Privacy
How this workspace handles data
Last updated: 22 July 2026.
Product URLs and report input
Submitted public URLs are fetched by the application and, when configured, an isolated accessibility worker. Do not submit private, authenticated, internal, or confidential URLs.
Browser-local data
Report history, finding review notes, evidence metadata, reminders, and beta metrics are stored in this browser using local storage. Clearing site data removes those local records.
Analytics
Events remain local unless a remote event endpoint is configured and you have granted analytics consent. Event properties are bounded and must not contain supplier documents, upload tokens, or sensitive personal data.
Supplier and evidence workflows
Protected supplier links use encrypted, expiring capabilities delivered in the URL fragment so the token is not sent in the initial HTTP request. If private storage is configured, files are uploaded to signed targets and remain unavailable for download or acceptance unless their recorded malware status is clean. This version does not run malware scanning itself.
Contact
A dedicated privacy contact address will be published when the public support channel opens.