A11y Check

Privacy Policy

Effective: July 24, 2026 (amended — administrator access to audit results and no-login teaser check disclosures; July 23, 2026 referral feature; July 22, 2026 web analytics (GA4); enacted July 16, 2026)

1. Data we collect

On sign-up: name (nickname) and email address — provided by your Google/GitHub account, or collected directly for email sign-up.

During use: audited URLs and results, evaluator judgments/notes, report details (site name, evaluator, etc.), and inquiry contents.

For service protection: sign-in records (including IP address) and server error logs.

When using the referral feature: your invite code, a one-way hash of the invitee's email (the original is not stored), and the invitee's IP address at sign-up — used only to prevent duplicate or fraudulent referrals.

When using the no-login teaser check: a one-way hash of your IP address for rate limiting (the original IP is not stored; deleted automatically after 2 days), and the checked domain with summary result figures for service statistics (no paths or personally identifiable information). Detailed results are not stored.

Cookies: authentication cookies for session management, plus web-analytics cookies for usage statistics (see Section 5). No advertising cookies.

2. Purposes

Identifying members and providing the service (audit history and reports), resource management such as quotas, responding to inquiries, sending service notification emails such as scheduled audit results (opt-out per domain), and non-identifying statistics for service improvement.

Audit target URLs and results may be processed into aggregate statistics that cannot identify any user or account, and used for academic research and policy proposals. Identifying elements such as domains are removed or generalized into categories.

For quality management, resolving audit errors, and handling inquiries, administrators may access your audit results (reports). Every access is recorded in an internal audit log and is not used for any other purpose.

3. Retention & deletion

Personal data is deleted without delay upon account deletion, together with service data such as audit results. Data required by law is stored separately for the mandated period, then destroyed.

Sign-in records collected for security (including IP addresses) and server error logs are kept for 90 days and then deleted automatically.

Email hashes in referral records are retained to prevent duplicate referrals of the same email and cannot be reversed. Sign-up IP addresses in referral records are deleted automatically after 90 days.

4. Processors

We entrust processing to: Supabase (database, authentication, file storage), Vercel (hosting, audit execution), Cloudflare (abuse-prevention checks at sign-up/sign-in and for no-login checks), and Resend (notification emails), each under their own security standards. Their servers may be located outside Korea.

5. Web analytics (Google Analytics)

We use Google Analytics (GA4) by Google LLC to understand and improve how the service is used. Cookies generate a random identifier, and visited pages, browsing environment (browser/device type), and approximate region may be transmitted to Google servers (outside Korea).

This data does not directly identify you and is used only for usage statistics. You can opt out by blocking cookies in your browser or with the Google Analytics opt-out add-on (tools.google.com/dlpage/gaoptout).

6. Third parties

We do not provide or sell personal data to third parties except as required by law.

7. Your rights

You can view and edit your information on My Page at any time, and request deletion by deleting your account.

8. Contact

Privacy inquiries: isaaceryn@gmail.com or the in-service support page.