Privacy Policy
Version 1.5 — Effective date: August 2, 2026 — Last updated: August 2, 2026
1. Who We Are
This Privacy Policy explains how WCAGC ("we", "us", "our") processes personal data when you visit wcagc.com, use the WCAGC application, request a free public scan, or communicate with us (the "Service").
The Service is operated as a Polish sole proprietorship (jednoosobowa działalność gospodarcza):
- Operator and controller: Pavel Charkasau, trading as WCAGC
- Registered address: ul. Garbary 100, 61-757 Poznań, Poland
- Business registration: NIP 7831856003
- Privacy contact: privacy@wcagc.com
We are the controller for account, billing, security, support, website, and public-scan data. When a Customer instructs us to scan a website, or saves a Local Check that it captured with the Extension in its own browser, and page content is captured incidentally, the Customer is the controller of that content and we act as its processor under the Data Processing Agreement.
2. Personal Data We Process
2.1 Data you provide
| Category | Examples | Why we receive it |
|---|---|---|
| Account data | Email address, display name, password hash, locale | Registration, authentication, and account administration |
| Organization data | Organization name, membership, and role | Tenant access and permissions |
| Site and scan data | URLs submitted for scanning, domain-verification records, scan configuration and results | Performing and displaying requested scans |
| Local Check data | The URL and title of the page you check, your label, detected rules with a bounded markup fragment and selector, an optional relative source-code hint, and capture metadata (engine, extension version, browser, viewport, colour scheme, time) | Saving and displaying a check you captured with the Extension and chose to save |
| Statement and report data | Contact details and text entered into generated accessibility statements or reports | Generating Customer-requested documents |
| Billing data | Stripe customer/subscription identifiers, subscription status, billing country and limited payment metadata returned by Stripe | Subscription administration; card details are entered on Stripe-hosted pages and do not pass through our servers |
| Communications | Emails, support requests, and their contents | Responding to requests and resolving issues |
2.2 Data collected automatically
| Category | Examples | When collected |
|---|---|---|
| Authentication data | Session and refresh identifiers, authentication events, trusted-device token | When you sign in or use an authenticated session |
| Technical and security data | IP address available to the request infrastructure, browser/user-agent, timestamps, requested route, and error information | When operating and securing the Service |
| Public-scan anti-abuse data | HMAC-SHA256 value derived from the requester IP; requested URL and normalized host | When an account-less public scan is requested |
| Optional analytics data | Page path without query parameters, general device/browser information, and a small set of product events | Only after analytics consent |
The public-scan HMAC is pseudonymous data, not anonymous data. The raw IP is not stored in the public-scan database row.
2.3 Data received from Stripe
Stripe sends subscription and payment-status events needed to activate, renew, cancel, or reconcile a subscription. We do not buy personal data and do not receive it from advertising data brokers.
3. Purposes and Legal Bases
| Purpose | Data | GDPR legal basis |
|---|---|---|
| Create accounts, authenticate Users, provide scans, reports, and statements | Account, organization, site, scan, report, and statement data | Art. 6(1)(b), performance of a contract or steps requested before a contract |
| Store, display, and delete Local Checks a User explicitly saves from the Extension, and export a finding to an issue tracker the Customer connected | Local Check data | Art. 6(1)(b) as regards the account holder. For personal data contained in captured page content, the Customer is the controller and we act as its processor under the DPA |
| Manage subscriptions and billing | Billing and subscription data | Art. 6(1)(b); Art. 6(1)(c) for accounting and tax records |
| Send verification, password-reset, scan, statement, and subscription messages | Email address, locale, relevant transactional content | Art. 6(1)(b) |
| Prevent abuse, protect accounts, diagnose failures, and maintain availability | Technical, authentication, security, and HMAC-derived data | Art. 6(1)(f), our legitimate interest in operating a secure and reliable Service |
| Respond to inquiries | Contact details and communication content | Art. 6(1)(b) or Art. 6(1)(f), depending on the request |
| Optional Google Analytics 4 measurement | Optional analytics data | Art. 6(1)(a), consent |
| Meet legal obligations and handle legal claims | Relevant account, billing, communication, and security records | Art. 6(1)(c) or Art. 6(1)(f) |
For security processing based on legitimate interests, we limit data to what is reasonably required, use HMAC-derived values where practical, apply retention limits, and do not use this data to profile users for advertising.
We do not use Customer data to train machine-learning models and do not make solely automated decisions that produce legal or similarly significant effects.
4. Scanned Website Content
Our crawler retrieves publicly accessible pages selected by the Customer and analyzes them for accessibility issues. Page text, HTML excerpts, and screenshots used as evidence may incidentally contain personal data already present on those pages.
For this content, the Customer must have authority and a lawful basis to instruct the scan. We process it only to provide the requested scan and related output, subject to the Data Processing Agreement. This Policy does not replace the scanned website's own privacy notice.
For eligible paid organizations, an owner or administrator may separately enable model-assisted fix guidance. When enabled, bounded page fragments, selectors, rule metadata, or a minimized semantic page digest may be sent to OpenAI. Passwords, authentication envelopes, cookies, form input values, screenshots, and complete page source are excluded. The generated suggestions require human review and are not used by WCAGC to train models.
4.1 Browser extension
The Extension runs a Local Check only after an explicit user action. The boundary is:
| Category | Treatment |
|---|---|
| Never read by the Extension | Cookies, request headers, localStorage and sessionStorage contents, the values you type into form fields, passwords, screenshots, the complete page source, the contents of other tabs, and the browser's history or list of previously visited pages |
| Sent to our server only when you select Save | The page URL and title, your label, the detected rules with the failing element's markup fragment (no more than 2,000 characters) and its selector, the rule's failure summary (no more than 2,000 characters), an optional source-code hint, and capture metadata such as engine, extension version, browser, viewport, colour scheme, and time |
| What a markup fragment can contain | The fragment is the failing element's own markup, as the page rendered it. It can therefore include attribute values and text that the page itself displays, including personal data shown on a page you are signed in to. The Extension does not read what you type into a field, and it does not remove content the page has placed in the element's markup. Choose what you save accordingly |
| Third parties | The Extension itself communicates only with https://api.wcagc.com and contains no third-party analytics. If you separately choose to export a saved finding to an issue tracker you connected, we send that finding — its page URL, selector, markup fragment, failure summary and any source hint — to that tracker (see Section 5) |
Saved Local Checks are deleted after 180 days. A permitted organization member can delete a saved Local Check sooner in the Service. Repository source hints are optional, are accepted only as relative paths, and can be disabled before saving.
5. Recipients and Service Providers
We do not sell personal data and do not disclose it to advertisers.
| Provider | Role and data | Production configuration |
|---|---|---|
| Fly.io, Inc. | Application and worker compute, PostgreSQL and RabbitMQ infrastructure; Service data required by those workloads | Primary resources run in Fly region arn — Stockholm, Sweden. Fly.io is a US provider and may use its published sub-processors |
| Upstash, Inc. (through Fly.io) | Managed Redis used for short-lived rate limits and application coordination | Stockholm, Sweden (arn) |
| Tigris Data, Inc. (through Fly.io) | Private object storage for generated scan images and related files | Globally distributed object storage; processing is not represented as EU-only |
| Pingram (formerly NotificationAPI) | Transactional email delivery; recipient address and message content | EU endpoint configured; the provider documents its EU data centre in Frankfurt, Germany |
| OpenAI | Optional model-assisted remediation guidance and semantic observations; bounded page fragments and rule metadata only after an organization administrator enables the feature | API requests use store=false and API content is not used for model training. Until Zero Data Retention is approved for the dedicated project, provider abuse-monitoring logs may retain request content for up to 30 days; European regional processing is a production launch prerequisite |
| Stripe Payments Europe, Ltd., Link, and Stripe group companies | Merchant-of-record Checkout for new subscriptions; payments, indirect taxes, fraud/disputes, receipts, transaction support, subscriptions, and billing portal | Stripe/Link-hosted payment and order-management surfaces; Ireland and other locations described by Stripe |
| Google Ireland Ltd. and Google LLC | Google Analytics 4, only after consent | Google may process data in the EEA and other countries under its contractual transfer safeguards |
Where a Customer connects an issue tracker (GitHub or Jira) and a User explicitly exports a finding, we transmit that finding — its page URL, selector, markup fragment, failure summary and any source hint — to the tracker instance the Customer nominated, using the credentials the Customer supplied. The Customer chooses and controls that destination; we do not select it and do not use it for any other purpose.
We may also disclose data where required by binding law or a competent authority, after checking the request to the extent legally permitted, or as part of a business transfer subject to appropriate confidentiality and notice.
6. International Transfers
The primary application, worker, PostgreSQL, Redis, and RabbitMQ resources are configured in Stockholm, Sweden. Tigris object storage is globally distributed, and some providers are established in or provide support from countries outside the EEA.
Where Chapter V GDPR applies, we rely on an applicable European Commission adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or the European Commission's Standard Contractual Clauses with supplementary safeguards where appropriate. Contact privacy@wcagc.com to request information about the applicable safeguard.
7. Retention and Deletion
We apply the following production retention rules:
| Data category | Retention |
|---|---|
| Active account, organization, sites, private scans, reports, and statements | While the account or organization is active. On a verified deletion, access is disabled immediately and operational data is deleted or irreversibly anonymized as the deletion workflow completes; there is no 30-day recovery grace period |
| Free public scan row, result, submitted URL, and HMAC-derived IP value | 30 days from creation |
| Optional public-report email lead: normalized email, locale, consent, report severity snapshot, site host, and HMAC-derived IP value | 90 days from creation. Used only to deliver the requested report and, where explicitly selected, one follow-up two days later |
| Public PDF source file | Deleted after processing; an orphan sweep removes abandoned temporary files after approximately 15 minutes |
| Public PDF result and access HMAC | 24 hours |
| Saved Local Checks, bounded markup fragments, selectors, and optional source hints | 180 days from capture, or earlier when deleted by a permitted organization member or through organization deletion |
| Delivered transactional outbox payload | Redacted immediately after successful broker delivery; non-content delivery metadata is deleted after 30 days |
| Stripe webhook idempotency record | Event ID, type, and receipt time for 30 days; no full Stripe payload is stored in this ledger |
| Revoked or expired sessions and refresh-token records | Up to 90 days after they become stale |
| Completed or expired two-factor challenges and fresh-auth grants | Up to 24 hours after they become stale |
| Optional GA4 user-level and event-level data | The shortest standard GA4 user/event retention setting, 2 months; standard aggregated reports are controlled separately by Google |
| Accounting, invoice, and tax records | For the statutory period, generally at least 5 years counted under applicable Polish tax and accounting rules |
| Support and dispute records | Until the matter is resolved, and longer only where reasonably necessary for a legal obligation or the establishment, exercise, or defence of claims |
| Security and application logs | Kept only for the provider's operational window or a shorter configured period, unless a specific record must be preserved for an active security incident or legal claim; no separate indefinite log archive is configured |
Deletion from active systems does not override a legal duty to retain a narrowly defined accounting, tax, fraud-prevention, or claims record. Such retained data is isolated from ordinary product use and used only for that legal purpose. Provider-level disaster-recovery copies that cannot be selectively edited are not used for ordinary processing and age out under the provider's rotation.
8. Google Analytics and Consent
GA4 is not loaded until you affirmatively accept analytics cookies. Our client configuration sends page paths without query strings, does not include submitted scan URLs or scan identifiers in product events, and disables Google Signals and advertising-personalization signals. We do not link GA4 to advertising products for remarketing.
You can reopen Cookie settings at any time and withdraw consent as easily as it was given. Withdrawal disables further collection and removes accessible first-party GA cookies from the browser. It does not make earlier consent unlawful or immediately erase data already received by Google; you may also exercise the rights in Section 9.
See the Cookie Policy for cookie and browser-storage details.
9. Your Rights
Subject to the conditions in the GDPR, you may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), or object to processing based on legitimate interests (Art. 21). You may withdraw consent at any time without affecting processing carried out before withdrawal.
Email privacy@wcagc.com. We normally respond within one month; GDPR permits an extension of up to two additional months for complex or numerous requests, with notice. We may request proportionate information needed to verify identity. Requests are free unless manifestly unfounded or excessive as provided by law.
You may complain to the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl, or another competent supervisory authority. If your data appears in a Customer-controlled website scan, contact that Customer first; we will assist it as processor.
10. Adults Only
The Service is intended only for persons aged 18 or older. We do not knowingly permit minors to create accounts. If we learn that a minor has provided account data, we will disable the account and delete or anonymize the data unless retention is legally required.
11. Security and Breach Handling
We use measures appropriate to the risk, including TLS, salted password hashes, HTTP-only Secure authentication cookies, CSRF protection, role-based tenant access, restricted production access, managed secret storage, HMAC-derived public-scan identifiers, and provider-side storage protections.
No system is completely secure. If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours where Article 33 GDPR requires it. We will notify affected individuals without undue delay where Article 34 GDPR requires it. When acting as processor, we notify the affected Customer without undue delay under the DPA.
12. Policy Changes and Contact
We may update this Policy to reflect legal, provider, or Service changes. We will provide notice of material changes where required by law or where the change materially affects account holders. The version and update date above identify the applicable text.
- Controller: Pavel Charkasau, trading as WCAGC
- Address: ul. Garbary 100, 61-757 Poznań, Poland
- Privacy: privacy@wcagc.com
- General contact: hello@wcagc.com
Related documents: Terms of Service · Cookie Policy · Data Processing Agreement · Acceptable Use Policy
The English-language version of these documents is the legally binding one.