Cookie Policy
Version 1.2 — Effective date: August 2, 2026 — Last updated: August 2, 2026
This Cookie Policy explains how WCAGC ("we") uses cookies and similar technologies on wcagc.com and app.wcagc.com (the "Service"). It supplements our Privacy Policy.
1. What Are Cookies
Cookies are small text files that a website stores on your device. They can be session cookies (deleted when you close your browser) or persistent cookies (kept until they expire or you delete them), and first-party (set by us) or third-party (set by another domain).
We also use browser web storage (localStorage and sessionStorage) — a related technology that stores small pieces of data in your browser without sending them to a server automatically.
2. How We Use Cookies
We use strictly necessary cookies, preference storage, and optional analytics cookies. Because we use optional analytics cookies (Google Analytics), we ask for your explicit consent via a cookie consent banner before setting them, in compliance with the ePrivacy Directive and GDPR.
2.1 Strictly necessary cookies
These first-party cookies are required to log you in, protect authenticated requests, and — only if you choose it during two-step verification — remember a trusted browser. They are marked Secure in production and SameSite=Lax. The CSRF cookie must be readable by the application so it can be copied into a request header; the other authentication cookies are HTTP-only.
| Name | Purpose | Duration | Provider |
|---|---|---|---|
access_token | Authenticates your requests to the API during a session | 15 minutes | WCAGC (first-party) |
refresh_token | Allows your session to be renewed without logging in again | 30 days | WCAGC (first-party) |
csrf_token | Protects state-changing requests against cross-site request forgery; readable by the application | 30 days | WCAGC (first-party) |
trusted_device | Remembers a browser that you explicitly choose to trust after two-step verification | 30 days | WCAGC (first-party) |
2.2 Preference storage (browser web storage)
These values are stored in your browser's localStorage or sessionStorage. They never leave your device as tracking data and contain no identifiers usable across other websites.
| Key | Type | Purpose | Duration |
|---|---|---|---|
wcagc-theme | localStorage | Remembers your light/dark/system theme choice | Until you clear it |
i18nextLng | localStorage | Remembers your interface language | Until you clear it |
wcagc-cookie-consent | localStorage | Remembers your cookie banner choices (whether you accepted or rejected analytics) | Until you clear it |
wcagc_checklist_*, wcagc_notes_* | localStorage | Saves progress and notes entered in the public interactive checklists on that browser | Until you clear it |
wcagc.resumeAfterUpgrade | sessionStorage | Remembers the in-app page and feature to resume after a Stripe checkout redirect | Removed after use, after about 1 hour, or when the tab's session ends |
wcagc.2fa.challengeToken | sessionStorage | Holds an opaque two-step-verification challenge between the password and code screens | Removed after verification or expiry, or when the tab's session ends |
chunk-error-reload | sessionStorage | Prevents an infinite reload loop if a newly deployed application version invalidates an old JavaScript chunk | Removed after recovery or when the tab's session ends |
2.3 Payment pages (Stripe)
When you subscribe to a paid plan or open the billing portal, you are redirected to pages hosted by Stripe (checkout.stripe.com / billing.stripe.com). On its own pages, Stripe sets cookies necessary for payment processing and fraud prevention under its own cookie policy. We do not embed Stripe scripts or cookies on WCAGC pages.
2.4 Analytics cookies (Google Analytics)
We use Google Analytics 4 (GA4) to understand how visitors interact with our Service (e.g., page views, button clicks) so we can improve it. These cookies are entirely optional. We will only set them if you click "Accept All" on our cookie banner. If you choose "Only Necessary" or ignore the banner, Google Analytics will remain disabled.
| Name | Purpose | Duration | Provider |
|---|---|---|---|
_ga | Used to distinguish browser instances for analytics purposes | Up to 60 days from the first consented visit, subject to browser limits | Google LLC |
_ga_* | Used to maintain analytics session state | Up to 60 days from the first consented visit, subject to browser limits | Google LLC |
For more information on how Google uses data from these cookies, please see Google's Privacy & Terms.
Our GA client configuration disables Google Signals, advertising storage, and advertising-personalization signals. It sets analytics cookies to expire after 60 days without refreshing that expiry on later page loads. Our required GA4 property setting is the shortest standard user/event-data retention period, 2 months. We do not use GA4 for remarketing or link it to advertising products.
You can change your choice at any time with the Cookie settings button shown on the Service. Withdrawing analytics consent disables our GA measurement, removes the GA scripts we loaded, and attempts to delete the _ga cookies for WCAGC from your browser. It does not affect processing that took place before withdrawal. You can also delete cookies and site data through your browser settings.
2.5 Browser extension storage
The wcagc browser extension sets no cookies and loads no analytics. It uses the browser's own extension storage for two things only: the disclosure version you accepted and your interface preferences (language, target standard, selected site, and whether to include source hints), kept in local extension storage; and, if you connect an organization, your access and refresh tokens, kept in memory-only session storage that is cleared when the browser restarts. Both are strictly necessary to provide the functions you asked for, so no consent banner applies. Removing the extension removes both.
3. Managing Cookies in Your Browser
You can block or delete cookies in your browser settings:
Note: blocking the strictly necessary authentication cookies listed in Section 2.1 will prevent you from logging in to the Service. Clearing browser storage also resets the choices and local tool data listed in Section 2.2.
4. Similar Technologies
We do not use web beacons, pixels, fingerprinting, or any other tracking technology. For the free public scan, we store a one-way cryptographic hash of your IP address server-side for rate limiting — this is not a cookie and is described in our Privacy Policy.
5. Changes to This Policy
We may update this Policy when our use of cookies changes. Material changes will be announced as described in the Privacy Policy. The "Last updated" date above reflects the current version.
6. Contact
Questions about this Policy: privacy@wcagc.com.
WCAGC, ul. Garbary 100, 61-757 Poznań, Poland — operator details in our Privacy Policy.
Related documents: Privacy Policy · Terms of Service
The English-language version of these documents is the legally binding one.