Privacy notice

What is stored, why, who else sees it, and how to get rid of it.

What we store about you

  • Account: your name, email address, and a bcrypt hash of your password. We never store the password itself. Sign-in is email and password only. We also store whether you have confirmed your address, and a one-way hash of any outstanding confirmation or reset link, never the link itself.
  • Preferences: your timezone, whether you want scan and weekly-summary emails, and whether you chose the developer or the leadership view.
  • Billing: your Stripe customer and subscription identifiers, plan, and subscription status. Card details go to Stripe directly and never reach our server.
  • Usage: your page-scan allowance and how much of it you have used.
  • Your sites and scans: the domains and pages you asked us to check, and the results — scores, issue counts, and for recent scans the offending HTML and small screenshots of the elements at fault.
  • Email records: that an email of a given kind was sent to you on a given date, so we can answer "did that actually send?".

This application runs no analytics and no advertising trackers of any kind — no Google Analytics, no session recording, no heatmaps, and one cookie, which is your session. We do not sell or share your data for marketing.

Our public marketing site at accesscheck.co is separate and does use analytics, including Google Analytics. It has no access to this application and never sees your scan data. Its own privacy policy lists every tool by name.

Content from the sites you scan

To report an issue we have to store a piece of evidence for it: the HTML of the element that failed and, for some findings, a small screenshot of it. If a page you ask us to scan shows personal data — a logged-out page normally does not, but a page behind a URL you share with us might — that content can end up in your scan results. Scan only pages you are comfortable storing with us, and note that the detailed evidence is removed after 180 days.

Who else processes it

  • Stripe — payments and subscriptions. They receive your email address and handle your card details.
  • Resend — sends our email. They receive your address and the message.
  • Sentry — error reporting, so we find out when something breaks. Requests are scrubbed before they are sent, so cookies, authorisation headers and request bodies are removed rather than uploaded.
  • Amazon Web Services — the server the application and its database run on.

How long we keep it

Account and scan history stay until you delete them. Detailed findings — captured HTML and element screenshots — are removed automatically after 180 days, while the counts, scores and trends are kept so your history remains readable. Backups of the database are retained for 7 days.

Getting your data, or getting rid of it

Both are self-service and immediate, from your account settings: export downloads your account and scan data, and deleting your account removes it. One deliberate exception: we keep a minimal record that an email of a particular kind was sent on a particular date, with your address removed from it, so we can answer questions about delivery afterwards. Nothing in that record identifies you.

Sharing a report

You can create a read-only link to a single report, to send to a developer who has no account. Anyone holding that link can open that one report, so treat it as you would the report itself. Links expire after 14 days, you can see how many times each has been opened, and you can revoke one at any time. Deleting your account revokes all of them immediately.

Who at AccessCheck can see your data

An administrator can open your account and see what you see. It exists so that when you tell us a report looks wrong, we can look at the same screen rather than asking you to describe it. It is read-only: every request that would change something is refused while it is active, so nobody can alter your sites, settings or scans this way. It expires after an hour.

Every use is recorded — who did it, whose account, and when — and that record is kept even if either account is later deleted. Being an administrator is set directly in the database and no request from any account can grant it. If you want to know whether your account has ever been opened this way, ask and we will tell you.

Contact

Anything about your data, including a request we have not built a button for: support@accesscheck.co. If our scanner visited your site and you want it to stop, see about our bot.