Skip to content

Privacy Policy

Version 1.5 — Effective date: August 2, 2026 — Last updated: August 2, 2026

1. Who We Are

This Privacy Policy explains how WCAGC ("we", "us", "our") processes personal data when you visit wcagc.com, use the WCAGC application, request a free public scan, or communicate with us (the "Service").

The Service is operated as a Polish sole proprietorship (jednoosobowa działalność gospodarcza):

  • Operator and controller: Pavel Charkasau, trading as WCAGC
  • Registered address: ul. Garbary 100, 61-757 Poznań, Poland
  • Business registration: NIP 7831856003
  • Privacy contact: privacy@wcagc.com

We are the controller for account, billing, security, support, website, and public-scan data. When a Customer instructs us to scan a website, or saves a Local Check that it captured with the Extension in its own browser, and page content is captured incidentally, the Customer is the controller of that content and we act as its processor under the Data Processing Agreement.

2. Personal Data We Process

2.1 Data you provide

CategoryExamplesWhy we receive it
Account dataEmail address, display name, password hash, localeRegistration, authentication, and account administration
Organization dataOrganization name, membership, and roleTenant access and permissions
Site and scan dataURLs submitted for scanning, domain-verification records, scan configuration and resultsPerforming and displaying requested scans
Local Check dataThe URL and title of the page you check, your label, detected rules with a bounded markup fragment and selector, an optional relative source-code hint, and capture metadata (engine, extension version, browser, viewport, colour scheme, time)Saving and displaying a check you captured with the Extension and chose to save
Statement and report dataContact details and text entered into generated accessibility statements or reportsGenerating Customer-requested documents
Billing dataStripe customer/subscription identifiers, subscription status, billing country and limited payment metadata returned by StripeSubscription administration; card details are entered on Stripe-hosted pages and do not pass through our servers
CommunicationsEmails, support requests, and their contentsResponding to requests and resolving issues

2.2 Data collected automatically

CategoryExamplesWhen collected
Authentication dataSession and refresh identifiers, authentication events, trusted-device tokenWhen you sign in or use an authenticated session
Technical and security dataIP address available to the request infrastructure, browser/user-agent, timestamps, requested route, and error informationWhen operating and securing the Service
Public-scan anti-abuse dataHMAC-SHA256 value derived from the requester IP; requested URL and normalized hostWhen an account-less public scan is requested
Optional analytics dataPage path without query parameters, general device/browser information, and a small set of product eventsOnly after analytics consent

The public-scan HMAC is pseudonymous data, not anonymous data. The raw IP is not stored in the public-scan database row.

2.3 Data received from Stripe

Stripe sends subscription and payment-status events needed to activate, renew, cancel, or reconcile a subscription. We do not buy personal data and do not receive it from advertising data brokers.

3. Purposes and Legal Bases

PurposeDataGDPR legal basis
Create accounts, authenticate Users, provide scans, reports, and statementsAccount, organization, site, scan, report, and statement dataArt. 6(1)(b), performance of a contract or steps requested before a contract
Store, display, and delete Local Checks a User explicitly saves from the Extension, and export a finding to an issue tracker the Customer connectedLocal Check dataArt. 6(1)(b) as regards the account holder. For personal data contained in captured page content, the Customer is the controller and we act as its processor under the DPA
Manage subscriptions and billingBilling and subscription dataArt. 6(1)(b); Art. 6(1)(c) for accounting and tax records
Send verification, password-reset, scan, statement, and subscription messagesEmail address, locale, relevant transactional contentArt. 6(1)(b)
Prevent abuse, protect accounts, diagnose failures, and maintain availabilityTechnical, authentication, security, and HMAC-derived dataArt. 6(1)(f), our legitimate interest in operating a secure and reliable Service
Respond to inquiriesContact details and communication contentArt. 6(1)(b) or Art. 6(1)(f), depending on the request
Optional Google Analytics 4 measurementOptional analytics dataArt. 6(1)(a), consent
Meet legal obligations and handle legal claimsRelevant account, billing, communication, and security recordsArt. 6(1)(c) or Art. 6(1)(f)

For security processing based on legitimate interests, we limit data to what is reasonably required, use HMAC-derived values where practical, apply retention limits, and do not use this data to profile users for advertising.

We do not use Customer data to train machine-learning models and do not make solely automated decisions that produce legal or similarly significant effects.

4. Scanned Website Content

Our crawler retrieves publicly accessible pages selected by the Customer and analyzes them for accessibility issues. Page text, HTML excerpts, and screenshots used as evidence may incidentally contain personal data already present on those pages.

For this content, the Customer must have authority and a lawful basis to instruct the scan. We process it only to provide the requested scan and related output, subject to the Data Processing Agreement. This Policy does not replace the scanned website's own privacy notice.

For eligible paid organizations, an owner or administrator may separately enable model-assisted fix guidance. When enabled, bounded page fragments, selectors, rule metadata, or a minimized semantic page digest may be sent to OpenAI. Passwords, authentication envelopes, cookies, form input values, screenshots, and complete page source are excluded. The generated suggestions require human review and are not used by WCAGC to train models.

4.1 Browser extension

The Extension runs a Local Check only after an explicit user action. The boundary is:

CategoryTreatment
Never read by the ExtensionCookies, request headers, localStorage and sessionStorage contents, the values you type into form fields, passwords, screenshots, the complete page source, the contents of other tabs, and the browser's history or list of previously visited pages
Sent to our server only when you select SaveThe page URL and title, your label, the detected rules with the failing element's markup fragment (no more than 2,000 characters) and its selector, the rule's failure summary (no more than 2,000 characters), an optional source-code hint, and capture metadata such as engine, extension version, browser, viewport, colour scheme, and time
What a markup fragment can containThe fragment is the failing element's own markup, as the page rendered it. It can therefore include attribute values and text that the page itself displays, including personal data shown on a page you are signed in to. The Extension does not read what you type into a field, and it does not remove content the page has placed in the element's markup. Choose what you save accordingly
Third partiesThe Extension itself communicates only with https://api.wcagc.com and contains no third-party analytics. If you separately choose to export a saved finding to an issue tracker you connected, we send that finding — its page URL, selector, markup fragment, failure summary and any source hint — to that tracker (see Section 5)

Saved Local Checks are deleted after 180 days. A permitted organization member can delete a saved Local Check sooner in the Service. Repository source hints are optional, are accepted only as relative paths, and can be disabled before saving.

5. Recipients and Service Providers

We do not sell personal data and do not disclose it to advertisers.

ProviderRole and dataProduction configuration
Fly.io, Inc.Application and worker compute, PostgreSQL and RabbitMQ infrastructure; Service data required by those workloadsPrimary resources run in Fly region arn — Stockholm, Sweden. Fly.io is a US provider and may use its published sub-processors
Upstash, Inc. (through Fly.io)Managed Redis used for short-lived rate limits and application coordinationStockholm, Sweden (arn)
Tigris Data, Inc. (through Fly.io)Private object storage for generated scan images and related filesGlobally distributed object storage; processing is not represented as EU-only
Pingram (formerly NotificationAPI)Transactional email delivery; recipient address and message contentEU endpoint configured; the provider documents its EU data centre in Frankfurt, Germany
OpenAIOptional model-assisted remediation guidance and semantic observations; bounded page fragments and rule metadata only after an organization administrator enables the featureAPI requests use store=false and API content is not used for model training. Until Zero Data Retention is approved for the dedicated project, provider abuse-monitoring logs may retain request content for up to 30 days; European regional processing is a production launch prerequisite
Stripe Payments Europe, Ltd., Link, and Stripe group companiesMerchant-of-record Checkout for new subscriptions; payments, indirect taxes, fraud/disputes, receipts, transaction support, subscriptions, and billing portalStripe/Link-hosted payment and order-management surfaces; Ireland and other locations described by Stripe
Google Ireland Ltd. and Google LLCGoogle Analytics 4, only after consentGoogle may process data in the EEA and other countries under its contractual transfer safeguards

Where a Customer connects an issue tracker (GitHub or Jira) and a User explicitly exports a finding, we transmit that finding — its page URL, selector, markup fragment, failure summary and any source hint — to the tracker instance the Customer nominated, using the credentials the Customer supplied. The Customer chooses and controls that destination; we do not select it and do not use it for any other purpose.

We may also disclose data where required by binding law or a competent authority, after checking the request to the extent legally permitted, or as part of a business transfer subject to appropriate confidentiality and notice.

6. International Transfers

The primary application, worker, PostgreSQL, Redis, and RabbitMQ resources are configured in Stockholm, Sweden. Tigris object storage is globally distributed, and some providers are established in or provide support from countries outside the EEA.

Where Chapter V GDPR applies, we rely on an applicable European Commission adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or the European Commission's Standard Contractual Clauses with supplementary safeguards where appropriate. Contact privacy@wcagc.com to request information about the applicable safeguard.

7. Retention and Deletion

We apply the following production retention rules:

Data categoryRetention
Active account, organization, sites, private scans, reports, and statementsWhile the account or organization is active. On a verified deletion, access is disabled immediately and operational data is deleted or irreversibly anonymized as the deletion workflow completes; there is no 30-day recovery grace period
Free public scan row, result, submitted URL, and HMAC-derived IP value30 days from creation
Optional public-report email lead: normalized email, locale, consent, report severity snapshot, site host, and HMAC-derived IP value90 days from creation. Used only to deliver the requested report and, where explicitly selected, one follow-up two days later
Public PDF source fileDeleted after processing; an orphan sweep removes abandoned temporary files after approximately 15 minutes
Public PDF result and access HMAC24 hours
Saved Local Checks, bounded markup fragments, selectors, and optional source hints180 days from capture, or earlier when deleted by a permitted organization member or through organization deletion
Delivered transactional outbox payloadRedacted immediately after successful broker delivery; non-content delivery metadata is deleted after 30 days
Stripe webhook idempotency recordEvent ID, type, and receipt time for 30 days; no full Stripe payload is stored in this ledger
Revoked or expired sessions and refresh-token recordsUp to 90 days after they become stale
Completed or expired two-factor challenges and fresh-auth grantsUp to 24 hours after they become stale
Optional GA4 user-level and event-level dataThe shortest standard GA4 user/event retention setting, 2 months; standard aggregated reports are controlled separately by Google
Accounting, invoice, and tax recordsFor the statutory period, generally at least 5 years counted under applicable Polish tax and accounting rules
Support and dispute recordsUntil the matter is resolved, and longer only where reasonably necessary for a legal obligation or the establishment, exercise, or defence of claims
Security and application logsKept only for the provider's operational window or a shorter configured period, unless a specific record must be preserved for an active security incident or legal claim; no separate indefinite log archive is configured

Deletion from active systems does not override a legal duty to retain a narrowly defined accounting, tax, fraud-prevention, or claims record. Such retained data is isolated from ordinary product use and used only for that legal purpose. Provider-level disaster-recovery copies that cannot be selectively edited are not used for ordinary processing and age out under the provider's rotation.

8. Google Analytics and Consent

GA4 is not loaded until you affirmatively accept analytics cookies. Our client configuration sends page paths without query strings, does not include submitted scan URLs or scan identifiers in product events, and disables Google Signals and advertising-personalization signals. We do not link GA4 to advertising products for remarketing.

You can reopen Cookie settings at any time and withdraw consent as easily as it was given. Withdrawal disables further collection and removes accessible first-party GA cookies from the browser. It does not make earlier consent unlawful or immediately erase data already received by Google; you may also exercise the rights in Section 9.

See the Cookie Policy for cookie and browser-storage details.

9. Your Rights

Subject to the conditions in the GDPR, you may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), or object to processing based on legitimate interests (Art. 21). You may withdraw consent at any time without affecting processing carried out before withdrawal.

Email privacy@wcagc.com. We normally respond within one month; GDPR permits an extension of up to two additional months for complex or numerous requests, with notice. We may request proportionate information needed to verify identity. Requests are free unless manifestly unfounded or excessive as provided by law.

You may complain to the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl, or another competent supervisory authority. If your data appears in a Customer-controlled website scan, contact that Customer first; we will assist it as processor.

10. Adults Only

The Service is intended only for persons aged 18 or older. We do not knowingly permit minors to create accounts. If we learn that a minor has provided account data, we will disable the account and delete or anonymize the data unless retention is legally required.

11. Security and Breach Handling

We use measures appropriate to the risk, including TLS, salted password hashes, HTTP-only Secure authentication cookies, CSRF protection, role-based tenant access, restricted production access, managed secret storage, HMAC-derived public-scan identifiers, and provider-side storage protections.

No system is completely secure. If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours where Article 33 GDPR requires it. We will notify affected individuals without undue delay where Article 34 GDPR requires it. When acting as processor, we notify the affected Customer without undue delay under the DPA.

12. Policy Changes and Contact

We may update this Policy to reflect legal, provider, or Service changes. We will provide notice of material changes where required by law or where the change materially affects account holders. The version and update date above identify the applicable text.

Related documents: Terms of Service · Cookie Policy · Data Processing Agreement · Acceptable Use Policy

The English-language version of these documents is the legally binding one.