Skip to privacy content
AccessAudit
FeaturesBenchmarkTransparencyResearchPricingAboutContactPrivacyTerms
Sign inStart free
Menu
FeaturesBenchmarkTransparencyResearchPricingAboutContactPrivacyTermsSign inStart free
Privacy Policy

How AccessAudit handles account, scan, report and AI assistance data.

This Privacy Policy explains what AccessAudit may collect, why it is processed, which service providers may receive it, how long it may be kept, and how users can request access, correction or deletion.

On this pageOverviewController and contactData we processWhy we process dataScans and reportsAI assistanceService providersRetentionUser rightsSecurityCookiesChanges

1. Overview

AccessAudit is an accessibility evaluation product. It processes data needed to create accounts, run scans, generate reports, provide AI-assisted explanations, receive contact messages, protect the service and improve the product during validation.

AccessAudit is not designed for storing secrets, passwords, API keys, payment card data, private customer records or sensitive internal information inside scan inputs or AI prompts.

2. Controller and contact

AccessAudit is operated by the project owner of the AccessAudit service. For privacy questions, data requests or deletion requests, use the contact form on the website.

No personal email address is exposed publicly on this website. Contact requests are routed through the private contact form.

Contact AccessAudit

3. Data we may process

Depending on how you use the service, AccessAudit may process:

  • Account data such as name, email address and authentication metadata.
  • Password credentials in hashed form where password login is used. Plain-text passwords are not intentionally stored.
  • Project data, scan history, submitted URLs and report metadata.
  • Technical scan results such as rule ID, WCAG criterion, severity, selector, status and timestamps.
  • Page evidence generated during scans, such as screenshots, visual markers, short HTML snippets and nearby text context.
  • AI assistance context used to explain findings or draft remediation suggestions.
  • Contact form data such as name, email, organisation, topic and message.
  • Basic logs, security events, request metadata, error diagnostics and abuse-prevention data.

4. Why we process data

AccessAudit may process data to:

  • create and secure user accounts;
  • run accessibility scans and generate reports;
  • show scan history and project results inside the dashboard;
  • provide AI-assisted explanations and draft remediation guidance;
  • send transactional or contact form emails;
  • debug errors, prevent abuse and protect the service;
  • understand product usage during validation and improve the workflow.

The legal basis may include performance of a service requested by the user, legitimate interests in operating and securing the product, consent where required, and compliance with legal obligations where applicable.

5. Scans and reports

When you submit a URL, AccessAudit may fetch the page, execute browser-based checks, run automated accessibility rules, capture screenshots, store findings and generate reports.

Scan outputs may include detected issues, affected elements, selectors, grouped findings, screenshots, visual markers, AI explanations, manual verification notes and report exports.

You should only submit pages that you own, manage, are authorised to test, or are legally allowed to evaluate.

6. AI-assisted processing

AI is used as an assistance layer. It is not the main scanner and it does not make legal compliance decisions.

What may be sent to AI

Relevant issue context may include the rule name, WCAG criterion, severity, selector, element text, short HTML snippet, nearby context, screenshot crop or other issue metadata needed to explain a finding.

How models are used

  • Claude Haiku may be used for plain-language explanations, WCAG context, user impact and draft remediation guidance.
  • Claude Sonnet vision may be used for selected visual or semantic checks, such as reviewing whether existing alt text appears descriptive.
  • axe-core and AccessAudit custom rules remain the primary technical detection layer.

Missing alt attributes can be detected by deterministic rules. Poor or misleading alt text requires interpretation and should be treated as AI-assisted review, not final proof of compliance.

7. Service providers and subprocessors

AccessAudit may use third-party infrastructure and APIs to host the product, store data, send email, run browser scans and provide AI assistance. Current or planned providers may include:

  • Vercel for web application hosting and deployment.
  • Railway for backend or worker infrastructure.
  • Supabase or another configured database provider for account, project and scan data.
  • Browserless or Playwright-based infrastructure for browser scans and screenshots.
  • Anthropic for Claude-based AI assistance.
  • Resend for transactional and contact form email delivery.
  • A payment provider if paid plans are introduced later.

These providers may process data only as needed to provide their respective services to AccessAudit.

8. Data retention

AccessAudit keeps data for as long as needed to provide the service, maintain reports, support user accounts, debug errors, investigate abuse, satisfy legal obligations or improve the product during validation.

Users may request deletion of account, project or scan data through the contact form. Some data may be retained where needed for security, abuse prevention, legal obligations or backup integrity.

9. User rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability or objection to processing of personal data.

AccessAudit will review reasonable requests submitted through the contact form and may need to verify the requester before acting on account or scan data.

10. Security

AccessAudit uses technical and organisational measures intended to protect account, scan and report data. No online service can guarantee perfect security.

Users should avoid submitting credentials, secrets, private customer data or sensitive internal information into scan inputs, reports or AI-assisted workflows.

11. Cookies and local storage

AccessAudit may use necessary cookies or local storage for authentication, session management, security and user interface behaviour.

If analytics, marketing cookies or similar tracking tools are introduced later, the policy and consent flow should be updated before those tools are used.

12. Changes to this policy

This policy may be updated as AccessAudit changes, introduces paid plans, adds providers or expands product features. The effective date above will be updated when material changes are made.

AccessAudit

AI-assisted accessibility evaluation with visual evidence and guided verification.

ResearchPricingAboutContactPrivacyTerms