How this service handles data

This is a factual data-handling disclosure, not a privacy policy. A privacy policy is a legal instrument whose required contents vary by jurisdiction; ours is with counsel and will be published here. Everything below is an accurate description of what the software does today, and is the same description we hand to counsel.

What the browser snippet collects

The snippet runs an accessibility rule engine in your visitors’ browsers and reports what it finds. It collects:

What it never collects

The snippet is read-only. It does not modify the host page, and it sets no cookies of its own. Site operators choose the scrubbing level; the strictest is the default, and turning it down is an explicit choice recorded in site settings.

What the crawler and markup sweep collect

Both fetch pages from our own infrastructure, as an ordinary visitor would, and record the same category of rule results. Neither authenticates as one of your users unless you configure it to.

Account data

Email addresses for sign-in and invitations; organization, workspace, and site configuration; audit results and reviewer notes that your team enters; and uploaded screenshot evidence. Sign-in uses emailed single-use links — we never store a password.

How long data is kept

Sub-processors

The service depends on third parties for hosting, storage, and email delivery. The current list, and notification of changes to it, form part of the data processing agreement — with counsel alongside the privacy policy.

Where data is stored

Infrastructure is hosted in the European Union. This is deliberate: the snippet processes data from EU consumer sites, so keeping processing within the EU avoids international transfer complexity entirely.

Your rights and requests

Account owners can export their organization’s data from the dashboard at any time. For access, correction, or deletion requests, contact the operator of this deployment.

← Home · Terms