Privacy

How this workspace handles data

Last updated: 22 July 2026.

Product URLs and report input

Submitted public URLs are fetched by the application and, when configured, an isolated accessibility worker. Do not submit private, authenticated, internal, or confidential URLs.

Browser-local data

Report history, finding review notes, evidence metadata, reminders, and beta metrics are stored in this browser using local storage. Clearing site data removes those local records.

Analytics

Events remain local unless a remote event endpoint is configured and you have granted analytics consent. Event properties are bounded and must not contain supplier documents, upload tokens, or sensitive personal data.

Supplier and evidence workflows

Protected supplier links use encrypted, expiring capabilities delivered in the URL fragment so the token is not sent in the initial HTTP request. If private storage is configured, files are uploaded to signed targets and remain unavailable for download or acceptance unless their recorded malware status is clean. This version does not run malware scanning itself.

Contact

A dedicated privacy contact address will be published when the public support channel opens.