Skip to content

Privacy Policy

Version 1.6 — Effective date: August 8, 2026 — Last updated: August 8, 2026

1. Who We Are

This Privacy Policy explains how WCAGC ("we", "us", "our") processes personal data when you visit wcagc.com, use the WCAGC application, request a free public scan, or communicate with us (the "Service").

The Service is operated as a Polish sole proprietorship (jednoosobowa działalność gospodarcza):

  • Operator and controller: Pavel Charkasau, trading as WCAGC
  • Registered address: ul. Garbary 100, 61-757 Poznań, Poland
  • Business registration: NIP 7831856003
  • Privacy contact: privacy@wcagc.com

We are the controller for account, billing, security, support, website, and public-scan data. When a Customer instructs us to scan a website, or saves a Local Check that it captured with the Extension in its own browser, and page content is captured incidentally, the Customer is the controller of that content and we act as its processor under the Data Processing Agreement.

2. Personal Data We Process

2.1 Data you provide

CategoryExamplesWhy we receive it
Account dataEmail address, display name, password hash, localeRegistration, authentication, and account administration
Organization dataOrganization name, membership, and roleTenant access and permissions
Site and scan dataURLs submitted for scanning, domain-verification records, scan configuration and resultsPerforming and displaying requested scans
Local Check dataThe URL and title of the page you check, your label, detected rules with a bounded markup fragment and selector, an optional relative source-code hint, and capture metadata (engine, extension version, browser, viewport, colour scheme, time)Saving and displaying a check you captured with the Extension and chose to save
Statement and report dataContact details and text entered into generated accessibility statements or reportsGenerating Customer-requested documents
Billing dataStripe customer/subscription identifiers, subscription status, billing country and limited payment metadata returned by StripeSubscription administration; card details are entered on Stripe-hosted pages and do not pass through our servers
CommunicationsEmails, support requests, and their contentsResponding to requests and resolving issues

2.2 Data collected automatically

CategoryExamplesWhen collected
Authentication dataSession and refresh identifiers, authentication events, trusted-device tokenWhen you sign in or use an authenticated session
Technical and security dataIP address available to the request infrastructure, browser/user-agent, timestamps, requested route, and error informationWhen operating and securing the Service
Public-scan anti-abuse dataHMAC-SHA256 value derived from the requester IP; requested URL and normalized hostWhen an account-less public scan is requested
Optional analytics dataPage path without query parameters, general device/browser information, and a small set of product eventsOnly after analytics consent

The public-scan HMAC is pseudonymous data, not anonymous data. The raw IP is not stored in the public-scan database row.

2.3 Data received from Stripe

Stripe sends subscription and payment-status events needed to activate, renew, cancel, or reconcile a subscription. We do not buy personal data and do not receive it from advertising data brokers.

3. Purposes and Legal Bases

PurposeDataGDPR legal basis
Create accounts, authenticate Users, provide scans, reports, and statementsAccount, organization, site, scan, report, and statement dataArt. 6(1)(b), performance of a contract or steps requested before a contract
Store, display, and delete Local Checks a User explicitly saves from the Extension, and export a finding to an issue tracker the Customer connectedLocal Check dataArt. 6(1)(b) as regards the account holder. For personal data contained in captured page content, the Customer is the controller and we act as its processor under the DPA
Manage subscriptions and billingBilling and subscription dataArt. 6(1)(b); Art. 6(1)(c) for accounting and tax records
Send verification, password-reset, scan, statement, and subscription messagesEmail address, locale, relevant transactional contentArt. 6(1)(b)
Prevent abuse, protect accounts, diagnose failures, and maintain availabilityTechnical, authentication, security, and HMAC-derived dataArt. 6(1)(f), our legitimate interest in operating a secure and reliable Service
Respond to inquiriesContact details and communication contentArt. 6(1)(b) or Art. 6(1)(f), depending on the request
Optional Google Analytics 4 measurementOptional analytics dataArt. 6(1)(a), consent
Meet legal obligations and handle legal claimsRelevant account, billing, communication, and security recordsArt. 6(1)(c) or Art. 6(1)(f)

For security processing based on legitimate interests, we limit data to what is reasonably required, use HMAC-derived values where practical, apply retention limits, and do not use this data to profile users for advertising.

We do not use Customer data to train machine-learning models and do not make solely automated decisions that produce legal or similarly significant effects.

4. Scanned Website Content

Our crawler retrieves publicly accessible pages selected by the Customer and analyzes them for accessibility issues. Page text, HTML excerpts, and screenshots used as evidence may incidentally contain personal data already present on those pages.

For this content, the Customer must have authority and a lawful basis to instruct the scan. We process it only to provide the requested scan and related output, subject to the Data Processing Agreement. This Policy does not replace the scanned website's own privacy notice.

An owner or administrator may separately enable model-assisted fix guidance; a limited monthly allowance is available on every plan, including the free plan. When enabled, bounded page fragments, selectors, rule metadata, or a minimized semantic page digest may be sent to Amazon Bedrock, where a geography-restricted inference profile confines processing to AWS European regions and never routes it outside the EU. For fix guidance, passwords, authentication envelopes, cookies, form input values, screenshots, and complete page source are excluded, and email addresses, telephone numbers, and long numeric identifiers are masked in what remains before the request leaves us. Amazon Bedrock is configured with account-level data retention set to none in every AWS European region the inference profile can reach, so request and response content is not retained after the response is returned; it is not shared with third-party model providers and is not used to train models. Content may still be examined where Amazon's abuse-detection processes flag it. The generated suggestions require human review and are not used by WCAGC to train models.

Screenshot analysis is a separate feature with a separate consent, described in Section 4.1. Enabling fix guidance does not enable it.

4.1 Screenshot analysis (visual checks)

Some accessibility problems are only visible in a rendered page — text over a photograph, what a focus outline actually looks like, an element hidden behind an overlay. On plans that include it, an organization can ask us to capture one screenshot of one page it has verified and send that image to Amazon Bedrock for comment.

We treat this as a different kind of processing from everything else in this Section, and we want to be direct about why. A screenshot can contain any personal data the page displays — a name in a header, an address in a table, the contents of a signed-in user's account — and the masking we apply to text cannot be applied to an image. There is no version of this feature in which the image is minimized in the way a markup fragment is.

Because of that, it is governed by its own controls:

ControlWhat it means
Separate consentAn owner or administrator must enable screenshot analysis specifically. It is off by default, and enabling model-assisted fix guidance does not enable it. Turning fix guidance off also turns screenshot analysis off; turning fix guidance back on does not turn it back on
Only on requestOne image per check, started by a person in the Service. It never runs in the background, never runs on a schedule, and is never part of an ordinary scan
Only on verified sitesThe page must be on a site the organization has proved it controls
Only on paid plansScreenshot analysis is available on the Professional and Agency plans. It is not available on the free or entry plans
What is capturedOne screenshot of the visible area of the page at the moment of capture, not the full length of the page, plus the position and size of elements that already failed an automated check. No text is taken from those positions
DeletionWe delete the image within 24 hours of capture and stop serving it at the 24-hour mark whether or not the scheduled deletion pass has run. The written observations are kept with the check; the image is not
Same provider termsThe image goes to the same geography-restricted Amazon Bedrock profile as everything else in this Section, under the same retention setting of none, the same no-training and no-sharing terms, and the same abuse-detection caveat
Not a findingWhat comes back is labelled as needing human confirmation. It is never counted as an accessibility finding, never appears in your issue totals, trend, comparison, CI result, or evidence pack, and never produces a score or a conclusion about compliance

A Customer must not run a visual check on a page whose content is predominantly special-category or criminal-offence data. That restriction already applies to scanning generally under the Data Processing Agreement, and it matters more here, because an image cannot be masked.

4.2 Browser extension

The Extension runs a Local Check only after an explicit user action. The boundary is:

CategoryTreatment
Never read by the ExtensionCookies, request headers, localStorage and sessionStorage contents, the values you type into form fields, passwords, screenshots, the complete page source, the contents of other tabs, and the browser's history or list of previously visited pages
Sent to our server only when you select SaveThe page URL and title, your label, the detected rules with the failing element's markup fragment (no more than 2,000 characters) and its selector, the rule's failure summary (no more than 2,000 characters), an optional source-code hint, and capture metadata such as engine, extension version, browser, viewport, colour scheme, and time
What a markup fragment can containThe fragment is the failing element's own markup, as the page rendered it. It can therefore include attribute values and text that the page itself displays, including personal data shown on a page you are signed in to. The Extension does not read what you type into a field, and it does not remove content the page has placed in the element's markup. Choose what you save accordingly
Third partiesThe Extension itself communicates only with https://api.wcagc.com and contains no third-party analytics. If you separately choose to export a saved finding to an issue tracker you connected, we send that finding — its page URL, selector, markup fragment, failure summary and any source hint — to that tracker (see Section 5)

Saved Local Checks are deleted after 180 days. A permitted organization member can delete a saved Local Check sooner in the Service. Repository source hints are optional, are accepted only as relative paths, and can be disabled before saving.

5. Recipients and Service Providers

We do not sell personal data and do not disclose it to advertisers.

ProviderRole and dataProduction configuration
Fly.io, Inc.Application and worker compute, PostgreSQL and RabbitMQ infrastructure; Service data required by those workloadsPrimary resources run in Fly region arn — Stockholm, Sweden. Fly.io is a US provider and may use its published sub-processors
Upstash, Inc. (through Fly.io)Managed Redis used for short-lived rate limits and application coordinationStockholm, Sweden (arn)
Tigris Data, Inc. (through Fly.io)Private object storage for generated scan images and related filesGlobally distributed object storage; processing is not represented as EU-only
Pingram (formerly NotificationAPI)Transactional email delivery; recipient address and message contentEU endpoint configured; the provider documents its EU data centre in Frankfurt, Germany
Amazon Web Services EMEA SARL (Amazon Bedrock)Optional model-assisted remediation guidance and semantic observations; bounded page fragments and rule metadata only after an organization administrator enables the featureA geography-restricted (eu.*) inference profile confines processing within AWS European regions (request entry point eu-north-1, Stockholm; the profile may route inference to other AWS EU regions, and to no region outside the EU). Email addresses, telephone numbers, payment card numbers, IBANs and other long numeric identifiers are masked before a request leaves us. Account-level data retention is set to none in every reachable EU region, so content is not retained after the response, not shared with third-party model providers and not used for training; model invocation logging is not enabled. Amazon's abuse-detection processes may still examine flagged content
Stripe Payments Europe, Ltd., Link, and Stripe group companiesMerchant-of-record Checkout for new subscriptions; payments, indirect taxes, fraud/disputes, receipts, transaction support, subscriptions, and billing portalStripe/Link-hosted payment and order-management surfaces; Ireland and other locations described by Stripe
Google Ireland Ltd. and Google LLCGoogle Analytics 4, only after consentGoogle may process data in the EEA and other countries under its contractual transfer safeguards

Where a Customer connects an issue tracker (GitHub or Jira) and a User explicitly exports a finding, we transmit that finding — its page URL, selector, markup fragment, failure summary and any source hint — to the tracker instance the Customer nominated, using the credentials the Customer supplied. The Customer chooses and controls that destination; we do not select it and do not use it for any other purpose.

We may also disclose data where required by binding law or a competent authority, after checking the request to the extent legally permitted, or as part of a business transfer subject to appropriate confidentiality and notice.

6. International Transfers

The primary application, worker, PostgreSQL, Redis, and RabbitMQ resources are configured in Stockholm, Sweden. Tigris object storage is globally distributed, and some providers are established in or provide support from countries outside the EEA.

Where Chapter V GDPR applies, we rely on an applicable European Commission adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or the European Commission's Standard Contractual Clauses with supplementary safeguards where appropriate. Contact privacy@wcagc.com to request information about the applicable safeguard.

7. Retention and Deletion

We apply the following production retention rules:

Data categoryRetention
Active account, organization, sites, private scans, reports, and statementsWhile the account or organization is active. On a verified deletion, access is disabled immediately and operational data is deleted or irreversibly anonymized as the deletion workflow completes; there is no 30-day recovery grace period
Free public scan row, result, submitted URL, and HMAC-derived IP value30 days from creation
Optional public-report email lead: normalized email, locale, consent, report severity snapshot, site host, and HMAC-derived IP value90 days from creation. Used only to deliver the requested report and, where explicitly selected, one follow-up two days later
Public PDF source fileDeleted after processing; an orphan sweep removes abandoned temporary files after approximately 15 minutes
Public PDF result and access HMAC24 hours
Saved Local Checks, bounded markup fragments, selectors, and optional source hints180 days from capture, or earlier when deleted by a permitted organization member or through organization deletion
Delivered transactional outbox payloadRedacted immediately after successful broker delivery; non-content delivery metadata is deleted after 30 days
Stripe webhook idempotency recordEvent ID, type, and receipt time for 30 days; no full Stripe payload is stored in this ledger
Revoked or expired sessions and refresh-token recordsUp to 90 days after they become stale
Completed or expired two-factor challenges and fresh-auth grantsUp to 24 hours after they become stale
Optional GA4 user-level and event-level dataThe shortest standard GA4 user/event retention setting, 2 months; standard aggregated reports are controlled separately by Google
Accounting, invoice, and tax recordsFor the statutory period, generally at least 5 years counted under applicable Polish tax and accounting rules
Support and dispute recordsUntil the matter is resolved, and longer only where reasonably necessary for a legal obligation or the establishment, exercise, or defence of claims
Security and application logsKept only for the provider's operational window or a shorter configured period, unless a specific record must be preserved for an active security incident or legal claim; no separate indefinite log archive is configured

Deletion from active systems does not override a legal duty to retain a narrowly defined accounting, tax, fraud-prevention, or claims record. Such retained data is isolated from ordinary product use and used only for that legal purpose. Provider-level disaster-recovery copies that cannot be selectively edited are not used for ordinary processing and age out under the provider's rotation.

8. Google Analytics and Consent

GA4 is not loaded until you affirmatively accept analytics cookies. Our client configuration sends page paths without query strings, does not include submitted scan URLs or scan identifiers in product events, and disables Google Signals and advertising-personalization signals. We do not link GA4 to advertising products for remarketing.

You can reopen Cookie settings at any time and withdraw consent as easily as it was given. Withdrawal disables further collection and removes accessible first-party GA cookies from the browser. It does not make earlier consent unlawful or immediately erase data already received by Google; you may also exercise the rights in Section 9.

See the Cookie Policy for cookie and browser-storage details.

9. Your Rights

Subject to the conditions in the GDPR, you may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), or object to processing based on legitimate interests (Art. 21). You may withdraw consent at any time without affecting processing carried out before withdrawal.

Email privacy@wcagc.com. We normally respond within one month; GDPR permits an extension of up to two additional months for complex or numerous requests, with notice. We may request proportionate information needed to verify identity. Requests are free unless manifestly unfounded or excessive as provided by law.

You may complain to the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl, or another competent supervisory authority. If your data appears in a Customer-controlled website scan, contact that Customer first; we will assist it as processor.

10. Adults Only

The Service is intended only for persons aged 18 or older. We do not knowingly permit minors to create accounts. If we learn that a minor has provided account data, we will disable the account and delete or anonymize the data unless retention is legally required.

11. Security and Breach Handling

We use measures appropriate to the risk, including TLS, salted password hashes, HTTP-only Secure authentication cookies, CSRF protection, role-based tenant access, restricted production access, managed secret storage, HMAC-derived public-scan identifiers, and provider-side storage protections.

No system is completely secure. If a personal data breach occurs, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours where Article 33 GDPR requires it. We will notify affected individuals without undue delay where Article 34 GDPR requires it. When acting as processor, we notify the affected Customer without undue delay under the DPA.

12. Policy Changes and Contact

We may update this Policy to reflect legal, provider, or Service changes. We will provide notice of material changes where required by law or where the change materially affects account holders. The version and update date above identify the applicable text.

Related documents: Terms of Service · Cookie Policy · Data Processing Agreement · Acceptable Use Policy

The English-language version of these documents is the legally binding one.