How this service handles data
This is a factual data-handling disclosure, not a privacy policy. A privacy policy is a legal instrument whose required contents vary by jurisdiction; ours is with counsel and will be published here. Everything below is an accurate description of what the software does today, and is the same description we hand to counsel.
What the browser snippet collects
The snippet runs an accessibility rule engine in your visitors’ browsers and reports what it finds. It collects:
- Accessibility rule results: which rule, which element, and where on the page.
- A fragment of the offending element’s HTML, scrubbed before it leaves the browser. At the default “strict” level this keeps structure only — tag names, classes, ARIA attributes — and masks all text content.
- The page URL with its query string removed, the page title, and a viewport size.
- A random per-page-view identifier, used to de-duplicate reports within one visit.
What it never collects
- Cookies, or any identifier that persists across visits.
- Form values, keystrokes, or clipboard contents.
- Anything that identifies an individual visitor.
The snippet is read-only. It does not modify the host page, and it sets no cookies of its own. Site operators choose the scrubbing level; the strictest is the default, and turning it down is an explicit choice recorded in site settings.
What the crawler and markup sweep collect
Both fetch pages from our own infrastructure, as an ordinary visitor would, and record the same category of rule results. Neither authenticates as one of your users unless you configure it to.
Account data
Email addresses for sign-in and invitations; organization, workspace, and site configuration; audit results and reviewer notes that your team enters; and uploaded screenshot evidence. Sign-in uses emailed single-use links — we never store a password.
How long data is kept
- Raw per-element findings are pruned on a schedule set by your plan (currently 90–180 days on lifetime plans).
- Deduplicated findings, trend history, and the evidence record are kept for the life of the account. That record is what makes a statement or report defensible, so it is deliberately not pruned.
- If a licence is refunded or deactivated, the account becomes read-only. Collection stops; nothing is deleted, and everything stays exportable.
Sub-processors
The service depends on third parties for hosting, storage, and email delivery. The current list, and notification of changes to it, form part of the data processing agreement — with counsel alongside the privacy policy.
Where data is stored
Infrastructure is hosted in the European Union. This is deliberate: the snippet processes data from EU consumer sites, so keeping processing within the EU avoids international transfer complexity entirely.
Your rights and requests
Account owners can export their organization’s data from the dashboard at any time. For access, correction, or deletion requests, contact the operator of this deployment.