Last updated: April 17, 2026
This Privacy Policy describes how AllyProof ("we", "us", "our"), operated as a sole proprietorship registered in Ukraine, collects, uses, and protects your personal data when you use the AllyProof platform ("Service").
We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
AllyProof is the data controller for the personal data we collect through the Service. For billing-related data, Paddle.com Market Limited acts as an independent data controller. See Paddle's Privacy Policy for details on how they handle payment data.
Contact: legal@allyproof.com
When you create an account, we collect:
When you use the Service, we collect:
We automatically collect:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and operate the Service | Performance of contract |
| Send transactional emails (scan results, alerts, account notifications) | Performance of contract |
| Send weekly digest emails (if opted in) | Consent |
| Generate AI-powered fix suggestions | Performance of contract |
| Prevent abuse and enforce terms of service | Legitimate interest |
| Respond to support requests | Performance of contract |
| Improve the Service | Legitimate interest |
We use the following third-party services to operate the platform:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (AWS eu-central-1) |
| Paddle | Payment processing, invoicing, tax handling | UK / US |
| Anthropic (Claude) | AI-powered accessibility fix suggestions | US |
| Resend | Transactional email delivery | US |
| Hetzner Cloud | Application hosting | EU (Germany) |
| Cloudflare | CDN, DDoS protection, DNS | Global |
| Cloudflare R2 | Report and document storage | EU |
| OAuth authentication (if chosen by user) | US | |
| GitHub | OAuth authentication (if chosen by user) | US |
For US-based sub-processors, data transfers are conducted under appropriate safeguards including Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework where applicable.
You have the right to:
You have the right to:
To exercise any of these rights, email us at legal@allyproof.com. We will respond within 30 days. You may also delete your account directly from the Settings page, which triggers an email-verified deletion process.
We use only essential cookies required for the Service to function:
| Cookie | Purpose | Duration |
|---|---|---|
| Supabase auth cookies | Authentication and session management | Session / 7 days |
| Active organization cookie | Remember which organization workspace is selected | 1 year |
| Theme preference | Remember light/dark mode preference | 1 year |
We do not use advertising cookies, tracking pixels, or third-party analytics cookies. Because we only use strictly necessary cookies, consent banners are not required under the ePrivacy Directive.
We implement appropriate technical and organizational measures to protect your data:
When generating fix suggestions, we send accessibility violation data (violation type, HTML code snippet, and WCAG criterion) to Anthropic's Claude API. We do not send your personal data, account information, or full page content to the AI provider.
Per Anthropic's data policy, API inputs are not used to train their models.
The Service is designed for business use and is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we learn that we have collected data from a child, we will delete it promptly.
Your data may be processed in the EU and the US depending on which Service features you use. Our primary database is hosted in the EU (Germany). When data is transferred to US-based sub-processors, we ensure appropriate safeguards are in place as described in Section 4.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service at least 30 days before they take effect. The "last updated" date at the top indicates the most recent revision.
For privacy-related questions or to exercise your data rights, contact us at: legal@allyproof.com