Phyllix reads your website, works out what your business actually does, and then works on your search visibility the way a marketing manager would – by finding what you could realistically rank for, what your existing pages half-cover, and what is missing entirely.
By default, it never publishes anything. Every article it writes is filed as a draft for you to read, edit and approve, and if you want that to stay true forever, it will. Every change it proposes to a page you already have is shown to you in full first, and the original is kept so it can be undone. An explicit Automation section in Settings lets an owner who wants more turn on exactly as much as they choose — anywhere from just sending findings to your Ideas queue automatically, up to approving, writing and publishing articles with no click at all. Every level is off by default, and turning any of it on is a deliberate choice you make.
What it does
How it treats your content
This is the part we care most about. A page you already have is a page that already works for someone, so:
Free plan
The free plan includes 3 AI-written articles, once — a one-time allowance, not a monthly one. Reading your site, the business profile, the content map, the keyword map, the gap analysis, manually-tracked competitors, Google Search Console tracking, and fixing technical SEO problems are always included, for free, forever, with no limit. Once the 3 free articles are used, buy AI credits ($1.25 each, pay only for what you use, no subscription) or move up to a paid plan for an ongoing monthly allowance. Free also reads up to 25 pages of your own site, once, ever.
Phyllix cannot work without connecting to an external service. It does not run AI models on your server, and it does not ask you for API keys. Instead it sends work to the Phyllix service, which runs the AI on your behalf. You should understand exactly what that means before you use it.
Phyllix connects to https://visualithicsolutions.com, operated by Visualithic Solutions, to license the plugin and to run every AI request.
When it connects:
What is sent:
home_url())What is not sent: your database, your users, your customers’ data, your orders, or the content of any page Phyllix has not been asked to work on. Pages you have marked Private or password-protected are skipped outright, whatever content type they are, and any email address found in a page’s text is stripped before that text reaches an AI request.
Terms: https://visualithicsolutions.com/terms
Privacy: https://visualithicsolutions.com/privacy
The Phyllix service passes your request to one of two AI providers, depending on the task. Your content is sent to them by the Phyllix service, not directly by this plugin.
If you choose to connect Google Search Console, Phyllix calls
https://oauth2.googleapis.com to exchange the credentials you supply for an
access token, and https://searchconsole.googleapis.com to read which searches
your site appears for. This is entirely optional and nothing is sent to Google
beyond the API request itself.
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
If you run a site health check, Phyllix calls https://www.googleapis.com/pagespeedonline with the public address of the page being checked, to retrieve its performance scores.
Terms: https://policies.google.com/terms
Privacy: https://policies.google.com/privacy
When checking AI Visibility questions or discovering competitors, Phyllix’s
research sometimes comes back with a citation on vertexaisearch.cloud.google.com
— a Google redirect link, not a real page. For those two features only, Phyllix
makes a HEAD request directly to that link to follow the redirect to the real
address, so it can show or record the actual source rather than a redirect
link. No data about you or your site is sent – the request only asks where
the link redirects to.
Google privacy: https://policies.google.com/privacy
When you run a site health check, Phyllix makes a HEAD request to the addresses
your pages link to, in order to find broken links and redirect chains. These are
the sites you have already linked to. No data about you or your site is sent –
the request only asks whether the address still responds.
The Diagnostics page in Settings makes one request to https://api.wordpress.org/
as a control check – a destination every WordPress site already trusts. This
confirms your server can reach the internet at all, so a failure to reach the
Phyllix service reads correctly as a problem with that one destination, not
your server’s outbound access in general. No data about you or your site is
sent – the request carries nothing beyond the request itself.
If your server’s normal DNS lookup for the Phyllix service ever fails, Phyllix
asks Cloudflare (1.1.1.1) and, if that also fails, Google (8.8.8.8) – both
public DNS-over-HTTPS resolvers – to look up the address instead, the same way
a browser’s own DNS-over-HTTPS setting would. This only happens after your
site’s normal outbound connection has already been proven to work. Only the
hostname being looked up is sent, and nothing about your site or its content
is included.
Cloudflare privacy: https://www.cloudflare.com/application-privacy-policy/
Google privacy: https://policies.google.com/privacy