Privacy Policy
Last updated: August 24, 2026
This Privacy Policy describes how AllyProof ("we", "us", "our"), operated as a sole proprietorship registered in Ukraine, collects, uses, and protects your personal data when you use the AllyProof platform, including the AllyProof browser extension for Chrome, Microsoft Edge, and Firefox (collectively, the "Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller
AllyProof is the data controller for the personal data we collect through the Service. For billing-related data, Paddle.com Market Limited acts as an independent data controller. See Paddle's Privacy Policy for details on how they handle payment data.
Contact: legal@allyproof.com
2. Data We Collect
2.1 Account Data
When you create an account, we collect:
- Email address — for authentication, communication, and account recovery
- Full name — for display in the application and team features
- Profile picture URL — if you sign in via Google or GitHub OAuth
- Organization name — for multi-tenant workspace management
2.2 Service Usage Data
When you use the Service, we collect:
- Site URLs — websites you add for accessibility scanning
- Scan results — accessibility violations found, including page URLs, violation details, and HTML code snippets
- Regulatory evidence — public legal-page excerpts, including provider names, business contact details, postal addresses, and policy wording needed to support the checks you request
- Reports and VPATs — documents generated from scan results
- API key metadata — key names, scopes, and usage timestamps (keys are stored as SHA-256 hashes)
- Activity logs — actions taken within the platform for audit purposes
2.3 Technical Data
We automatically collect:
- IP address — for security, rate limiting, and abuse prevention
- Browser and device information — user agent string for compatibility
- Cookies — essential cookies for authentication and session management (see Section 7)
2.4 Data We Do Not Collect
- We do not access private or authenticated areas unless you explicitly configure that access. Public pages may contain business-contact personal data, which is processed only where needed to produce and support the requested scan result.
- We do not collect payment card numbers, bank details, or financial information. All payment processing is handled by Paddle.
- We do not build cross-site advertising profiles or sell your data. Analytics and advertising cookies are set only after you consent, and our own cookieless measurement stores nothing on your device (see 7.1 and 7.2).
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the Service | Performance of contract |
| Send transactional emails (scan results, alerts, account notifications) | Performance of contract |
| Send weekly digest emails (if opted in) | Consent |
| Generate AI-powered fix suggestions | Performance of contract |
| Prevent abuse and enforce terms of service | Legitimate interest |
| Respond to support requests | Performance of contract |
| Improve the Service | Legitimate interest |
4. Sub-Processors
We use carefully selected third-party service providers ("sub-processors") to operate the platform, including for hosting, database and authentication, payment processing, email delivery, and AI-powered features. All sub-processors are contractually bound to process data only as instructed and to implement appropriate technical and organisational security measures.
A current list of sub-processors is available upon request at legal@allyproof.com. We will notify you of material changes to our sub-processors in accordance with Section 12 (Changes to This Policy). Where sub-processors are located outside the EU/EEA, data transfers are conducted under appropriate safeguards, including Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework where applicable.
5. Data Retention
- Account data — retained while your account is active and for 30 days after deletion
- Scan results and reports — retained while your account is active; deleted within 30 days of account deletion
- Regulatory evidence snapshots — retained while the related site remains in your account; deleted within 30 days after the site or account is deleted
- AI API request content — not retained by AllyProof as a separate prompt log; an AI provider may retain request content for abuse monitoring for up to 30 days under its API data policy unless zero-retention controls apply
- Activity logs — retained for 90 days
- API key hashes — retained while the key is active; deleted when revoked
- Email delivery logs — retained by our email provider per their retention policy
- Billing data — retained by Paddle per their retention policy and tax law requirements
6. Your Rights
Under GDPR (EU/EEA residents)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interest
- Withdraw consent at any time (for consent-based processing)
- Lodge a complaint with your local data protection authority
Under CCPA/CPRA (California residents)
You have the right to:
- Know what personal information we collect and how it is used
- Delete your personal information
- Opt out of the sale or sharing of personal information (we do not sell your data)
- Non-discrimination for exercising your privacy rights
To exercise any of these rights, email us at legal@allyproof.com. We will respond within 30 days. You may also delete your account directly from the Settings page, which triggers an email-verified deletion process.
7. Cookies
We use only essential cookies required for the Service to function:
| Cookie | Purpose | Duration |
|---|---|---|
| Authentication cookies | Authentication and session management | Session / 7 days |
| Active organization cookie | Remember which organization workspace is selected | 1 year |
| Theme preference | Remember light/dark mode preference | 1 year |
The cookies listed above are strictly necessary, so the ePrivacy Directive does not require consent for them. Analytics and advertising cookies are covered separately in 7.1 below and are set only with your consent.
7.1 Optional analytics cookies and your choice
We use Google Analytics 4 and Google Ads conversion measurement. These set cookies in your browser, so they run only after you give consent through the cookie banner that appears at the bottom of the page on your first visit. Until you accept, Google Consent Mode keeps them switched off and no advertising or analytics identifier is stored on your device. The banner lets you:
- Accept all — allow strictly necessary and analytics cookies.
- Reject non-essential — only strictly necessary cookies are set.
- Customise — toggle each non-essential category on or off individually.
Your choice is stored in a first-party cookie named aap_cc for twelve months and is not shared with any third party. You can change your decision at any time by selecting Cookie preferences in the page footer. Withdrawing consent is as easy as giving it, and we never set non-essential cookies before you have made a choice.
7.2 Cookieless measurement that needs no consent
Separately from the cookie-based analytics above, we keep our own basic record of how the site is used. This measurement stores nothing on your device — no cookie, no local storage, no device fingerprint — so it runs for every visitor, including those who decline analytics cookies. It is limited to audience measurement for our own product, and the data never leaves our infrastructure.
For each page view or product action we record:
- the page path (never the query string, which can contain sign-in links);
- the site that referred you, as a domain name only;
- any campaign parameters in the link you arrived through;
- your country and whether you are on a phone, tablet or desktop;
- a short pseudonymous code derived from your IP address and browser, salted with a value that changes every day.
We never store your IP address or your full browser user-agent string. Because the salt rotates daily, the code cannot be used to recognise you tomorrow, on another site, or across devices. We do not sell or share this data, do not use it for advertising, and do not combine it with anything from a third party. Records are deleted automatically after 400 days.
We rely on our legitimate interest in understanding how our own service is used (Art. 6(1)(f) GDPR). Because nothing is stored on or read from your device, the consent requirement in Article 5(3) of the ePrivacy Directive does not apply to this measurement. You retain the right to object under Art. 21 GDPR — contact us using the details below.
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data in transit is encrypted via TLS (HTTPS)
- Database access is restricted by Row Level Security (RLS) policies
- API keys are stored as SHA-256 hashes, never in plaintext
- Authentication uses a PKCE OAuth flow with secure, HttpOnly session cookies
- Content Security Policy (CSP) headers protect against XSS attacks
- Infrastructure is hosted in EU data centers (Germany)
- Account deletion requires email verification
9. AI Data Processing
For AI-assisted fix suggestions, we send the violation type, WCAG criterion, and a bounded HTML snippet. For the optional Regulatory Evidence Monitor, we send bounded excerpts from publicly accessible legal pages to OpenAI's API so the model can locate relevant wording. Those excerpts may contain provider names, business email addresses, representatives, or postal addresses. We do not send account credentials, billing data, private website areas, or unrestricted full-page source.
AI output is treated as supporting evidence, not a legal verdict. Exact excerpts are matched back to the fetched source before use, and AI-only evidence cannot create an automatic passing result. API inputs are not used to train provider models by default. Depending on the provider and the data-control terms available to our account, request content may be retained for abuse monitoring for up to 30 days.
10. Children's Privacy
The Service is designed for business use and is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.
11. International Data Transfers
Your data may be processed in the EU and the US depending on which Service features you use. Our primary database is hosted in the EU (Germany). When data is transferred to US-based sub-processors, we ensure appropriate safeguards are in place as described in Section 4.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before they take effect. The "last updated" date at the top indicates the most recent revision.
13. Browser Extension
The AllyProof browser extension is a distribution channel for the Service. By default it operates entirely on your device — no account is required, no data is sent to AllyProof, and no analytics or telemetry are collected.
13.1 Data Stored Locally in Your Browser
The extension uses the following Chrome storage areas:
- chrome.storage.session — current scan result and (if signed in) the short-lived access token. Cleared when the browser restarts.
- chrome.storage.local — extension settings (theme, dock-mode preference, API base), the most recent 50 scan results for the current device, and (if signed in) a refresh token used to renew access tokens.
- chrome.storage.sync is never used. We deliberately avoid syncing tokens or scan history across your other Chrome devices to reduce the blast radius of a single compromised device.
13.2 Data Sent to AllyProof — Only When You Sign In and Take Action
The extension never phones home automatically. The following data is sent only in response to an explicit action you take while signed in:
- Save to dashboard — when you click "Save to dashboard" on a scan result, we send the page URL, page title, scan duration, score, severity counts, and the violation list (including HTML snippets of failing elements) to your AllyProof account.
- Crawl this site — when you initiate a multi-page crawl from the extension, we send the site origin to start a server-side scan.
- AI fix suggestion — when you click "Generate AI fix", we send the violation type, WCAG criterion, and the HTML snippet of the single failing element. We do not send full page content, surrounding markup, or any personal data found on the page.
- Sign-in (magic link) — when you sign in via the extension, a one-time link mints session tokens that are returned to the extension. Account credentials are never entered into the extension itself.
13.3 Browser Permissions
- activeTab — inject the accessibility scanner into the active tab when you click the toolbar icon or the "Scan this page" button. Granted on user gesture and revoked when you navigate away.
- tabs — read tab URL and title across tabs so the side panel can display the scan for whichever tab you are currently viewing as you switch between tabs. This grants tab metadata only; it does not grant access to read or modify any page's content. The same permission is requested by axe DevTools, WAVE, and Lighthouse for the same reason.
- storage — the chrome.storage buckets described in 13.1.
- sidePanel — open the in-browser results panel docked to the side of the page.
- scripting — programmatically inject the same axe-core scan-runner content script into the active tab when you click "Scan this page", in cases where the auto-injected version is not present (tabs that were open before the extension was installed or reloaded). The script path is read from the extension's own manifest at runtime; this permission is never used to inject arbitrary code, only the bundled scanner.
- We do not request the
<all_urls>host permission. The extension cannot read or modify the contents of any tab without an explicit user gesture (clicking the toolbar icon or the "Scan this page" button), cannot run in background tabs without your action, and cannot read your full browsing history.
13.4 What the Extension Does Not Do
- It does not load remote scripts (no eval'd code from the network).
- It does not include third-party analytics, tracking pixels, or ad SDKs.
- It does not collect telemetry by default; an optional opt-in is off out of the box.
- It does not transmit scan results to AllyProof unless you sign in and explicitly save them.
14. Contact
For privacy-related questions or to exercise your data rights, contact us at: legal@allyproof.com