Privacy Policy

Last updated: 2026-07-30

This page describes exactly what data this service handles. It is deliberately specific: an accessibility product that is vague about privacy would be contradicting itself.

The widget collects no personal data

When the accessibility widget loads on a website, it does not set cookies, does not use browser fingerprinting, does not read page content, and does not identify visitors in any way.

It sends one anonymous counter event per action — widget loaded, menu opened, tool used — containing only the site's licence identifier and the event name. There is no visitor identifier, no session, and no way to link two events to the same person.

  • No cookies and no local storage used for tracking (accessibility preferences are stored locally on the visitor's own device, and never transmitted).
  • IP addresses are transmitted as part of any HTTP request, as is technically unavoidable, but are not stored or logged by us.
  • Because no personal data is processed, the widget requires no consent banner.

What we store for account holders

If you create an account to manage a widget, we store the following, and nothing else:

  • Your email address, and optionally a name and company you choose to enter, used to authenticate you and nothing more.
  • The domains you add, and the widget configuration for each.
  • Scan results for the sites you add: public page URLs, detected accessibility issues, and short HTML snippets of the offending elements.
  • Anonymous usage counters per site, as described above.

Processors we rely on

We use a small number of third parties, each for a single purpose:

  • Google Firebase — authentication and database storage.
  • Google Gemini — when you press the button to generate a remediation plan, the detected issues and HTML snippets for that scan are sent for analysis. Nothing is sent unless you ask for it.
  • Our hosting provider, which processes requests in order to serve the site.
  • If you choose to donate, the donation platform and payment provider handle that transaction under their own privacy policies. We never receive your card details.

Scans only touch public pages

A scan fetches pages the same way any visitor's browser would, over the public internet, using the URL you provide. It does not log in, does not submit forms, and refuses any address that is not publicly routable. Do not use it against sites you do not control.

Retention and your rights

Deleting a website in the dashboard deletes its configuration and scan history. Deleting your account removes your data. You can request access to, correction of, or deletion of your data, and you can object to processing, by contacting us.

We do not sell data, do not share it for advertising, and run no advertising or analytics trackers on this site.

Questions about this?

Ask anything about how your data is handled — a real person answers.

Contact