Skip to content

Cookie Policy

Version 1.2 — Effective date: August 2, 2026 — Last updated: August 2, 2026

This Cookie Policy explains how WCAGC ("we") uses cookies and similar technologies on wcagc.com and app.wcagc.com (the "Service"). It supplements our Privacy Policy.

1. What Are Cookies

Cookies are small text files that a website stores on your device. They can be session cookies (deleted when you close your browser) or persistent cookies (kept until they expire or you delete them), and first-party (set by us) or third-party (set by another domain).

We also use browser web storage (localStorage and sessionStorage) — a related technology that stores small pieces of data in your browser without sending them to a server automatically.

2. How We Use Cookies

We use strictly necessary cookies, preference storage, and optional analytics cookies. Because we use optional analytics cookies (Google Analytics), we ask for your explicit consent via a cookie consent banner before setting them, in compliance with the ePrivacy Directive and GDPR.

2.1 Strictly necessary cookies

These first-party cookies are required to log you in, protect authenticated requests, and — only if you choose it during two-step verification — remember a trusted browser. They are marked Secure in production and SameSite=Lax. The CSRF cookie must be readable by the application so it can be copied into a request header; the other authentication cookies are HTTP-only.

NamePurposeDurationProvider
access_tokenAuthenticates your requests to the API during a session15 minutesWCAGC (first-party)
refresh_tokenAllows your session to be renewed without logging in again30 daysWCAGC (first-party)
csrf_tokenProtects state-changing requests against cross-site request forgery; readable by the application30 daysWCAGC (first-party)
trusted_deviceRemembers a browser that you explicitly choose to trust after two-step verification30 daysWCAGC (first-party)

2.2 Preference storage (browser web storage)

These values are stored in your browser's localStorage or sessionStorage. They never leave your device as tracking data and contain no identifiers usable across other websites.

KeyTypePurposeDuration
wcagc-themelocalStorageRemembers your light/dark/system theme choiceUntil you clear it
i18nextLnglocalStorageRemembers your interface languageUntil you clear it
wcagc-cookie-consentlocalStorageRemembers your cookie banner choices (whether you accepted or rejected analytics)Until you clear it
wcagc_checklist_*, wcagc_notes_*localStorageSaves progress and notes entered in the public interactive checklists on that browserUntil you clear it
wcagc.resumeAfterUpgradesessionStorageRemembers the in-app page and feature to resume after a Stripe checkout redirectRemoved after use, after about 1 hour, or when the tab's session ends
wcagc.2fa.challengeTokensessionStorageHolds an opaque two-step-verification challenge between the password and code screensRemoved after verification or expiry, or when the tab's session ends
chunk-error-reloadsessionStoragePrevents an infinite reload loop if a newly deployed application version invalidates an old JavaScript chunkRemoved after recovery or when the tab's session ends

2.3 Payment pages (Stripe)

When you subscribe to a paid plan or open the billing portal, you are redirected to pages hosted by Stripe (checkout.stripe.com / billing.stripe.com). On its own pages, Stripe sets cookies necessary for payment processing and fraud prevention under its own cookie policy. We do not embed Stripe scripts or cookies on WCAGC pages.

2.4 Analytics cookies (Google Analytics)

We use Google Analytics 4 (GA4) to understand how visitors interact with our Service (e.g., page views, button clicks) so we can improve it. These cookies are entirely optional. We will only set them if you click "Accept All" on our cookie banner. If you choose "Only Necessary" or ignore the banner, Google Analytics will remain disabled.

NamePurposeDurationProvider
_gaUsed to distinguish browser instances for analytics purposesUp to 60 days from the first consented visit, subject to browser limitsGoogle LLC
_ga_*Used to maintain analytics session stateUp to 60 days from the first consented visit, subject to browser limitsGoogle LLC

For more information on how Google uses data from these cookies, please see Google's Privacy & Terms.

Our GA client configuration disables Google Signals, advertising storage, and advertising-personalization signals. It sets analytics cookies to expire after 60 days without refreshing that expiry on later page loads. Our required GA4 property setting is the shortest standard user/event-data retention period, 2 months. We do not use GA4 for remarketing or link it to advertising products.

You can change your choice at any time with the Cookie settings button shown on the Service. Withdrawing analytics consent disables our GA measurement, removes the GA scripts we loaded, and attempts to delete the _ga cookies for WCAGC from your browser. It does not affect processing that took place before withdrawal. You can also delete cookies and site data through your browser settings.

2.5 Browser extension storage

The wcagc browser extension sets no cookies and loads no analytics. It uses the browser's own extension storage for two things only: the disclosure version you accepted and your interface preferences (language, target standard, selected site, and whether to include source hints), kept in local extension storage; and, if you connect an organization, your access and refresh tokens, kept in memory-only session storage that is cleared when the browser restarts. Both are strictly necessary to provide the functions you asked for, so no consent banner applies. Removing the extension removes both.

3. Managing Cookies in Your Browser

You can block or delete cookies in your browser settings:

Note: blocking the strictly necessary authentication cookies listed in Section 2.1 will prevent you from logging in to the Service. Clearing browser storage also resets the choices and local tool data listed in Section 2.2.

4. Similar Technologies

We do not use web beacons, pixels, fingerprinting, or any other tracking technology. For the free public scan, we store a one-way cryptographic hash of your IP address server-side for rate limiting — this is not a cookie and is described in our Privacy Policy.

5. Changes to This Policy

We may update this Policy when our use of cookies changes. Material changes will be announced as described in the Privacy Policy. The "Last updated" date above reflects the current version.

6. Contact

Questions about this Policy: privacy@wcagc.com.

WCAGC, ul. Garbary 100, 61-757 Poznań, Poland — operator details in our Privacy Policy.

Related documents: Privacy Policy · Terms of Service

The English-language version of these documents is the legally binding one.