Privacy Policy

Effective date:

AccessLint, LLC (“AccessLint”, “we”, “us”) builds tools that test websites and code for accessibility problems. This policy explains what personal information we collect when you use them, why, who we share it with, how long we keep it, and the choices and rights you have.

It covers:

It does not cover the a11y agent Chrome extension, which has its own policy, or our open source packages, which run on your own systems and send nothing to us.

The short version

Who is responsible for your information

AccessLint, LLC is the controller of the personal information described in this policy, except where we process information on a customer’s behalf (see “Information we process for our customers”). Our address is AccessLint, 350 Northern Blvd, STE 324 -1142, Albany, NY 12204-1000, United States, and you can reach us at support@accesslint.com.

Information we collect

Information you give us

Account and sign-in. You can sign in with GitHub, with Google, or with an email address. Depending on which you choose, we receive your GitHub or Google account identifier, username, and email address, or the email address you enter. When AccessLint is installed on a GitHub organization, we also receive the organization’s member list so that we can grant access to the right people.

What you set up. Workspaces and their members; the repositories you connect; the domains you add; the Flows you write, which describe journeys through your site in plain language; the schedule you choose; and the decisions you make about results, such as dismissing a finding. Do not put passwords or other secrets into a Flow; Flows do not need them (see “Signing in to your site”).

Billing. If you subscribe through Stripe, you enter your card on Stripe’s checkout page; card numbers never reach our servers. We keep subscription identifiers and status, and the name of your workspace appears on the Stripe customer record. If you subscribe through GitHub Marketplace, GitHub bills you and tells us your plan.

Messages. Anything you send us, such as a support email, and the address you sent it from.

Marketing preferences. If you opt in to product news, we record your address, when and where you opted in, and any later opt-out.

Information we collect automatically

Server logs. Our servers keep standard request logs: the date and time, the URL, the response status, your IP address, your browser’s user agent, and a request identifier. We use them to run, secure, and debug the service, including rate limiting. Logs are kept for 90 days.

Error reports. When something breaks, a report of the error and where it happened in our code goes to our error tracker. Reports are configured to exclude personal data.

Analytics. We use Amplitude to measure how our sites and app are used. “Analytics” below describes what it collects and how to turn it off.

Bot protection. The sign-in page and the free scanner can show a Cloudflare Turnstile challenge. Cloudflare receives your IP address and browser signals to decide whether you are a person; we receive only the result.

Cookies and similar storage. Described under “Cookies”.

Information from other sources

Information we process for our customers

Some of what we handle is not about you but about the people who use your website or your repositories. For that information you are the controller and we act as your processor, on your instructions and under our Terms of Service. A data processing agreement is available on request, and the services we use to do this work are listed on our Subprocessors page.

Pull request reviews. To review a pull request we read the changed files and related code from your repository, look for accessibility issues, and post comments back to GitHub. We keep the results (repository, pull request, commit, file, line, and rule) and do not store copies of your source code. Our staff do not read your private repositories except to provide support you have asked for.

Flows and site scans. When a Flow or scan runs, our browser loads pages on your site, follows the journey you described, and checks each page. We keep the results, excerpts of the page markup we flagged, screenshots, and cropped images of the elements with problems. Images can include whatever was on screen, including content your site shows to a signed-in user. Screenshots from routine passing runs are deleted after seven days; runs that need your attention keep theirs until you delete them.

Signing in to your site. If a journey is behind a login, you invite a test mailbox we own, an @accesslint.email address, as a user of your site, and we sign in through the links or codes your site sends it. We never ask for or store your site’s passwords. Mail received by the mailbox is deleted within 24 hours, and the signed-in session is kept, encrypted, until you remove the domain or change its sign-in settings.

Free scanner. Anyone can scan a public page at app.accesslint.com/scan without an account. We keep the URL and the findings, and for seven days a snapshot of the page and images of the elements we flagged. A scan is not linked to a person unless you were signed in. Scans of public repositories work the same way.

Our testing agent. The browser that does this work identifies itself in its user agent, links to a page describing what it does and how to block it, and honors robots.txt. Flows only run against domains whose owner has verified control of them. If you operate a website and have a question about visits from our agent, write to us.

How we use information, and our legal bases

Where the GDPR or the UK GDPR applies, we must have a legal basis for each use of your personal information. The table lists each purpose, the information involved, and the basis we rely on.

PurposeInformationLegal basis
Create your account, sign you in, and give you access to the right workspacesSign-in identity, session, workspace and organization membershipPerformance of a contract
Run the reviews, Flows, and scans you ask for and show you the resultsRepository contents, domains, flows, results, screenshots, test mailbox mailPerformance of a contract; your instructions, where we act as your processor
Bill you and send receipts, trial, and payment noticesBilling identifiers, subscription status, email addressPerformance of a contract; legal obligation for tax and accounting records
Send service email, such as sign-in links, setup messages, and alerts about your runsEmail address, run resultsPerformance of a contract; legitimate interest in telling you about a failure
Send product newsEmail address, consent recordConsent, which you can withdraw with the unsubscribe link in every message
Keep the service secure and workingIP address, logs, user agent, error reportsLegitimate interest in protecting the service and its users
Understand how the product is used and improve itPseudonymous analytics identifier, pages and features used, plan, session replaysConsent on our marketing site in the EEA, UK, and Switzerland; legitimate interest elsewhere and for signed-in product usage
Answer your questionsWhat you send usLegitimate interest in supporting you; performance of a contract where you are a customer
Stop sending to addresses that bounce or complainEmail address, reasonLegitimate interest in deliverability; legal obligation under anti-spam law
Comply with the law and enforce our termsWhatever is relevant to the requestLegal obligation; legitimate interest

We do not use your information to make automated decisions that have legal or similarly significant effects on you.

Cookies

A cookie is a small piece of data a website stores in your browser. We use a few, listed here with the similar browser storage our sites use. “Essential” entries are needed for the site to work and need no consent; the rest are analytics.

NameSet byPurposeKindLasts
_access_lint-app_sessionapp.accesslint.comKeeps you signed in and protects forms against cross-site request forgeryEssentialUntil you close your browser or sign out
accesslint_consentwww.accesslint.comRemembers whether you accepted or declined analyticsEssential180 days
__stripe_mid, __stripe_sidStripe, on app.accesslint.comFraud prevention for paymentsEssential1 year, 30 minutes
AMP_… cookies and related browser storageAmplitude, on .accesslint.comA random device identifier, the current session, the campaign that brought you here, and a short buffer for session replayAnalyticsUp to 1 year

“Manage cookies” in the footer of www.accesslint.com lets you change your analytics choice at any time; withdrawing consent removes Amplitude’s cookies and stored data. Your browser also lets you block or delete cookies, though blocking the session cookie will sign you out. The Cloudflare Turnstile widget may store data in your browser while it completes a challenge, under Cloudflare’s privacy policy.

We do not respond to “Do Not Track” signals, because there is no agreed standard for what they should mean. We do not sell or share personal information, so there is nothing for a Global Privacy Control signal to opt you out of; your analytics choice is controlled from “Manage cookies”.

Analytics

We use Amplitude, a product analytics service hosted in the United States, to understand how our sites and app are used: pages viewed, sessions, features used, and plan, keyed to a random device identifier and, when you are signed in, to a pseudonymous user identifier. We do not send Amplitude your email address. On some pages Amplitude also records a session replay, a reconstruction of what was on screen; sensitive text and images are masked or left out, and replay is not recorded for visitors in Europe. The marketing site and the app share the identifier so that a visit and a sign-up can be connected.

Where the law requires opt-in, in the EEA, the UK, and Switzerland, our marketing site does not load Amplitude until you accept. Elsewhere it is on by default and you can opt out from “Manage cookies”. Inside the app, analytics of signed-in usage runs as first-party measurement under our legitimate interest. The app does not yet have an analytics switch of its own; you can block the Amplitude script in your browser, and you can object to this processing by writing to us.

How we share information

We share personal information only in the ways below. We do not sell it, and we do not share it for advertising.

Service providers. Companies that host or help run the service, under contracts that limit what they may do with the data. Each one is named on our Subprocessors page with what it can receive and where it processes data. Today they are:

At your direction. Review comments are posted to your pull requests on GitHub, where anyone with access to the repository can read them. If you connect the AccessLint chat connector to Claude.ai, ChatGPT, or another client, the results you ask for are delivered to that client and handled under its provider’s policy. If you share a report link, anyone with the link can open it.

Within your workspace. Other members of a shared workspace can see what you do in it, such as which findings you dismissed.

Legal reasons. When required by law, subpoena, or court order, or when we believe it necessary to investigate or prevent fraud, abuse, a security incident, or harm to a person, or to enforce our terms. Where the law allows, we will tell you before disclosing your information.

Business transfers. If AccessLint is acquired by or merges with another company, your information may transfer with it. We will notify you before your information becomes subject to a different privacy policy.

Aggregated or de-identified data, such as how many scans ran last month or which accessibility rules fail most often, which does not identify you.

Use of AI models

Flows use AI models from Anthropic to interpret the journeys you write and to locate elements on the pages being tested. For that we send the text you wrote and content from those pages. We do not send credentials, and Anthropic does not use this data to train its models.

International transfers

We are based in the United States, and most of our service providers process data there. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to the United States. Where a provider is certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions we may rely on that certification; otherwise we rely on the European Commission’s Standard Contractual Clauses, with the UK and Swiss addenda, as incorporated into that provider’s data processing agreement. A copy of the relevant clauses is available on request.

How long we keep information

We keep personal information only as long as we need it for the purposes above, and then delete it. The specific periods are:

InformationHow long we keep it
Your account and workspacesUntil you delete your account. Deleting it from your settings removes you and every workspace only you belonged to, immediately. Uninstalling the GitHub App, or a subscription ending, schedules a workspace for deletion 30 days later unless it still has an active plan.
Email sign-in attempts that were never completed7 days.
Screenshots and images from Flow runs7 days for routine passing runs; otherwise until you delete the run or the flow.
Page snapshots and images from scans7 days. The URL and the findings stay so that the report link keeps working.
Mail received at a test mailboxUp to 24 hours.
A signed-in session for a domainUntil you remove the domain or change its sign-in settings.
Server logs and error reports90 days.
Analytics eventsUp to 24 months, after which they are deleted. Aggregated statistics that do not identify you are kept indefinitely.
Billing recordsStripe keeps invoices and payment records for as long as tax and accounting law requires, even after you delete your account.
Bounce and spam-complaint suppression listKept, so that we do not send to that address again.
Marketing consent recordsWhile you are subscribed; deleted with your account.
API keys and chat connector tokensUntil you revoke them.
Support correspondenceAs long as needed to resolve your request and keep a record of it.
Analytics consent cookie180 days.

Security

All traffic to our sites uses TLS. Access tokens, sessions, and other sensitive data are encrypted at rest. Card numbers are handled by Stripe and never touch our servers. Access to production systems is limited to the people who run the service. No system is perfectly secure; if we learn of a breach that affects you, we will notify you and the relevant authorities as the law requires.

Your rights and choices

These apply to everyone, wherever you are:

If you are in the EEA, the UK, or Switzerland

You have the right to access the personal information we hold about you, to have it corrected or erased, to restrict or object to our processing of it (including any processing based on legitimate interests, and direct marketing at any time), to receive it in a portable format, and to withdraw any consent you have given, without affecting what was done before you withdrew it. The tools above cover most of these; for anything they do not, write to us and we will respond within one month. You also have the right to complain to your local data protection authority, or to the UK Information Commissioner’s Office if you are in the UK.

If you are in California or another US state with a privacy law

You have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, and to receive it in a portable format, all of which this policy and the tools above provide. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer anything about you, so there is no sale or sharing to opt out of. We will not discriminate against you for exercising any of these rights. You may use an authorized agent, in which case we will ask for proof that you authorized them. If we decline a request, we will say why, and you may appeal by replying to our response.

How we verify requests

The tools in your settings act on the account you are signed in to, which is the verification. For a request by email, we will write back to the address on your account, or ask you to sign in, before we act on it.

Children

Our services are for businesses and developers and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to us and we will delete it.

Other websites

Our sites link to other sites, and our testing agent visits sites our customers ask us to test. This policy does not cover those sites; each has its own privacy practices.

Changes to this policy

We may update this policy from time to time. We will post the new version here with a new effective date. If a change is material, we will tell you by email to the address on your account or by a prominent notice on our site before it takes effect. Earlier versions are available on request.

Contact

Questions, requests, and complaints about this policy can be sent to support@accesslint.com or by post to:

AccessLint
350 Northern Blvd
STE 324 -1142
Albany, NY 12204-1000
United States

See also our Subprocessors page and our Terms of Service.