4
Stable tag: 1.0.3
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Privacy-first website analytics with an AI analyst. See your full analytics dashboard inside WordPress.

== Description ==

GoTrace is website analytics that explains itself: a statistics engine finds what changed on your site, and an AI analyst tells you why and what to do next, with every number checked against your data.

This plugin connects your WordPress site to your GoTrace account:

* **One-click setup.** Click "Connect with GoTrace", approve, and the tracking script is added to every page. No code to paste.
* **Your full dashboard in wp-admin.** Daily briefings, AI insights, the AI analyst, real-time visitors, traffic sources and campaigns, AI traffic from ChatGPT and other assistants, pages, journeys, funnels, heatmaps and session recordings, all under GoTrace → Analytics.
* **Dashboard widget.** Visitors, pageviews, conversions and AI-assistant traffic for the last 7 days, with your top pages.
* **Privacy options.** Cookie-free mode, wait-for-consent mode, and roles that are never tracked (administrators and editors by default).
* **You decide who sees it.** Administrators only, or editors and authors too.

= What you need =

A GoTrace account with this site added as a website. Every plan works, including the free trial.

= Privacy =

The plugin itself stores no visitor data in WordPress. The tracking script sends anonymous usage data to GoTrace: IP addresses are used in memory only and never stored, and nothing typed into forms is collected. The plugin adds suggested wording to Settings → Privacy → Policy guide that you can copy into your privacy policy.

== External services ==

This plugin is the WordPress connector for GoTrace (https://gotrace.site), a hosted analytics service. It needs a GoTrace account and talks to the GoTrace servers in the following cases, and in no others. Nothing is sent until an administrator clicks "Connect with GoTrace".

* **Connecting.** When an administrator clicks "Connect with GoTrace", their browser is sent to gotrace.site with the address of this WordPress admin area, so the right website can be picked and the administrator can be sent back. After they approve, WordPress sends the one-time code it received, and the same address, to gotrace.site and receives a connection key, which is stored in this site's database.
* **Tracking visitors.** Once connected, and unless tracking is switched off in GoTrace → Settings, every public page loads the script https://gotrace.site/a.js. In each visitor's browser it sends the page address, the referring page (without its query string), browser, operating system, device type, screen size, language, scroll depth, time on page and clicks on links, downloads and forms (never field values) to gotrace.site. The visitor's IP address is used briefly to count visits and find the country, and is never stored. Logged-in users with the roles you exclude are not tracked. Cookie-free mode and wait-for-consent mode are available in the settings.
* **Viewing analytics.** When someone with access opens GoTrace → Analytics or clicks "Open in a new tab", WordPress asks gotrace.site for a one-minute link (sending the connection key) and the dashboard is loaded from gotrace.site.
* **Dashboard widget.** When the WordPress dashboard is shown, WordPress asks gotrace.site for the last 7 days of totals and top pages (sending the connection key). The answer is cached for 10 minutes.
* **Disconnecting.** When an administrator clicks "Disconnect", WordPress tells gotrace.site to revoke the connection key.

GoTrace terms of service: https://gotrace.site/legal/terms
GoTrace privacy policy: https://gotrace.site/legal/privacy

== Installation ==

1. Upload the plugin and activate it.
2. Go to GoTrace → Settings and click "Connect with GoTrace".
3. Sign in, pick the website that matches this WordPress site, and approve.

== Frequently Asked Questions ==

= Do I need a GoTrace account? =

Yes. The plugin connects WordPress to your GoTrace account, where the analytics are stored and processed. You can start a free trial at https://gotrace.site/register.

= The dashboard says my browser blocked the embedded view =

Some browsers (Safari in particular) block cookies inside embedded pages. Click "Open in a new tab" above the dashboard; everything works there.

= Can I limit what WordPress users can do in the dashboard? =

Yes. When you connect, you choose whether WordPress users may use the AI analyst and whether they may create goals and funnels. They can only ever see the one connected website, never your billing, team or other websites.

= How do I disconnect? =

GoTrace → Settings → Disconnect. You can also remove the connection from your GoTrace account under Organization → WordPress connections.

== Screenshots ==

1. Your GoTrace dashboard inside wp-admin: daily briefing, key numbers and traffic.
2. Settings: connection, tracking options, privacy switches and who can see analytics.
3. The dashboard widget with the last 7 days and your top pages.

== Changelog ==

= 1.0.3 =
* Tested with WordPress 7.1.
* Suggested privacy policy text under Settings → Privacy → Policy guide.
* Redirects to the analytics server use wp_safe_redirect(); the disconnect confirmation no longer uses an inline script.

= 1.0.2 =
* The GoTrace logo is the menu icon.
* A newly connected site with no visits yet shows a "waiting for the first visit" note instead of a link to the manual install guide.

= 1.0.1 =
* The menu is now called GoTrace.
* Works on hosts that strip the Authorization header (Apache with PHP-FPM).
* A refused request no longer removes the saved connection.

= 1.0.0 =
* First release.
