Sabriel AI

Documentation

Every setting of the plugin, explained: what it really does and how to configure it best.

Choose your plan

Free
$0
forever, one site
24/7 AI chat with your customers
No message cap: you decide the limit
Main colors and logo
9 languages, bot and panel
The bot remembers the customer on the same device
×Dashboard and customer management
×Advanced customization
×Bookings
×PDF quotes
×Lead thermometer and Analytics
×Website check
×Recoverable history
×Portfolio / Products
×Site knowledge
×Mailchimp synchronization
Your current plan
MOST CHOSEN
Pro
$19
/month, one site
Everything in the free edition
Dashboard and customer management
Full advanced customization
Bookings
PDF quotes
Lead thermometer and Analytics
Website check
Recoverable history
Portfolio / Products
Site knowledge
Mailchimp synchronization
Sabriel AI branding removed
Automatic updates
Upgrade to Pro
Studio
$39
/month, 5 sites
Everything in Pro
Can be activated on 5 sites with the same licence
Made for those looking after more than one site
Go Studio
Agency
$79
/month, 20 sites
Everything in Pro
Can be activated on 20 sites with the same licence
Built for agencies and freelancers
Upgrade to Agency

Secure payment via Freemius. You can cancel anytime.

Setup wizard

The first screen you see after activating the plugin. It exists for a specific reason: the most important fields (AI engine, language, basic identity) are scattered across different pages of the panel, without a guide, a first-time administrator would have to discover on their own where each one is. The wizard lines them up, one after another, in the order they're really needed. Finishing it isn't mandatory: you can skip it at any time (the "Skip" button at the top doesn't lose anything you've already written) and configure everything later from the normal pages, where exactly the same fields live, the wizard isn't a "special" place, it's just the same configuration presented in a more convenient order the first time.

Bot language

Sabriel AI → Setup wizard

What it does: Which language the bot replies in to clients in the chat. This is not the language of the panel you are looking at: they are two separate things and they never affect one another. You choose the panel's language in the dropdown provided (under Settings, General tab): as long as «Same as the site» is set there, the panel follows the WordPress language; if instead you pick a language of your own, from that moment the panel stays on it even when the site language changes, until you set «Same as the site» again. While you are looking at this plugin's pages, the surrounding WordPress menus follow the language you chose too; as soon as you leave, they go back to the site language.

Why this distinction exists: Whoever installs the plugin and whoever uses it to talk to the bot are almost always different people: you configure the site in Italian, but the customers writing in chat could be Spanish, English, any nationality. If the panel and the bot shared the same language, changing one would change the other without you wanting it: that's why they're two completely separate settings, even though they resemble each other.

How to configure it best: Choose your customers' main language. If your audience writes in multiple languages, don't worry: by default the bot always replies in the language the customer uses to write, whatever it is. This choice only serves as a starting point for the first greeting, even before the customer has written anything the bot can use to understand the right language.

Already have a Pro or Agency license?

Sabriel AI → Setup wizard / Premium

What it does: Field to enter an already purchased license key, to immediately unlock all Pro features.

How you see it in the panel

Already have a Pro or Agency license?

The plugin will periodically send essential license data to Sabriel AI to check for security and feature updates, and to verify the validity of your license.

Why this notice about the data: The license key isn't just a decorative code: it's really checked at regular intervals against the license server, to confirm it's still valid and linked to THIS site. That's the same reason you can't just copy a customer's key onto another site without first deactivating it on the first one: the periodic check would notice.

How to configure it best: Leave it empty if you haven't bought anything yet: the bot still works in the free version, with basic functions. You can activate a license at any time, even months later: there's no deadline to "take advantage" of this field, it just sits there waiting.

AI Engine

Here you choose which artificial intelligence the bot will use to understand and reply to customers, and enter the key that connects it to your account. This is probably the first page to actually configure: without a valid key, the bot can't respond to anyone.

Why you need YOUR OWN key and not one already included in the plugin: every conversation the bot processes has a real cost, paid to the chosen AI service (Google, OpenAI or Anthropic), based on how much is written and read. If the plugin included a shared key, that cost would fall on whoever created it, for every site using it: unsustainable. With your own key, the cost stays yours and under your direct control: you see the invoices, set spending limits, change engine whenever you want, never going through any intermediary.

Engine choice

Sabriel AI → AI Engine

What it does: Determines which AI service processes every customer message. You can change it at any time, even with conversations already in progress.

How you see it in the panel
Google Gemini
✓ active
Key saved
OpenAI (ChatGPT)
No key
Claude (Anthropic)
No key

Why changing engine doesn't break anything: The chosen engine ONLY influences how the bot processes the NEXT message: the history of conversations already had, bookings, quotes, everything stays exactly where it was. You can try an engine for a week, change it, and no customer data gets touched: it's a switch for "who thinks", not for "what's already been saved".

How to configure it best: Google Gemini is the cheapest choice and has a generous free tier, good for starting without spending anything at first. ChatGPT and Claude are excellent alternatives if you already have a subscription or a personal preference: the quality of responses for the type of conversations this bot handles (commercial chat, not complex creative tasks) is comparable across all three.

Model choice

Sabriel AI → AI Engine

What it does: Each engine (Gemini, ChatGPT, Claude) offers several models, from the cheapest and fastest to the most powerful. Here you choose which model the active engine uses. Each option shows the indicative price per million tokens, that is how much processing the messages costs, so you can decide by budget, and the recommended one is already selected by default.

Which to choose: For a commercial chat like this one, the recommended, already preselected model is almost always the best choice: it is the cheapest one that handles this kind of conversation well. Move up to a more powerful model only if you notice weak replies; moving down is pointless, since the recommended one is already the most sensible, cost-effective tier.

Custom: If the AI service releases a new model not yet in the list, you can type its exact name by hand using the custom option. The prices shown are verified as of the date indicated in the panel and may change over time: the official price list of the AI service, linked next to it, always prevails.

How to get a Google Gemini key (free)

1. Go to aistudio.google.com and sign in with a Google account.

2. Click "Get API key", then "Create API key".

3. Copy the generated key and paste it into the panel field.

Good to know: Google's free tier has a limit on requests per minute and per day: plenty for a bot on a site with normal traffic, but if your site gets an unusual wave of visitors one day, you might temporarily exhaust it. Google always shows current usage on the same page where you created the key.

How to get an OpenAI (ChatGPT) key

1. Go to platform.openai.com and create an account (different from the normal ChatGPT account: this is for developers, requires a payment method).

2. Go to "API keys", click "Create new secret key".

3. Copy the key right away (starts with "sk-..."): it won't be visible anymore after closing that window.

Good to know: unlike Gemini, there's no free tier here: every conversation has a cost, charged to the linked payment method. OpenAI lets you set a maximum monthly spending cap in your account's billing settings, useful as a safety net.

How to get an Anthropic (Claude) key

1. Go to console.anthropic.com and create an account (requires a payment method).

2. Go to "API Keys", click "Create Key".

3. Copy the key (starts with "sk-ant-...") and paste it into the panel.

Good to know: like OpenAI, requires a payment method and doesn't have a permanent free tier (they sometimes offer trial credits for new accounts). Here too you can set spending limits from the console.

⚠️ When the server allows it (almost always), every key is encrypted before being saved in the database, and not even by looking inside WordPress or the database can it be read in clear. If your server is missing the PHP OpenSSL extension, encryption is not possible: you are told right away, in a warning above the form, the moment you save the key, and the System status page keeps saying so in the «Key encryption available» row. In any case, do not share the key with anyone: it is tied to your account and to your usage costs, exactly like a password.

Customization

The look of the chat widget and the quote PDF: everything the customer sees visually, unlike Behavior (the section after this) which is about what the bot SAYS, not how it looks.

Identity: Bot name and Logo

Sabriel AI → Customization

What it does: The name the bot uses to introduce itself and the logo shown in the chat header and as the button icon.

How your customers see it
Hi! I'm Sabriel AI, the digital assistant of Sabriel Agency. How can I help you?
I'd like some information

Why a proper name instead of "Virtual assistant": A name gives the customer something to address ("Hi Luna, I have a question") instead of talking to an anonymous entity: a small difference, but in the writer's experience it changes the tone of the whole conversation, making it feel more like writing to a person at the company than filling out a form.

If you leave the name empty: the bot introduces itself with your business name — the one in Settings → General — and keeps following it even if you change it later. The field shows it in grey as a hint: while it stays grey the field is empty and the name comes from there. Type something in and you pick a name of your own, which stays until you empty the field again.

How to configure it best: A short, easy-to-say name. A square, simple logo that stays readable even very small: the chat button icon is tiny, a logo with too much detail or small text gets completely lost at that size.

Colors

Sabriel AI → Customization

What it does: The primary color tints the chat header, the button, and the bot's messages. The secondary is used for accents and details.

How you see it in the panel
Primary
Secondary

Why the main colors in the Free plan instead of a full theme: The main colors (primary, secondary, bot name in the header, light contrast color and background behind the logo) are enough to make the widget feel "yours" instead of a generic widget: they're the part the eye notices first. The rest of the customization (welcome bubble, PDF template) is part of the Pro plan because it requires more maintenance time from us and really only serves those who already have an established business with more precise branding needs.

How to configure it best: Use your brand colors: it's the first thing a visitor notices about the widget. The preview updates live as you change them, so try different combinations before saving. Avoid colors that are too light for the main one: the bot messages' white text must remain readable over it.

Welcome bubble

Sabriel AI → Customization

What it does: A small speech bubble with a message that appears next to the chat button, to grab attention even before the visitor clicks.

How your customers see it
Hi! I'm Sabriel AI, always online and ready to help you.

Why it's not always the right choice: A site already rich with elements that move or appear on their own (popups, banners, notifications) risks feeling chaotic if this is added too. It's designed for the opposite case: a simple site, with normally low traffic, where the widget alone might go unnoticed without a visual cue.

How to configure it best: Useful on sites with low traffic. A 10-15 second wait before hiding it is a good balance: enough to be noticed, not so much that it becomes annoying for those who stay longer on the page.

Proactive Trigger: open the chat on its own instead of hiding the message

Why this is off by default: A widget that opens on its own, without anyone asking for it, can feel intrusive on many sites: it's worth trying for a period and observing whether started conversations increase or decrease, not something to turn on blindly.

The contract clauses on the quote

Sabriel AI \u{2192} Customization \u{2192} Quote template

What they are: every quote the bot produces has a page of its own for the terms, and that page is written by you. Each clause is made of a title and a text, and you can add as many as you like: they wrap and break onto a new page by themselves when they are long. Below the clauses come the links to your privacy policy and your terms, and on the last page the space for date and signature.

The ones already written are not legal advice: the plugin proposes a few generic ones because a quote with no terms is worse than one with imperfect terms. They are a starting point, not a text tailored to you: before using them with paying customers have a consultant or a lawyer read them, because the document your customer signs is sent by you, not by us.

If you leave them empty: the terms page is not printed at all and the quote stays two pages long. An empty page with only the heading never comes out.

If you already have terms of sale on your site, copy them here instead of rewriting them: that way the customer reads the same thing in the PDF and on the page, and you don't end up with two versions that drift apart over time.

Advanced CSS

Sabriel AI \u{2192} Customization

What it is for: a box where you write style rules of your own, for the adjustments the colors and shapes above don't cover: moving the widget higher, changing a radius, hiding a piece. What you write is loaded after the plugin's own style, so it wins over it.

When it is NOT needed: almost always. Colors, button shape, icon and bubble are changed from the fields above without writing anything, and they stay put when the plugin updates. Hand-written CSS, on the other hand, can stop working if the structure of the widget changes one day: use it for what can't be done otherwise, not as a first route.

Reset does not delete it: the button that returns the appearance to its starting values clears colors, font, shape and icon, but leaves your CSS, the bot name and the logo alone. If you want it gone, empty the box yourself.

Quote PDF template

Sabriel AI → Customization → Quote template

What it does: Logo, colors, font, and Privacy/Terms links printed on every downloadable quote.

How the customer sees it
Sabriel Agency
Quote #0042
Total: 1,450 €

Prefix before the number: The two or three letters that appear before the number on every quote, for example ROSSI-2026-0001. Put your business initials there: they are what the customer finds in the file name and on the document you send. If you leave it empty the plugin uses a neutral one, which works but says nothing about you.

Why the Privacy/Terms links are here and not optional: A quote that the customer signs or accepts is, to all effects, a pre-contractual document: showing where to find the terms before they accept is good commercial transparency practice, as well as often a requirement under your country's trade regulations (this isn't legal advice, but a practical recommendation).

How to configure it best: Match the colors with the visual identity already chosen above, for consistency between widget and document: a customer receiving a PDF with completely different colors from what they saw in chat might think for a moment they got the wrong document.

Settings → General

Your business details. They are not decoration: the bot reads them on every reply and uses them to introduce itself, to say how you can be contacted and to fill in the header and footer of the PDFs it sends to customers.

Who you are and how to reach you

Sabriel AI → Settings → General

What it does: Business name, owner's name, tagline, support email, phone, WhatsApp number and website. The business name appears at the top of every PDF page, the email and phone in the «how to proceed» boxes of the quotes, the WhatsApp number in the button the visitor sees when the bot hands over to a person.

Good to know: The WhatsApp number must be written with the international prefix and without the plus sign: that is the format WhatsApp expects, and with the plus the button leads to a non-existent number. The phone, instead, is written out in full, as on a business card: that one is only meant to be read.

How to set it up best: Fill in at least the business name, the support email and the website: those three end up everywhere. If you leave the support email empty the plugin uses the WordPress administrator's one, which is often not the address you want customers to write to.

Address, VAT number, year founded, service area

Sabriel AI → Settings → General

What it does: They are all optional. Address and VAT number appear in the footer of the PDFs, where people usually expect to find them. Year founded and service area let the bot answer questions like «how long have you been working?» or «do you also work outside the area?» without making anything up.

How to set it up best: If you only work remotely, write it in the service area instead of leaving it empty: the bot stops answering vaguely about the area and says it plainly. If you have no VAT number, leave the field empty: the footer closes up by itself with no gaps.

Settings → Service price list

The list of what you sell, with prices. It is the tab that decides the quality of the quotes: the bot does not invent figures, it takes these.

The price list rows

Sabriel AI → Settings → Price list

What it does: Each row has a name, a price and a short description. The bot reads them all in every conversation: it uses them to answer «how much does it cost?» and to build the line items of the PDF quote.

Good to know: The price is a text field, not a number: you can write «from 900», «1,200 – 1,800», «on request». The bot reports it exactly as you wrote it, and when it has to add things up it takes the first amount it finds. Writing a range is perfectly fine; writing two figures without explaining which is which is not.

How to set it up best: A few clear rows beat twenty rows that look alike: the bot has to be able to tell one service from another. In the description write what is included, not adjectives: that is the part the bot repeats to the customer when asked the difference between two items. If you would rather not show prices in the chat, leave the list empty: the bot says so instead of improvising.

Behavior

The most important section for the bot's "education": here you write how it should talk, not what it sells. Every field in here ends up in the instructions the bot reads with every single response it gives: it's the part closest to "how one of your employees would behave on their first day if you yourself explained how to talk to customers".

The average customer writes quickly and imprecisely, the bot still stays impeccable even with the fields below the base values: the most delicate behaviors (when to offer a quote, when to book, when to hand off to a human contact, how to handle awkward pricing questions) are already solidly written into the bot's base functioning, even BEFORE you write anything here. These fields further customize the tone, you're not building safe behavior from scratch, that already exists; you're adjusting the personality on top of a base that holds regardless.

Which alphabets the name comes out in on the quote

What happens: the quote PDF writes the customer's name exactly as they typed it. The characters it can draw are the Latin alphabet (accents included), its Central and Eastern European extension, Cyrillic, Greek, Hebrew, Arabic, Armenian and Georgian.

Where it does not reach: Chinese, Japanese, Korean, Thai and Hindi. A name written in these scripts comes out blank in the document, with no error message: the rest of the quote is fine. It is not a fault to report to support, it is a known limit — a font containing even just Chinese weighs more than half the plugin on its own, and every customer would download it for a rare case.

What to do if it happens: open the quote from the panel and rewrite the name in our script, the way the customer would on a local document. The quote number, the prices and the terms are untouched.

Quote number and corrections

How numbering works: every quote the bot generates gets a running number per year, with the prefix you choose (for example SAB-2026-0001). The number is assigned when the client downloads the PDF, not before: if a client asks for a quote and then does not download it, that number is not burned.

If the client corrects themselves: when right afterwards they say for example «I got it wrong, add the product upload too», the bot understands it is a correction and does NOT create a second document. It regenerates the same quote with the exact same number, the new PDF takes the place of the old one and the old file is no longer downloadable. In the Dashboard one card remains, with the orange MODIFIED tag and the reason written underneath, and you get an email titled Quote MODIFIED by the client.

If instead they ask for a different service: that is a document of its own and takes the next number, as it should.

The grey POSSIBLY A CORRECTION tag: if the client closes the page and comes back later, the browser no longer knows which quote they were correcting. In that case a new document with a new number comes out, but the reason the client wrote is not thrown away: the card in the Dashboard gets a grey tag and a line warning you it might be a duplicate, so you look with your own eyes and decide whether to delete one.

Corrections count towards the daily limit: a correction uses up one slot of the per-email quote limit, exactly like a new quote. It is deliberate: it stops anyone amusing themselves by having documents regenerated over and over.

Moving or cancelling an appointment

How it happens: when a client asks in chat to move or cancel, the bot touches nothing there and then: it sends an email with a personal link to the address they booked with, not the one they type in chat. It is a security choice: without it, anyone who knew a client's email could cancel their appointment.

If the email does not go out: the bot tells the client and gives them your support address, instead of answering check your inbox for a message that never left. Almost always the cause is the WordPress email configuration, not the plugin: the technical reason is in System status, on the last sending error line, and the usual fix is installing an SMTP plugin.

If there is no appointment: this happens when the client types an address in chat different from the one they booked with. Here too the bot says so clearly instead of leaving them waiting.

Who actually makes the change: The bot does not move or cancel anything by itself: it only sends the link. It is the client who completes the operation with one click inside the email, and until that click the appointment stays as it was. If they have lost the email they can ask in chat to have it sent again, and the bot really does it: the link is always the same and leads to the page where they see the date and time of their appointment and decide what to do with it.

Before opening the bot to real clients, send yourself a test email from the button in System status. If that does not arrive, the links to move appointments will not arrive either.

Bot behavior and tone

Sabriel AI → Settings → Behavior

What it does: The description, written in your own words, of how the bot should talk: how formal it is, what to emphasize, phrases to avoid or use, how to handle specific requests from your industry.

Why the quality of this text matters more than any other field: A vague instruction ("be professional") gives the bot nothing specific to YOUR field to base itself on: it stays generic, and sounds like any other virtual assistant. A concrete instruction ("never use the word 'cheap', let's say 'affordable'; if they ask for a discount, reply that our prices are already calculated to the minimum to guarantee work quality") gives the bot a real distinctive character, that sounds like YOUR business and not like any old chatbot.

How to configure it best: Write it as you'd explain it to a new colleague on their first day of work: simple sentences, no need for technical language. Think of the 3-4 questions you get most often and how you'd want them handled, write them here explicitly instead of hoping the bot will "figure it out on its own". The presets for business type fill the field with an already-written starting point: start with one close to your field and edit it with your business's real details, instead of writing everything from scratch or leaving it generic.

Bot language

Sabriel AI → Settings → Behavior

What it does: The language your bot speaks to your customers in: the wording of the widget and the first greeting, and — depending on the switch below — the language it replies in during the chat.

How you see it in the panel
The bot speaks every language

Why "on" is almost always the right advice: Imagine a German tourist writing in German to your Italian bot: with this on, the bot replies in German, which is the natural and welcoming experience. If you turn it off, the bot always replies only in the language you chose above, even to those writing in another one.

How to set it up best: Leave it on (it is the default): the bot adapts by itself to the customer's language, whatever it is, even one that is not among the nine in the list. Turn it off only if you have a specific reason to want replies always in the same language.

The language chosen above still counts in both cases: it always decides the language of the buttons, the calendar and the widget labels, and the language the bot greets in first. The switch only concerns which language the bot replies in.
With the switch on, the bot follows the customer's language from their very first message, even if it is just a «hello». The language chosen above stays as the fallback and is used only when the message makes it impossible to tell which language it is written in (digits only, emoji only, or mixed languages): never a random one. With the switch off there is no way round it: the assistant answers in the language chosen above and in that one only. A customer who writes in another language, and even one who asks it outright to switch, gets a polite line back in the chosen language saying that here it only answers in this one, and then the conversation carries on. Asked which languages it speaks, it says what is true of this site: at the moment, only that one.
The same rule also covers what the bot writes inside the appointment and inside the quote: the appointment reason and the title, the line items and the description of the PDF come out in the language of the conversation, because it is the customer who reads them in the confirmation card and in the document.

How far ahead they can book

The rule: your customers can book an appointment up to 24 months from today. Past that date the calendar stops turning and, if someone tries anyway, the bot replies with the last available day.

Why there is a limit: before, there wasn't one and you could book for any future date at all, even a hundred years out. You didn't even need to keep clicking through the calendar: when the bot books the appointment by itself, it is the bot that writes the date, and one wrong year is enough to leave in your diary an appointment nobody will ever honour — with the confirmation email already gone to the customer.

It does not apply to you: from the «New appointment» page in the panel you write whatever date you want, with no limit at all. The cap only concerns people booking from outside.

Appointment capacity

Sabriel AI → Settings → Behavior

First thing to know: The appointment duration sets the calendar's step. Choose 60 and customers see 09:00, 10:00, 11:00; choose 45 and they see 09:00, 09:45, 10:30. Everything else on this page is counted against that duration.

How long an appointment lasts: the menu holds the most common durations, from 15 to 120 minutes. If you need something else pick «Other» and a box appears where you type the minutes you want: for a 4-hour appointment type 240, for a whole day 480. It accepts 5 to 1440 minutes, and while you type it shows alongside how many hours that is. On a fresh install it starts at 30 and a yellow notice above the fields reminds you: it disappears by itself as soon as you choose a different duration.

You don't need a field for breaks: if you need time between two customers to clean up, travel or catch your breath, put it inside the duration. A 45-minute appointment plus 15 minutes of break: type 60. The calendar offers 09:00, 10:00, 11:00 and you have your quarter of an hour. There is deliberately no separate field for breaks, because it would do the same thing in a more confusing way.

Appointments per slot: how many people can book the exact same time before that time counts as full. With 1 you work one at a time; with 3 you take three people at 10:00, like a restaurant setting several tables for the same hour.

An appointment never runs past closing time: the calendar only offers a time if the whole appointment fits inside the opening window. If you close at 22:00 and an appointment lasts 4 hours, the last time offered is 18:00, not 22:00. You do not have to work it out yourself: the blue box below the fields tells you, day by day, what the last start time is with the duration you have set right now.

If a time band is shorter than one appointment: that day cannot offer a single time. With 90-minute appointments, a 12:00 - 13:00 band does not fit and disappears from the calendar. It does not happen silently: a red notice appears with the list of affected days.

If customers complain that the calendar always looks full, check the duration first: the longer it is, the fewer times fit into the day. The blue box shows it right away with your numbers.
Bookable times start from the opening time and move on one duration at a time: if you open at 09:20 with 30-minute appointments, they are 09:20, 09:50, 10:20 and so on. If a customer asks for a time that is already taken, or one where a whole appointment does not fit, the bot says so straight away and offers the times still free to choose from — without first asking for a name, a reason or how many people, only to say no afterwards. The free times for today and tomorrow are worked out by the plugin, so it cannot get them wrong.

Opening hours

Sabriel AI → Settings → Behavior

What it does: Two distinct and independent things: (1) it calculates the REAL available times in the booking calendar, if you say Tuesday you're closed, the bot will never offer a Tuesday as an option to someone wanting to book; (2) it lets the bot know, in ANY conversation (even without talking about bookings), whether the business is open or closed right at this moment.

How you see it in the panel
Monday

Why the second use counts as much as the first: A customer writing at 11pm asking "can I come now?" deserves an answer that takes reality into account: if the bot didn't know the hours, it might answer ambiguously or assume you're always open. With hours configured, the bot can naturally say "we're closed right now, we reopen tomorrow at 9" instead of leaving the customer confused.

⚠️ On a fresh install the opening hours are deliberately EMPTY: any preset schedule would be wrong for most businesses, and the bot would tell your customers it was true. Until you set your own, the calendar offers no slots, the bot books no appointments and refers people to your direct contact, and System Status keeps a red light on this item. Set them as soon as you install the plugin, especially if you work evenings, weekends, or close on a weekday.

If you work past midnight: go ahead and enter a shift that runs past midnight, for example from 22:00 to 02:00. When you save, the plugin splits it into two pieces by itself (the evening of that day and the night of the next), and tells you so. This is needed because an appointment at one in the morning belongs to the following day: without the split it would land in your calendar with the wrong date, and the client would get that same wrong date in the confirmation email.

How to configure it best: Fully turn off closed days (use the "Open" checkbox, don't just leave times at zero): a day marked as closed is completely excluded from the calendar, while a day left "open" by mistake with random hours could still offer slots that don't really exist.

A shift running past midnight is still stored split in two (the calendar needs it that way, otherwise the bookable times come out wrong) but the bot no longer reads it out split: it says «Monday 15:00-02:00», not «Monday until 00:00» and «Tuesday from 00:00», which made customers think you close at midnight.

Payment structure and installments

Sabriel AI → Settings → Behavior

If the next day is closed, we open it just for the tail: a shift like Friday 22:00 → 02:00 ends on Saturday. If Saturday is switched off, the plugin now opens it with that tail alone (00:00 → 02:00) and tells you so with a note. Before, the tail was discarded: between midnight and two the bot answered "we are closed" while the place was still full. ⚠ Saturday does not become an opening day: in the chat the bot keeps saying Saturday is closed and shows the shift on Friday. The only thing that changes is the answer to "are you open right now?" — and, in the complete edition, which hours can be booked. Those hours also become bookable in the calendar, because at that time you really are open.

What it does: How the payment request for a project is split (deposit, halfway through the work, on final delivery) and whether to offer installments from an amount threshold you choose upwards. The bot uses this structure both when discussing it in chat and when generating a PDF quote.

How you see it in the panel
25%
25%
50%
Deposit
Halfway
On delivery

Why the percentages must add up to exactly 100: The bot uses these percentages to work out REAL amounts, in the currency you chose, inside the quotes it generates: if they added up to, say, 90 instead of 100, a tenth of the agreed price would simply vanish from the calculation, and nobody would notice until it was time to collect that missing part.

Why installments are off by default and should be turned on carefully: When this feature is on, the bot promises the customer the possibility of paying in installments: it's a real commercial promise, not a decorative option. If you don't actually handle installment payments, a customer expecting this possibility after the bot proposed it might end up disappointed or confused when they find out it's not really available.

What the bot actually says about instalments: The threshold is a minimum and it counts as included: a project priced at exactly that figure already qualifies, and on the quote PDF the instalments line appears from that figure upwards. From there up the bot puts the two routes on the table together, the standard split or the instalment plan, as equal choices for the customer to pick from rather than one of them as a fallback. Below the threshold the bot says plainly that it is not reached and the standard split stands. It never invents how many instalments there are, of what size, or over how long, because the plugin never asks you for those: if the customer asks, the bot says the plan is agreed with you directly and points them to contact.

How to configure it best: The percentages together must add up to 100%. If you never work with a halfway intermediate payment, leave that field empty or at zero: it's not mandatory to split it into three parts, you can use just deposit and final balance. Turn on installments only if you actually offer them in practice.

Password-protected content

What it does: If you have put a password on a page, a post or a portfolio item, the bot does not show it: it never appears among the examples in chat, and it is not offered in the list of pages you can teach the bot in Site knowledge.

Why it matters: in WordPress, protected content is still «published», so without this rule it would have ended up in the cards the bot shows visitors — title, image and link — precisely for the things you deliberately locked: a case study reserved for one client, a price list for a few.

Good to know: if you had already ticked a protected page in Site knowledge, the tick stays where it is and is not removed, but that page no longer reaches the bot. If that content is meant to be public, remove the password: from that moment the bot starts using it again.

One active appointment at a time

How it works: The same email address cannot hold two upcoming appointments at once. If a client who already has one tries to book another, the bot does not create a second: it emails them the link to move or cancel the one they already have. This applies both from the chat and from the link received by email.

What it does NOT block: past appointments, cancelled ones, declined ones and the ones you marked as done do not count. A regular client can therefore book again right after visiting you: the block only concerns the future.

Why it exists: without this rule, one distracted client — or a form sent twice — was enough to fill your calendar with duplicate appointments for the same person. If you really need to give them two, you enter them yourself from the «New appointment» page: this limit does not apply there.

High amount alert

Sabriel AI → Settings → Behavior

What it does: Enter an amount and every quote the bot prepares above that amount reaches you marked «HIGH AMOUNT WARNING» in the email, and also shows up flagged in the Dashboard. The quote is still prepared and delivered to the client: this is a heads-up for you, not a block.

What it is really for: it is a safety net for the rare case where someone tries to make the bot write an out-of-scale figure. The bot takes prices from your price list and does not invent them, but on a commercial document that carries your name it is better to notice straight away than to hear it from a client.

How to configure it best: set it a little above your largest typical quote, so it does not warn you about normal jobs. Leaving it empty means you never get this alert.

Allowed topics (off-topic conversations)

Sabriel AI → Settings → Behavior

What it does: By default the bot stays focused on your services: it politely declines questions unrelated to your work — general knowledge, school homework, off-topic requests — and never reveals what technology it is built on, only its name. Turning this switch on makes the bot more permissive, so it can also chat about topics unrelated to your business.

Why it is off by default: a bot that answers everything gets used as a free assistant by people who are not your clients, and you pay the AI engine for every answer. Off, almost every business is better served.

The bot works out on its own when a request is not your trade. It tells from «What kind of business are you» and from the price list: if you run a restaurant and someone asks for a website, it says so kindly and offers neither appointments nor quotes for something you do not do. You do not have to write «we don't do this» in the behaviour field yourself. If instead the request plausibly is your line of work but is not on the list, it asks one or two questions and passes your contact along, without ever inventing a price.

Collect visit statistics

Sabriel AI → Settings → Modules and limits

What it does: To count returning visitors without using cookies, the widget derives a short code from the visitor's browser (screen size, language, time zone and the like) and sends it along with the page address. Nothing leaves your site and no cookie is written.

⚠️ In the European Union, reading this information from the browser counts as accessing the device: if you do not ask visitors for consent, turn this switch off. It is the safest choice, and the chat keeps working exactly as before.

What stops working when it is off: nothing is collected any more, and along with the statistics the Thermometer's contact scoring also switches off, since it needs that data to tell which visitors are most interested. Appointments, quotes, site check and chat do not change one bit.

The message that reaches you without going through the bot

How it works: when the bot works out that a real person is needed, instead of carrying on answering it shows your contact details — WhatsApp, email and phone, whichever you filled in — and below them a box where the visitor can write their message and send it to you straight away. That message arrives in your contact inbox with the name, address and phone number of whoever wrote it, and it uses no AI request at all.

Why it matters: it is the way out for the visitor who does not want to talk to a bot. Without it the only option would be closing the chat and hunting for contact details on the site, and at that point most people simply leave.

What you see: an ordinary email, as if it had been written to you from the contact form. If it doesn't arrive, the problem is almost always the site's email sending: you test that from the button in System status.

Conversation history

The text of a conversation is never shortened: whatever was written stays there, from the first message to the last. What does have a limit is something else, and there are three separate things that are easy to mistake for a cut.

1. After five minutes of silence a new conversation begins. If the visitor stops and picks up again later, the history shows two entries instead of one. Nothing has been lost: they are two conversations, and in the new one the bot still remembers the earlier ones from the same address.

2. The last thirty conversations are kept. When the thirty-first arrives, the oldest one drops out. The cap exists because the history lives in the visitor's browser storage, which is small and shared with everything else on the site: without a limit it would fill up and stop saving the very conversation in progress. Thirty conversations are far more than a real visitor ever has, and the copy kept on the site follows the same number.

3. The bot remembers the last sixty exchanges. In a very long conversation it may forget how things started, but the text stays written and readable: it is its memory that stops there, not the history.

If browser storage is full: the plugin makes room on its own by discarding the oldest conversations and keeping the one in progress, which is the only one that cannot be recovered. If even that is not enough, the visitor gets a notice in the chat instead of carrying on believing everything is being saved.

Voice messages in chat

What it does: Next to the box where people type, inside the widget, there is a microphone button: visitors can speak instead of typing and their words appear written in the box. Handy on a phone, and for anyone who struggles to type.

Where the voice ends up: nowhere. The speech-to-text conversion is done by the visitor's browser, on their own device: no audio file leaves your site, nothing is saved, and the bot only receives the text, as if it had been typed. No recording is ever sent to the AI engine.

Good to know: it is not a plugin feature but a browser one, so the button works where the browser allows it (recent Chrome, Edge, Safari) and stays quiet elsewhere — in that case the visitor simply types. The first time, the browser asks permission for the microphone: if the visitor denies it, the chat just says so. You can change the microphone colour while recording under Customisation.

Currency

Sabriel AI → Settings → Behavior

What it does: Sets the currency used in the prices the customer sees, both in the PDF quotes and when the bot writes an amount in chat. Choose among the most common currencies or enter a custom one, and decide whether the symbol goes after the amount (1,200 €) or before ($1,200). The default is Euro.

How to configure it best: Choose the currency you actually work in and write the price list in that same currency: the bot will use the symbol you set here, but the figures stay the ones you write in the price list. If your currency is not in the list, use custom and enter code and symbol by hand.

Settings → Pages

Where the bot finds links to share and where it takes examples of work/products from: two different ways of connecting the bot to content that already exists on your site, instead of having to rewrite it by hand.

Work examples shown in chat

Sabriel AI → Settings → Pages

What it does: When a client asks to see work, products or projects already done, the bot shows a few cards inside the conversation. Here you decide where it takes them from, among five possible sources.

List you write yourself: the table at the bottom of the Pages tab, where you write each work with name, type, keywords, image and link. It is the way that always works, with any theme or page builder, even when the portfolio is a page written in HTML inside a code block: that content cannot be read from the outside, but a list written here can. If you fill in this table, the bot uses it and ignores the other sources. The work name is required: rows without a name are not saved, and after saving the panel tells you how many works it actually recorded.

Don't want to write it by hand: the «Read the page and fill the table» button downloads a page of your site the way a visitor sees it, works out the projects and adds the rows at the bottom of the table, without touching the ones you already wrote. Then you correct whatever you want and save. If it finds no work on the page it tells you in plain words.

The other four sources: WooCommerce products; the theme portfolio, that is the «Portfolio» or «Projects» entry many themes add to the WordPress menu, which the plugin recognises on its own even when the theme gives it a name of its own; the portfolio page listed in the links table, which is read automatically; and as a last resort the blog posts with a featured image, which however are not work samples. From the page the plugin also picks up the link of the single work, when there is one: this way the card in the chat opens the project and not the general page.

Real work, products and articles are not the same thing: Only three sources contain work done for clients: the list you write yourself, the theme portfolio and the portfolio page. Shop products and blog articles do not, and the bot really knows it: with either of those two sources it never says it can show you work, it does not promise it and it does not do it even if the customer insists or accepts an offer. It shows them only for what they are, products or articles, and only when the customer asks for that exact kind of product or topic. If the customer asks for something that is not in there, the bot says so instead of showing something else instead.

The portfolio page is re-read on its own: once it has been read, the plugin remembers the page and never forgets it. When the list gets old it re-reads it in the background and meanwhile keeps using the last real list, so the bot never ends up saying you have no work just because the reading had expired. The very first reading happens shortly after you connect the page: until it is finished the bot does not promise samples, because it does not yet know what is in there.

Automatic or one specific source: with «Automatic» the bot tries the sources in order and uses the first one that has something in it. If you pin one instead, it uses only that: if it is empty it shows nothing and does not quietly fall back to the blog. The coloured boxes above the dropdown tell you at a glance which sources exist on your site and which one it is using right now.

If the module is off or the licence has run out: the bot shows no cards at all, not even an empty one. It does keep mentioning the link to your portfolio page as usual, if you put one in the links table. What you wrote here stays saved and works again as soon as you switch the module back on or renew the licence.

How your customers see the gallery in chat
Sure, here are some examples of our work

Why you need to choose a source instead of "putting everything together": A site that has BOTH a WooCommerce shop AND a blog with photos of past projects generates two possible different galleries: mixing them would confuse the customer about what they're really looking at (a product for sale now, or an inspirational example of past work). The automatic source tries the options in a priority order that's sensible for most sites; fixing one by hand removes all ambiguity.

How to configure it best: Automatic works well for most sites with ONE main content source. Fix a specific source only if the site has multiple possible sources together and you want to be 100% sure which one is always shown, regardless of what automatic would have chosen.

The cards the bot shows in the chat come from the shop, from the blog or from the list you write yourself — not from the service list, which is a different thing. If a dish or a product is only written in the service list, the bot can talk about it and give its price but has no card to show you: in that case it says so, instead of showing you something else that looks similar. Of the products it shows you in the chat, on the other hand, the bot also knows the price and the variants, so if you then ask what that dish contains or what colours that shirt comes in, it can answer. This works for the whole shop, without ticking anything here: the cards are searched in the catalogue on the spot and are not subject to the 40-page limit.

Site knowledge

A paid-plan feature. On the free plan the menu does not appear and the bot receives no page content.

Here you decide which pages of your site the bot should really know. That is the difference between a bot that knows where a page is and one that knows what is written in it.

What it does, and how it differs from «Links to pages»

Sabriel AI → Knowledge

What it does: Pick the pages with a tick and press «Have the bot read the pages». The bot reads them one by one and writes a summary for each, which you see straight away in the right-hand column: that way you check with your own eyes what it understood. From then on the bot knows what each of those pages is about and can send the customer there. How much detail it has depends on the choice below: with «Summary only» it answers broadly and points to the page, with «Summary plus the text of the page that fits» it answers with what is actually written.

How it differs from «Links to pages»: The two complement each other and work best together. «Links to pages» gives the bot the address to share: it knows a Services page exists and can send you there. «Knowledge» makes it read the text of that page: it knows what you offer, at what price and in what time, and can answer without making the customer open the link.

The same question, before and after
Do you also provide support after delivery?
Without Knowledge: «You will find all the details on the Services page» + link.
With Site knowledge, in the complete mode: «Yes, three months of support are included, then it can be renewed. Shall I prepare a quote for you?»
If the site runs WooCommerce, for every product you tick the bot also receives the product sheet: variants and attributes (with sauce / without sauce, black / white, size), tags, categories, price, code and stock. That is what lets it answer «do you have dishes without sauce?» or «I'd like a black hoodie» instead of listing everything. Before, it only read the description written on the product page.

It updates itself

If you edit a page you had selected, the summary goes stale and the bot redoes it by itself after a few minutes. You do not have to remember to come back here. If you do not want to wait, open this page and press the button again: it immediately rereads the changed ones and leaves the others alone.

It works the other way round too: if you move a selected page to the trash, set it to draft or delete it, the bot immediately stops mentioning it and stops giving its link. If you restore it from the trash it comes back into the knowledge on its own, without you having to select it again.

What it costs: Reading a page is a single request to the AI engine, and it only happens again when that page changes. With «Summary only» the weight on everyday conversations is small, because the summaries are deliberately short. With «Summary plus the text of the page that fits» the text of a page is added only on the messages where a matching one is found: on the others the weight stays the same.

The words customers use to find a page

In the “summary plus the text of the page that fits” mode, for every question the bot has to work out which of your pages is relevant. It does that by matching words. The problem is that customers use different words from yours: you write “ecommerce” and they ask for “online store”.

That is why, while reading a page, the bot also prepares a list of words that make it findable: the different ways of saying the same thing, the common names of the services, the problems they solve. It costs nothing extra, because it writes them at the same moment as the summary. From then on “online store” finds the page that only says “ecommerce”.

You can correct them yourself: open “More details” on a page and you will find them at the bottom, under the summary. Add the words your customers actually use when they ask, separated by commas. What you write wins and is never redone on its own, exactly as with the summary.

From then on, scrolling through the list of pages, a green mark appears next to “More details” on the ones you have edited by hand: one for the summary and one for the words. Opening the page, under the box you find exactly what you added and what you removed compared with the ones the bot prepared, so months later you recognise your own work without having to remember it.

The “Back to the bot's words” button restores exactly the words it had written: they are kept, so the restore is instant and does not re-read the page. And if you type its own words back in by hand, the green mark disappears on its own, because nothing of yours is left.

The same goes for the summary: the «Restore the bot's version» button puts back exactly the summary it had written, the one shown in the «Your changes to this page» box. It is instant, it does not make the page be read again and it costs no request to the engine. The only case in which the page is read again is if you had corrected that summary before the plugin started keeping the bot's version: there is nothing to put back then, so it writes it again. The confirmation message tells you which case you are in.

Has the bot really read this sentence?

Sometimes you ask the bot about something written on one of your pages and it answers that it does not know. Before blaming the bot, it is worth checking whether that sentence really ended up in the text it read.

Open “More details” on the page and write the sentence in the box “Has the bot read this sentence?”. The answer is plain: if it read it, you are told where on the page it sits; if it did not, you are told where to look. You also see how many characters it read in total, so you know whether the reading stopped before the end.

If the sentence shows as read but the bot does not use it: From a long page the bot does not get everything at once, but the parts that relate to the question: it aims on its own at the most distinctive word the customer wrote, the one that appears on only a few pages of your site, and it can take two far-apart parts of the same page. If it still does not pick it up, add that word to the list “The words customers use to find this page”: from then on the page is findable with that term too.

The limits, and why they exist

Up to 40 pages. This is not a commercial limit, it is a technical choice. Everything the bot has to keep in mind is repeated to it with every single message: loading it with a hundred pages would not make it learn more, it would make it forget the other instructions, preparing the quote, for instance, or offering the appointment. Ten well chosen pages beat a hundred random ones.

It does not make things up. The bot is explicitly told not to add anything that is not written on the pages: if the information is not there, it says so and offers to put you in touch. That is deliberate: we prefer an «I do not know» to a promise you then have to keep.

Pages with no text stay out. A page made only of images, or built entirely by a theme with no text of its own, has nothing to read: it will show as «not read yet», and that is fine.

If the button gives an error: Almost always it is the AI engine key. Go to «AI Engine», check that it is entered and valid, and try again. The plugin stops by itself instead of retrying, so it does not burn requests for nothing.

How to choose well

Start with the pages a customer reads before buying: services, prices, how you work, frequently asked questions, shipping and returns if you sell products. Skip the minor pages (legal notices, archives, old posts), that add nothing and take up room.

After the first pass, read through the summaries column: it is the quickest way to notice whether a page on your site is written confusingly. If the bot did not understand it, a customer probably does not either.

Settings → Modules and limits

Every module can be turned off completely: the bot entirely stops offering that function, as if it had never been installed. All on by default, because most businesses use them all; this page is for those who need to remove what they don't need, not to "enable" something missing.

With the free version these 8 modules are switched off: the chat works, everything else does not. On that page, in place of the toggles, you see the box to unlock them. There is nothing to configure until you activate a licence. And if the licence expires one day, the choices you made here stay exactly as you left them, they are not reset.

Module off and licence: the thing that confuses people most

Sabriel AI → Settings → Modules and limits

They are two different things: a module can be idle for two reasons that have nothing to do with each other. Either because the free licence does not include it, or because you switched it off. The first is a licence condition, the second is a choice of yours.

Why it looks like a fault: with the free licence the Dashboard cards are shown anyway, as a preview with the PRO veil, because they are there to show you what you would get by upgrading. With a Pro licence instead only the cards of the modules that are on are shown. So if you switched the toggles off while on the free licence, you do not notice: the previews are there all the same. The day you activate the licence, those cards disappear, and it looks like the update broke something. Nothing is broken: you are finally seeing the truth of the toggles.

How to tell in ten seconds: open System status, the Licence and modules section. For each module it says whether it is blocked by the licence, switched off by you, or on. That line settles every doubt without having to think about it.

Another effect of the same thing: with a module off, its page is not registered in the menu at all. If you can no longer find the Site knowledge entry in the left menu, almost always it is just its toggle being off, not an update gone wrong.

As soon as you activate a paid licence, the first thing to do is go through Modules and limits and switch on what you need. Thirty seconds that save you half an hour of doubt.

The modules that can be turned off

Sabriel AI → Settings → Modules and limits

How you see them in the panel
Bookings
Portfolio / Products

Bookings: the bot can set, reschedule, or cancel appointments in chat. Turn it off if your business doesn't handle appointments at all (a pure online shop, for example), otherwise the bot might offer to book something that doesn't make sense for you.

⚠️ When the first booking email goes out, the plugin creates a public page called “Reschedule appointment” by itself. Do not delete it and do not remove the [sabriel_reschedule] shortcode it contains: it is the page the “Reschedule or cancel appointment” buttons in every email already sent to your customers point to. You can rename it or move it wherever you like, but if you delete it those links stop working.

Quotes: generates downloadable PDF documents with a project's details. Useful for those selling customized services with a price to be agreed case by case; less relevant for those selling fixed-price products.

Thermometer: classifies every conversation as hot, warm, or cold, visible in Analytics: this always runs automatically behind the scenes, requires nothing from you; turning it off only makes sense if you don't care at all which contacts to follow up with priority.

Audit: the bot offers a free check of a potential customer's website: especially relevant for agencies and freelancers in the digital field, where it's a natural selling point; less relevant for a business not related to the web.

History: the customer retrieves past conversations even from another device, useful for purchase processes that require multiple visits over time (a customer who thinks it over for a few days before coming back). Even without this module the bot still remembers anyone who has already talked to it from the same device: what History adds is recovery from a different device, through a link sent by email.

Portfolio / Products: a single switch covers ALL sources together (WooCommerce included), turning it off turns off the entire mechanism, no second switch is needed for WooCommerce.

Site knowledge: the bot reads the pages of your site that you pick and uses what they say to answer, instead of just sending the link. See the Site knowledge section further down for how it works in full.

Mailchimp: syncs classified contacts with a Mailchimp list, only with the customer's own explicit consent. See the Mailchimp section further ahead for full operation.

Limits

What they do: They protect every feature from excessive use or automated abuse, not from a real customer using the service normally. For example, the daily message limit exists to stop an external bot trying to make your bot write thousands of times in an hour (making you spend needlessly on the AI key), not to interrupt a real conversation halfway through.

Why the base values should almost never be touched: They were designed to be broadly sufficient for a normal conversation, with margin: a real customer writing normally never reaches them. If you notice real customers being blocked, a genuine edge case (an unusually long conversation) is more likely than the value itself being too low.

How to configure them best: The base values are already balanced for the typical traffic of a small/medium site: change them only if you notice real customers blocked by mistake, or conversely clear signs of automated/abusive use (many identical requests within a few seconds, for example).

Security and cleanup

A basic package of common protections for WordPress: it doesn't replace a dedicated security plugin (Wordfence, Sucuri) if you have advanced needs like a real-time firewall or malware scanning, but it safely covers the best-known basic techniques, without needing to install anything else or set up complicated configurations.

Every protection below is REALLY connected to your site: they aren't just graphical switches. They genuinely affect WordPress's behavior: they close real protocols, send real HTTP headers, read and delete real rows from your database. All off by default: installing the plugin changes nothing about your site's behavior until you decide to turn them on.

Protections

How you see them in the panel
Limit login attempts

Disable XML-RPC: closes an old WordPress communication protocol, often the target of automated attacks (particularly mass password-guessing attempts that exploit a known weakness of this protocol). Almost no modern site really still uses it: turn it on unless you know for certain that an app or external service depends on it.

To check that it works, open yoursite.com/xmlrpc.php in a private window: it must reply “Forbidden” with error 403. With the protection on, the file is closed before WordPress replies, every command of the protocol is disabled (including the pingback one that the standard WordPress block would let through on its own, and that is exactly the one used in large scale automated attacks) and the site stops advertising its own XML-RPC address in the headers and in the page code. Turning the switch off, or deactivating the plugin, makes xmlrpc.php reachable again straight away: the block is not written into any file of your site, so it does not stay stuck there as with plugins that modify the .htaccess file.

How you know a protection is really active: under each switch there is a badge showing the real saved state: green “Protection active” if it is working right now, grey “Protection not active” if it is off. As soon as you touch the switch the badge turns orange and says “To be saved”, because until you press Save protections nothing has really changed. If you have the package without an active licence, a protection that is on tells you so clearly instead of letting you believe you are protected.

You can always go back: every protection on this page is reversible. Turning the switch off puts the site back exactly as it was before, straight away and without leaving traces: none of these protections modifies your site files (it does not touch .htaccess or wp-config.php) and none writes anything permanent to the database. They only work while the switch is on. The only irreversible thing on this page is the database Cleanup below, because it really does delete data: that one asks for confirmation before going ahead.

Security headers: adds three HTTP headers that reduce the risk of clickjacking (your site loaded hidden inside another site to steal visitors' clicks) and a common type of XSS attack. No visible effect for visitors: you can turn it on and leave it on.

Brute force protection: two scales working together, one on the connection the attempts come from and one on the account. On both: 5 errors and you take a fifteen minute pause, another five and the pause becomes an hour, another five and it closes. The connection stays out for 30 days (not for life, because addresses change and in an office or on mobile many people share a single one). The account instead stays closed until someone reopens it, but whoever owns it immediately receives an email with a link to reopen it themselves in thirty seconds, without disturbing you: the link goes ONLY to the address registered on that account, is valid once, expires, and only reopens access without letting anyone in and without changing any password. Both scales are needed: the one on the connection alone can be got around by changing network, the one on the account alone would let anyone shut you out by hammering your name. Together, whoever tries gets their connection banned before they can block anyone else's account. At the bottom of the Dashboard and at the bottom of the Security page you will find the list of everything blocked right now, connections and accounts together, including blocks of a few minutes, with the button to reopen immediately: it is the same list seen from two places. If the site email is not working, the list tells you instead of letting you believe the link went out. After twenty four hours with no errors and no blocks in progress it starts from zero again, so someone who gets it wrong twice a year does not end up banned. And so that this defence cannot be turned against you: from the browser you have already logged in from at least once the blocks do not apply, whoever is already in stays in, and in an emergency you just add the line define('SABRIEL_LOGIN_SBLOCCA', true); to wp-config.php, which turns them all off instantly. Under the bonnet, the blocks live in a table of their own in the database, not mixed in with the settings: every connection and every account has its own row, and the count of attempts is done by the database itself. This is needed because during a real attack many attempts arrive all at once: if the count were done by reading and rewriting a single list, two attempts in the same instant would be counted as one and the block would kick in later than promised. Rows that are no longer needed are thrown away on their own at regular intervals, and blocks in progress and permanent ones are never touched. Uninstalling the plugin removes the table.

After a block, it starts over: Once the 30-day block is over, that connection starts with a clean slate: it is not banned forever, but it does not become immune either, because the ladder begins again from the first step. The same applies when you reopen something from the list yourself: it starts from zero, not from where it left off.

If the limiter cannot work, it tells you: The blocks need a table of their own in the database, which the plugin creates by itself at the first opportunity. On some very restricted hosts it cannot, because the database user is not allowed to create new tables or because the disk space has run out. In that case the limiter cannot record anything and so it does not protect: rather than letting you believe otherwise, the plugin writes it in red at the top of the Security page, and the badge under the switch turns red instead of green. The plugin tries again by itself to create the table every time you open that page, so as soon as the host fixes the permission it starts working again with nothing for you to do.

Testing the blocks without waiting for hours: If you want to see for yourself how the limiter behaves, adding the line define('SABRIEL_LOGIN_PROVA', true); to wp-config.php makes the pauses last 20 and 40 seconds instead of a quarter of an hour and an hour, and the connection block last 60 seconds instead of 30 days. It is only for testing: as long as that line is there, a red warning appears at the top of the Security page to remind you, so it cannot stay on by mistake on a real site. Remove the line and everything goes back to the normal durations. The account’s final block stays permanent instead, just as on a real site: otherwise the unlock link email could not be tested.

The secret address is checked: The address you choose is checked before it is saved. If it is an address WordPress already uses for itself (such as wp-admin), or if it already belongs to a page of your site, it is not saved and you are told: in the first case your panel would break, in the second that page would disappear from the site to make room for the login form, and both are problems you find out about late. The registration page instead follows the site setting: if you have turned on «Anyone can register» under Settings → General it stays reachable, otherwise it stays hidden like the rest.

Seeing where the ladder stands: In the list you also see whoever is not blocked but already has some failed attempts behind them, with how many attempts are left before the next block. It is needed because after a pause the count restarts from zero and the next block arrives at the fifth failed attempt from that moment: without seeing it, the block seems to snap shut at random after a single mistake. Remember too that connection and account are two separate brakes that each count on their own, so reopening only one of them leaves the other where it was and it can stop access anyway: when that happens the panel tells you. If you want to truly start from zero, the «Clear all login blocks» button removes everything at once, permanent ones included.

If the unlock link does not arrive: The panel tells you whether the link was handed to the site’s mail, which is not the same as «arrived»: from that point on the message no longer depends on the plugin. If it does not arrive, almost always it is the site failing to get its own emails accepted, and you check that under System status → Email sending. That is why next to every closed account there is a «Send the link again» button: the first email goes out by itself at the moment of the block, and if that one gets lost, without this button there would be no way to have another sent. The new link replaces the old one, which stops working from then on, and always goes only to the address registered on that account: from the panel you decide when to resend it, never to whom.

Hide WordPress version: removes the version number from the site's public code: an attacker uses it to know if you're using an old version with vulnerabilities already known and already fixed in newer versions.

Blocking username discovery: a single switch that closes all four routes through which someone can find out what the users of your site are called. The first is the best known trick, visiting an address like ?author=1. The second is the user list that WordPress exposes by default on the API (/wp-json/wp/v2/users), readable even by someone who is not logged in. The third is the site map of authors, which WordPress publishes on its own. The fourth, the least known, is the reply the site gives when someone shares one of your pages: inside it there is the name of the author, which on very many sites is the username or even the email address. Knowing a valid username is the first step of a brute force attack aimed at that account. None of this touches how the site works for someone already logged in, and share previews keep working: the only change is that the name of the site appears instead of the name of the person. It disappears from the index of sitemaps and, if someone tries to ask for it anyway by typing the address by hand, it replies “page not found” instead of showing the home page, as WordPress left to itself would do.

Generic login error message: by default, WordPress EXPLICITLY says whether you got the password OR the username wrong: a detail that confirms to someone attempting an attack that this username really exists on the site, narrowing down the work left for them to do. With this on, the error becomes just one, always identical, without confirming anything about what exactly was wrong.

Disable file editor from wp-admin: prevents editing theme and plugin PHP files directly from the panel. The reason isn't to stop YOU from working: it's that if someone still managed to get unauthorized admin access, they couldn't use this specific route to insert malicious code directly into the site's files.

Hide the WordPress readme and licence files: blocks public access to the WordPress readme.html and license.txt files, which by default anyone can read and which reveal which version you are running: the first thing someone looking for a site to attack checks.

On some servers these files are delivered straight by the web server, without going through WordPress: in that case no plugin can stop them, and promising you otherwise would be a lie. That is why the plugin tries to download them itself and, if it succeeds, it tells you plainly and gives you the rule to pass on to your host's support team.

Hide the login page: moves the login page to an address of your choosing. Anyone trying the usual addresses gets a "page not found" and cannot even tell that the site is built with WordPress. This is the protection that on its own stops most automated password-guessing attempts, because those programs always knock on the same door.

Which secret addresses cannot be used: The address you choose is checked before being saved. If it is one WordPress already uses itself (wp-admin, wp-json, feed and the like) it is rejected: using it would lock you out of the panel. It is also rejected if it is already the address of a page, a post or a product on your site, because that page would disappear for visitors and the login screen would show up in its place. In both cases the protection is switched off and you are told why, instead of being left with a broken site and no explanation. The check is repeated every time the Security page is opened, so if one day you create a page named like your secret address you notice straight away.

⚠️ Write your secret address down somewhere before you turn this on, and try it out straight away in a separate window. If you forget it, you have not lost the site: ask whoever manages your hosting to add one line to the wp-config.php file, define( 'SABRIEL_LOGIN_HIDE_OFF', true );, the login page becomes reachable again immediately, just as before. Deactivating the plugin from the plugins folder also puts it back as it was.

Database cleanup: shows how many "waste" items have accumulated over time (revisions, autosave drafts, trash, spam comments, expired temporary data) with a button to delete them in one click, plus an option to optimize (defragment, without deleting anything) the database tables. Periodic cleanup every 1-2 months keeps the site lighter and more responsive, especially on sites with lots of content or traffic.

Automatic cleanup: under the cleanup table you will find “How often do you want to clean up automatically?”. There is only one table and it serves both purposes: you tick the items you want, then the black “Clean now” button cleans them straight away, while the light “Save automatic cleanup” button saves them so that they get cleaned on their own every day, every week or every month. When you reopen the page the items already appear ticked as you scheduled them, so you can see at a glance what will be cleaned automatically. Having the automatic cleanup on does not stop you from pressing “Clean now” whenever you want. It starts on “Never, I will do it myself” and nothing runs. Careful: cleanup really does delete data and there is no going back, so watch out above all for old versions of posts, which are your safety net if you change a text by mistake. Going back to “Never”, or unticking everything, removes the automatic job straight away, and it is also removed on its own if you deactivate the plugin or if the licence expires.

What the cleanup number really says: The cleanup works in batches: each item removes at most a few thousand at a time, so the page does not time out on big sites. If any are left, it now tells you and says to press «Clean now» again until the number reaches zero. The number you read is the number of items that REALLY disappeared from the database, not the ones it tried to remove: if something is not deleted, it is not counted. Optimising the tables does not delete anything, so it stays out of that count and is reported separately. ⚠ And one thing to know about the Trash: it does not hold only posts and pages, but also the bookings, quotes, audits and conversations you have trashed from the Dashboard. Emptying it means that customer data is gone for good, and the same applies if you include the Trash in the automatic cleanup.

Mailchimp

Automatically connects contacts classified by the Thermometer to your Mailchimp list, ONLY for those who gave explicit consent. Depends on the Thermometer module: without lead classification, there's nothing to synchronize.

API key and list: the key from your Mailchimp account (Account → Extras → API keys) and the list chosen from a dropdown with your account's real lists, not an ID to copy by hand, so you don't risk mistyping it.

How the customer sees it in chat

Why the checkbox only appears when everything is ready: Showing a consent checkbox for a feature that isn't really connected to anything would be misleading for the customer: the checkbox only exists when there's a valid key and list AND the Thermometer module is also on, otherwise it stays hidden. If something is missing, a notice says so both here and on the Settings → Modules and limits tab, pointing out exactly what to turn on.

⚠️ Without explicit consent given by the customer themselves, no data is ever sent to Mailchimp, even if the module is configured and on: this isn't a choice that can be bypassed by a setting, it's written into the bot's very functioning.

What happens if a customer withdraws consent later: The customer receives, along with the subscription confirmation email, an unsubscribe link: clicking it, they're really removed from Mailchimp, not just marked as "to ignore".

The emails that go out on their own: when the subscription becomes real the customer always gets the confirmation, whether they clicked our link or Mailchimp's one after coming back from an unsubscribe: it goes out once per subscription, never twice. When they unsubscribe instead, they get an email confirming it and explaining how to come back, should they change their mind one day. You get a notice in both cases, with name and email: if you don't want it, turn it off in Settings, under Email notifications to you, and the register in the Dashboard stays complete anyway.

Consent table (Dashboard → Consents): a log of who gave or withdrew consent, with date: remains as proof even after a withdrawal or if Mailchimp is disconnected entirely, useful in case of disputes over a send.

You notice when a new one arrives: the Consents tab behaves like Appointments, Quotes and Audits: the word NEW appears next to the name on every consent that arrived since you last opened it, and the red number beside the tab name says how many there are. The dot in the WordPress menu counts them together with the others. Opening the tab clears everything; if you want to remove a single row sooner, click the x next to NEW.

The fifteen-minute pause between one email and the next: whoever asks to subscribe receives ONE confirmation email, and for a quarter of an hour no other one goes to the same address. This stops anyone using the chat checkbox to fill someone else's inbox with emails. If in the meantime the customer ticks the box again, the bot tells them plainly and writes how many minutes until they can request it, instead of pretending it was resent. After ten emails in an hour from the same computer everything stops for an hour, and that's said too: it's a protection, not a fault.

Unticking the box really does unsubscribe: the customer isn't forced to hunt for the link in the email: they just open "Your details" in the chat and untick the box. They're removed from Mailchimp right then, the bot confirms it and the confirmation email arrives. The link at the bottom of the emails stays anyway, for whoever prefers it or no longer has the chat at hand.

The confirmation link expires: anyone asking to subscribe gets an email with a link to click, and that link is valid for 30 days. If a client writes to say they are seeing "this link is no longer valid", that is normal: they just need to request the subscription again from the chat. The expiry serves one precise purpose: stopping an old confirmation email, reopened months later or pre-loaded on its own by corporate spam filters, from putting back in someone who had unsubscribed in the meantime.

Someone who unsubscribed and wants to rejoin: it's Mailchimp that forbids putting back someone who has removed themselves: they must return of their own accord. When that happens, the plugin doesn't send its own confirmation email but asks Mailchimp to send theirs, and it tells the customer plainly. Until they click that link they stay out, and in Mailchimp you see them as "pending": pending contacts don't appear in the audience list, you can only find them by searching for the address. If the customer doesn't confirm within 60 days, Mailchimp deletes them.

The checkbox always tells the truth: when the customer reopens "Your details" in the chat, the state of the checkbox is requested from the site, not taken from whatever their browser had saved. So anyone who unsubscribed from the link in the email no longer finds the box ticked, and below it they read a notice explaining why and telling them they can tick it again to resubscribe. If instead they have just subscribed and still have to confirm, the box stays ticked and the notice reminds them to open the email: the subscription is in progress, not cancelled.

The re-entry email is sent by Mailchimp, not by your site: anyone rejoining after unsubscribing receives the confirmation directly from Mailchimp, with their button and with the contact address set in your Mailchimp account, not the site's one. This is normal and can't be changed from here: if you want a different one, change it in Mailchimp, under Audience, audience settings. If their link gives a page-not-found, it usually means it had already been used: just tick the box again in the chat and a new one arrives.

On the second or third time in a row, Mailchimp doesn't resend the email: it's a rule of theirs, not a plugin fault. Mailchimp sends the confirmation email when a contact goes into pending, but it doesn't send a new one every time you ask for the same address: that stops the form becoming a tool for bombarding someone. The plugin can ask for the re-entry and know it was registered, but it can't know whether they actually sent the email, and so it doesn't claim it did. The important part: the confirmation link already received does NOT expire with each new request, so just open the earlier email and click that one. If a genuinely new confirmation is needed, the only way is to delete that contact from the Audience in Mailchimp and have them subscribe again from the chat.

The "pending" status clears itself: the customer clicks that link on Mailchimp's site, so your site is never notified by anyone. So you're not left reading "pending" forever, every hour the plugin asks Mailchimp what happened to the contacts left hanging and updates the table by itself. A customer who reopens the chat sees it even sooner, because it's checked on the spot at that moment.

If someone removes themselves from inside Mailchimp: a customer may unsubscribe from the Mailchimp panel or from the link at the bottom of one of your campaigns, without going through the chat. There too, nobody notifies your site. That's why, every time someone ticks the box, the plugin first asks Mailchimp how that address really stands: so you don't end up reading "Subscribed" in green about a person who has left the list.

Addresses that bounce: if emails sent to an address come back, Mailchimp marks it as unreachable and will never let it back in. In that case the bot says so to the customer and asks for another address, instead of letting them believe they subscribed.

Dashboard

The daily operations center. Not a setting to configure once, but the page you check every day to see what really happened while you weren't looking: who wrote in, who booked, who is ready to buy.

How you see it in the panel
Appointments
Quotes
Audit
Analytics
Consents
Extra

Appointments / Quotes / Audits: every element received, with direct actions (confirm, reschedule, cancel, download): no need to go looking for bookings in the calendar or quotes among emails, it's all already here in one place.

Analytics: conversations analyzed by the Thermometer, leads ready to buy, visits and the site's most-clicked pages: the overall view of how the bot is really doing, not just conversation by conversation.

How "asked for a human contact" is counted: every time the card with your direct contact details appears in the chat, that conversation is counted: it's a certain fact, not an interpretation. It also counts when the bot offered the contact and the customer accepted. Once counted it stays counted, because it really happened: it only resets by clearing Analytics.

Security blocks: how many suspicious requests the plugin turned away on its own: attempts to have someone else's conversation emailed to them, repeated requests beyond the hourly caps, attempts to write to a customer's record from a different device. This number usually stays at zero. If it goes up, someone tried to take advantage of the bot and the plugin has already stopped them: you don't need to do anything, this is a report of what was blocked, not a list of things to fix.

Periods and the month-to-month comparison: the filters at the top (30 days, 6 months, 12 months) use your site's time, the one set in WordPress, so the count adds up wherever in the world you are. The "This month vs last month" box compares the same elapsed time from the first of the month in both: if you look at the page on the 6th at nine in the morning, last month is measured up to the 6th at nine, not up to midnight. Otherwise the current month would always look like it's doing worse than it is.

Site visits stop at 90 days: traffic data is kept for 90 days and then deleted automatically, so the database doesn't grow forever. If you choose 6 or 12 months the other cards cover the whole period, but visits, visitors and most-clicked pages still show the last 90 days: those are the only ones that exist.

Your data stays yours: every section has a link to download what it contains in a file that opens with Excel: appointments, quotes, audits and consents. It always works, even if one day the licence expires: in that case the sections stay visible but no longer operational and the button becomes more prominent. This is your customers' data, not the plugin's, and you can take it with you whenever you want.

Clear memory: wipes everything the bot remembers from the conversations. If there are a great many conversations to delete, the job is done a piece at a time so the request does not time out halfway through: the button tells you how many are left and you just press it again. It is not an error, it is how the job gets finished instead of being left half done.

New quote and New appointment: The two buttons at the top of the dashboard open two pages where you can create a quote or book an appointment BY HAND, without going through the bot. They are for when the customer phoned you or sent an email: you fill in the fields and the document comes out identical to the ones made in chat, with the same progressive number and the same template. The manual quote allows at most five line items, like the bot's, so the two documents stay the same.

Notify the client or not: When you book an appointment by hand you can choose whether to notify the client. With "Yes" they get an email with the date, the time and the link to move or cancel it themselves, in the language chosen for the bot. With "No" the appointment stays in the panel only, as a reminder for you. If the email cannot go out, the panel tells you straight away instead of letting you believe it arrived.

The manual quote and the email to the client: Here too you can choose. With "Yes" the client gets an email with the PDF attached, in the language chosen for the bot. With "No" the quote stays in the panel only. If the PDF was not generated, nothing goes out and the panel tells you, because an email promising an attachment that isn't there is worse than no email at all.

How much the bot really knows your pages: In Website knowledge you choose the pages and decide how much the bot should know about them. With “only the summary” it gets about 40 words per page: it knows what the page is about and can send the customer there, but it has not read what is inside. With “summary plus the text of the page that fits”, for every question it also gets the real text of the relevant page, found using the words of the question: so it answers with the details that are actually written, and you only pay for that text in the messages where it is needed. The page is found by words and not by meaning, but the bot prepares its own list of words customers might search for, so it finds the page even when they use wording different from yours: you can correct that list by hand. Everything keeps itself up to date: when you edit a page, the summary and the text are redone shortly after, without you doing anything.

The emails that reach you, and how to turn them off: The plugin emails you when something happens: someone books, moves or cancels an appointment, a quote is generated, a contact qualifies (and you get the conversation transcript), someone asks for a check of their site. With some traffic they add up. In Settings, section Email notifications to you, there is a switch for each one: they all start on and you turn off only what you do not need. Two emails cannot be turned off there on purpose: the ones going to the CUSTOMER, because they are what the bot promises them in the chat and otherwise the bot would look like a liar, and the message a visitor leaves when asking to speak to a person, because that text is not saved anywhere and the email is the only copy.

What the site check really checks: It runs up to twenty-five checks on the site the visitor gives you, split across four areas that the report groups for you: security (secure connection, redirect to https, certificate expiry, resources loaded in the clear), visibility on Google (title and description of the right length, a single H1, declared language, canonical, structured data, robots.txt, sitemap, error page, image alternative text, analytics), experience and speed (mobile tag, link preview, favicon, response time, page weight, compression, file caching) and trust (privacy and cookies, clickable contacts on the homepage, copyright year). At the top there is a percentage score: green from 80 up, orange from 55, red below.

When a check does not appear in the report: That is on purpose. If a check cannot answer with certainty, that line disappears instead of becoming an «absent»: better one item less than a wrong one on a document you send to a potential customer. It happens for example when the site does not answer in time, or when it is built so that the browser fills in the content later: in that case some checks are not possible and the report says so plainly. The time available adapts by itself to how much your hosting allows.

The site check report also arrives by email: When someone has their site analysed from the chat, the document does not stay only in their browser: it reaches you with the PDF attached, so you have the contact and the report without opening the dashboard, and it reaches them too. The same goes for the quote the bot prepares in the chat: the PDF also reaches the customer by email. These two copies to the customer each have their own switch in Settings: if you turn them off, all they have left is the download button in the chat, and if they do not press it the report is lost.

How many checks the same person can ask for: In Settings there is the field «Days between one free site check and the next for the same email». Left empty it means 365 days. With 0 the limit disappears entirely and the same address can ask for checks as often as it likes: handy while testing, worth thinking over once the site is live, because every check is a call to the engine that you pay for.

The percentage next to Quotes and Appointments: this is the conversion rate: out of a hundred analysed conversations, how many actually led to a quote or an appointment. Only documents created AFTER the conversation are counted, that is, the ones that conversation could really have produced: a customer who asked for a quote months ago and today comes back with just a question is not counted as a conversion. If this percentage drops after updating, nothing is broken: returning customers used to be counted too, now the figure is the real one.

Sorting and searching in the lists: Above every list (appointments, quotes, audits, consents) there is a bar with a magnifier and a dropdown to choose the order. The magnifier also searches the phone number, the quote title and number and the address of the checked website, not just the name and the email. The search works on the database, so it also finds what is not on the page you are looking at. In the appointments the dropdown has three choices, because there are two different dates: the order of arrival (who booked last) and the appointment date, closest or furthest first. In the consents the page number follows the search.

Extra: test tools to reset test data while configuring the bot: useful during testing, before handing the site over to a real customer, to start fresh from a clean state without carrying over the fake bookings made during testing.

What «Unlock the chat limits» removes: not just the daily message count. It also removes the cap on chat summaries (three per hour per email address), the one on direct messages and the one on newsletter requests. These are defences against abuse, but during testing you are the one who runs into them: if you are testing with your own address and the fourth summary within the same hour brings nothing, that is the cap and not a fault.

If a tool in the Extra tab does nothing, it tells you: every button checks whether the server actually did what it was asked. If it didn't — because the licence isn't active, because that module is switched off, or because the page had been open so long that the security token expired — a notice says so, instead of a confirmation that isn't true. This applies to «Unlock everything» too, which tells you how many of the six unlocks failed.

System status

A snapshot of how the bot is configured right now: green means correctly set, red indicates something still missing, almost always with a direct link to fix it right away without having to look for it yourself in the menu.

The notice “your hosting is missing mbstring”

If this yellow notice appears on the plugin pages, it is not a fault and you have lost nothing. mbstring is a part of PHP that handles accented letters: almost every hosting has it, but it is not mandatory. Without it the plugin keeps working, though on text with many accents a cut may shift by one character.

What to do: write to your hosting and ask them to enable the mbstring extension for PHP. It is a completely normal request, done in a few minutes and free of charge. In the technical summary, section “Technical environment”, there is a line telling you whether you have it or not.

The «dom extension» row

What it checks: dom is a piece of PHP used to read web pages. Two features rely on it: the Site Check, which analyses a prospect's website, and the automatic reading of your portfolio page. Almost every host has it, but it is not mandatory like other parts of PHP, so now and then it is missing.

What happens if it is missing: nothing breaks and nobody sees a blank page. The Site Check tells the visitor it could not analyse the site right now, and the automatic portfolio reading finds no work: in that case write your projects by hand in the table under Settings, which always works. Everything else in the bot keeps working as before.

What to do: write to your host and ask them to enable the dom extension for PHP, exactly as for mbstring. It is a routine request and they enable it in a few minutes.

How you see it in the panel
✓ Configured ✗ Still empty

Why there's a page dedicated just to "checking": The bot's settings are scattered across many different pages: without a summary, it would be easy to forget you left an important field empty on a page you don't visit often (the AI key, for example, is configured once and then it's easy to forget it exists). This page gathers everything in one place, so a single glance is enough to know if something's missing.

Live key test: sends a real test message to the chosen AI engine: confirms everything really works, from the key through to the response, not just that the field was filled with something that looks like a valid key.

If you import the wrong file you can go back: importing replaces the whole configuration, so before doing it the plugin puts the current one aside and shows you a button to restore it. The exported file contains ALL your settings and they are all put back: business name, price list, page links, opening hours, VAT, currency, logo, PDF, modules and portfolio works. If the file you pick contains no Sabriel AI setting it is rejected without touching anything. When it does go through it tells you how many settings it applied, and if the file also had things that are not Sabriel AI's it tells you how many entries it ignored: if you read a number much lower than you expected, do not trust it and restore the previous configuration.

Are the keys really encrypted? One line on the page answers this question by checking the server, not by guessing. On some very old hosting the component needed for encryption is missing: in that case a red box appears explaining what to ask your host's support team, instead of letting you believe your keys are safe when they are not.

Are your customers' PDFs protected? Quotes and reports end up in a protected folder. On some servers that protection is ignored, and it would be impossible to notice by looking at the panel: so the plugin tries to download a dummy file from that folder itself and, if it succeeds, it tells you and gives you the exact rule to pass on to your host.

Support email: If you don't set one of your own, the WordPress administrator address is published instead: in the chat, inside the PDF quotes and in the source code of every page of your site. This row tells you right away, instead of letting you find out from the spam that starts arriving.

Duplicate copies of the plugin: If old Sabriel AI code pasted in by hand is still active on the site (for example from before it became a plugin), the panel detects it and names it. This is the situation that throws sites into error during a migration, and without this indicator it would be extremely hard to work out.

Export / Import configuration: downloads a file with all current settings: useful as a backup before major changes, or to copy the same configuration to another site with similar characteristics. The AI and Mailchimp keys aren't included in the export (they stay encrypted and separate for security): after an import they'll need to be re-entered by hand. A colour that is not written as a proper colour is ignored as well, whatever file it came from: colours end up inside the stylesheet of the chat window, so only real colour values are accepted there.

What goes into the technical summary: the «Copy technical info» button and the report email to support use the exact same summary, so whoever answers you sees exactly what you see. It includes a Portfolio section: which source the bot is using, how many works you wrote by hand and how many of those have an image, a link and keywords, which theme content type was recognised and whether the plugin already knew it by name or worked it out on its own, whether WooCommerce is there, which portfolio page is linked and whether it has already been read. If the module is off or blocked by the licence, the section does not disappear: it says it is off and why, so nobody goes looking for a fault that does not exist.

Check this page as soon as you finish configuring a new site, and every time the bot seems to behave strangely: often the cause of unexpected behavior is exactly a red line left here, not a real error in how the bot works.

Privacy and data

This page lists, without beating about the bush, which data leaves your site, which is kept and for how long, and which limits are worth knowing about. It is there to help you write your site's privacy policy: nobody can do that for you, because it depends on how you use the plugin and where you are based.

⚠️ This page describes how the plugin works, it is not legal advice. If you collect customer data in the European Union, have it read by whoever looks after your privacy compliance.

If a client asks for their data or for deletion

Tools → Export personal data / Erase personal data

The consent to updates comes out with the conversation: the person's choice on the "I want to receive email updates" box, with the date and how it stands on Mailchimp, is delivered together with their chat conversation: that's where the plugin records it, and that's where you'll find it in the exported file.

Where to do it: you do not need a Sabriel AI page: you use the two tools WordPress has built in under Tools. The plugin has declared itself to both, so its data appears in the export and is handled in the erasure together with the other plugins. Type the person's email address, confirm, and WordPress does the rest.

What comes out in the export: name, email and phone; the appointments with date, time, reason, status and notes; the quotes with number, title and amount; the site checks requested; the consent to email updates with its date and the status on Mailchimp; and the full text of the chat conversations, message by message, with the summary and the automatic rating if present.

What happens with the erasure: conversations are deleted entirely. Appointments, quotes and site checks are anonymised instead: name, email, phone and notes disappear, the document stays without a name. It is not a shortcut: those documents contain amounts and dates that in many countries must be kept for tax obligations, and deleting them would put you in a different mess from the one you wanted to avoid. WordPress also tells this to the person who made the request.

The limit on profile changes: a customer can change their details a limited number of times every 30 days, and you decide the number in Settings. The count only kicks in if they actually change first name, last name or email: opening the panel and pressing save without touching anything, or changing only the phone or the updates checkbox, doesn't use up any of their allowance. The limit is there to stop someone changing identity over and over, not to block someone who wants to fix a wrong letter in their own name.

If you want to delete everything anyway: the button on the Security and cleanup page really deletes, with no exceptions. Use it only if you know what you are doing: it cannot be undone.

The text for your privacy policy: under Settings → Privacy, in the draft policy, there is already a paragraph about Sabriel AI: what it collects, who it is shared with, how long it stays, what is never kept and what rights the person has. Read it, adapt it to your situation and paste it into your policy.

This page describes how the plugin works, it is not legal advice. If you collect data from clients in the European Union, have your policy read by whoever handles privacy for you.

What leaves your site

The AI service. Every message the visitor writes in the chat, together with the attachments they upload and your business information (price list, opening hours, contact details), is sent to the AI service you have chosen: currently Google Gemini. That is how the bot works: without sending it, there would be no reply. How that data is handled and for how long is decided by the AI service, not by this plugin: its terms are what apply.

⚠️ One special case to be aware of: Anthropic's Fable 5 model requires data to be kept for 30 days and is not available with the no-retention mode. If that is a problem for your clients, pick a different model on the AI Engine page.

The disposable email check. When a visitor leaves their email address, the plugin can check that it does not belong to a throwaway service. To do that it sends only the part after the at sign (the domain, for example "gmail.com") to an external service called Kickbox, based in the United States. The full address never leaves your site. You can switch this check off whenever you like. Right now it is on.

Sabriel AI → Settings → Modules and limits

For developers: the check can also be disabled with the sabriel_ai_controllo_email_temporanee_online filter.

Nothing else. Apart from these two cases, and from Mailchimp if you connect it yourself, the plugin sends data to no one else: not to whoever created it, not to analytics services, not to advertising networks.

What stays saved, and where

Visits to the site. The plugin counts page visits and how many chats are opened. To avoid counting the same person twice, it gives every visitor a random code, saved in their browser. There is no name, no email, no IP address: just a code and the paths visited, kept for 90 days and then deleted automatically.

⚠️ Worth knowing: this count starts switched on and does not ask visitors for consent. You can switch it off whenever you like from Settings → Modules and limits, with the «Collect visit statistics» toggle: once off, nothing more is collected. If you leave it on and your site uses a cookie banner, remember to mention it in your privacy policy alongside the other statistics tools.

The conversations and the contacts. Chats, appointments, quotes and site analyses stay inside your WordPress, in your database: they are not copied anywhere. They are your data, and they stay yours even if the licence expires one day. The Dashboard has a button to download them all into a file that opens with Excel.

The PDF documents. Quotes and analysis reports end up in a protected folder, not in the public media library. They can only be opened through a signed link: guessing the file address will not download it. System status has an indicator that checks exactly this and warns you if your host does not follow the rule.

The AI service keys. They are saved encrypted, so not even by looking inside the database can they be read in clear. For that to be possible the PHP OpenSSL extension is needed: it is there almost always, and the System status page tells you whether it really is on your server. If it is missing, the key stays written in clear and there you see it stated plainly. If one day the WordPress security keys change or you move the site, the encrypted keys may become unreadable: the panel tells you and you just enter them again.

When you uninstall. If you leave the relevant checkbox ticked in the Settings, uninstalling the plugin deletes all of its data. Only the "Reschedule appointment" page remains, which the plugin creates by itself the first time it is needed: it is deliberately not deleted, because you might have edited it or added it to your menu. If you no longer need it, remove it by hand from the WordPress Pages.

Limits worth knowing

These are three intended behaviours, not defects. We write them here because in certain businesses they matter.

1. It is possible to find out whether an address has an appointment. When a client asks the bot to move or cancel their appointment, the bot has to be able to answer "yes, there is one". That means that by trying an email address, someone can work out whether that person has an appointment with you, not when, and no other details. There are brakes that make trying many of them impractical (only a few requests per hour from the same connection), but for a medical or legal practice this is worth knowing.

2. The chat summary goes to the address written in the widget. Anyone chatting can have a copy of the conversation sent to them by email. That address is not verified with a second confirmation message: it works like the "send me a copy" forms found on many sites. It means someone could enter another person's address and have that copy delivered to them. To limit this, each address can receive at most three summaries per hour, and at the bottom of the email there is always a line explaining where it comes from and that it can be ignored.

3. Behind certain protection services all visitors look like a single one. The anti-abuse brakes count requests per connection. The plugin already recognises Cloudflare and works out who the real visitor is. If your site sits behind a different system instead (nginx, Varnish, AWS or Sucuri, for example), every visitor may look like the same connection: in that case the limits run out far sooner than expected. It is fixed by telling the plugin which system to trust.

For developers: the systems to be treated as trusted are added with the sabriel_ai_range_proxy_attendibili filter.

Premium: plans and license

The bot also works in the free version, with a limited number of messages per day and the basic features (identity, main colours and logo). The paid plans unlock every other feature described in this manual. The only difference between them is the number of sites the same licence can be activated on, never the features: what you unlock with the cheapest plan is exactly what you unlock with the most expensive one.

Free
$0
forever, one site
24/7 AI chat with your customers
No message cap: you decide the limit
Main colors and logo
9 languages, bot and panel
The bot remembers the customer on the same device
×Dashboard and customer management
×Advanced customization
×Bookings
×PDF quotes
×Lead thermometer and Analytics
×Website check
×Recoverable history
×Portfolio / Products
×Site knowledge
×Mailchimp synchronization
Your current plan
MOST CHOSEN
Pro
$19
/month, one site
Everything in the free edition
Dashboard and customer management
Full advanced customization
Bookings
PDF quotes
Lead thermometer and Analytics
Website check
Recoverable history
Portfolio / Products
Site knowledge
Mailchimp synchronization
Sabriel AI branding removed
Automatic updates
Upgrade to Pro
Studio
$39
/month, 5 sites
Everything in Pro
Can be activated on 5 sites with the same licence
Made for those looking after more than one site
Go Studio
Agency
$79
/month, 20 sites
Everything in Pro
Can be activated on 20 sites with the same licence
Built for agencies and freelancers
Upgrade to Agency

Secure payment via Freemius. You can cancel anytime.

How you see it in the panel
PRO

Why the boundary is "how many sites" and not "which functions": An agency managing 10 different client sites doesn't need different functions from a single professional with just one site: it needs the SAME thing, repeated across multiple installs. Splitting plans by number of sites instead of by functions avoids the common frustration of discovering an important function is locked behind an even more expensive plan.

Activate license: paste the key received at purchase to immediately unlock all Pro features, even months after starting with the free version: there's no deadline to take advantage of it.

Deactivate license: frees the license from this site so it can be reactivated on another: useful if you change domain, server, or simply want to move where you use it. Without deactivating it first, the same key can't be activated elsewhere as long as it stays tied to this site.

Re-check the license now: the site does not ask Freemius on every page whether the license is still valid: it asks once a day and uses the answer it already has for the rest of the time. So after a renewal, a plan change, a cancellation or an expiry it can lag behind by up to 24 hours and still show yesterday's picture. This button asks straight away. Use it if you have just renewed and still see Free, if you moved to a higher plan and cannot find the new modules, or if you changed something on Freemius and want to see the effect now. If something changed it tells you and reloads the page; if nothing changed it tells you that too, instead of leaving you guessing.