Privacy Policy
Effective date:
AccessLint, LLC (“AccessLint”, “we”, “us”) builds tools that test websites and code for accessibility problems. This policy explains what personal information we collect when you use them, why, who we share it with, how long we keep it, and the choices and rights you have.
It covers:
- our marketing site at www.accesslint.com, including the help pages;
- the AccessLint web app at app.accesslint.com, including pull request reviews, the free scanner, and Flows monitoring;
- our API and the AccessLint chat connector at mcp.accesslint.com;
- our testing agent, which visits websites on behalf of our customers; and
- the email we send.
It does not cover the a11y agent Chrome extension, which has its own policy, or our open source packages, which run on your own systems and send nothing to us.
The short version
- We collect what we need to run the service: your sign-in identity (GitHub, Google, or an email address), the workspaces, repositories, domains, and flows you set up, your billing status, and the results of the tests you run.
- We do not sell personal information and we do not share it for advertising. There are no ad networks on our sites.
- We use one analytics service, Amplitude, to understand how the product is used. On our marketing site in the EEA, the UK, and Switzerland it stays off until you accept it. “Manage cookies” in the footer lets you change your mind.
- We never ask for or store your site’s passwords. What we capture while testing your site is kept briefly and deleted on the schedule below.
- You can export the personal data we hold about you, or delete your account and its data, from your settings page at any time.
Who is responsible for your information
AccessLint, LLC is the controller of the personal information described in this policy, except where we process information on a customer’s behalf (see “Information we process for our customers”). Our address is AccessLint, 350 Northern Blvd, STE 324 -1142, Albany, NY 12204-1000, United States, and you can reach us at support@accesslint.com.
Information we collect
Information you give us
Account and sign-in. You can sign in with GitHub, with Google, or with an email address. Depending on which you choose, we receive your GitHub or Google account identifier, username, and email address, or the email address you enter. When AccessLint is installed on a GitHub organization, we also receive the organization’s member list so that we can grant access to the right people.
What you set up. Workspaces and their members; the repositories you connect; the domains you add; the Flows you write, which describe journeys through your site in plain language; the schedule you choose; and the decisions you make about results, such as dismissing a finding. Do not put passwords or other secrets into a Flow; Flows do not need them (see “Signing in to your site”).
Billing. If you subscribe through Stripe, you enter your card on Stripe’s checkout page; card numbers never reach our servers. We keep subscription identifiers and status, and the name of your workspace appears on the Stripe customer record. If you subscribe through GitHub Marketplace, GitHub bills you and tells us your plan.
Messages. Anything you send us, such as a support email, and the address you sent it from.
Marketing preferences. If you opt in to product news, we record your address, when and where you opted in, and any later opt-out.
Information we collect automatically
Server logs. Our servers keep standard request logs: the date and time, the URL, the response status, your IP address, your browser’s user agent, and a request identifier. We use them to run, secure, and debug the service, including rate limiting. Logs are kept for 90 days.
Error reports. When something breaks, a report of the error and where it happened in our code goes to our error tracker. Reports are configured to exclude personal data.
Analytics. We use Amplitude to measure how our sites and app are used. “Analytics” below describes what it collects and how to turn it off.
Bot protection. The sign-in page and the free scanner can show a Cloudflare Turnstile challenge. Cloudflare receives your IP address and browser signals to decide whether you are a person; we receive only the result.
Cookies and similar storage. Described under “Cookies”.
Information from other sources
- GitHub sends us the account information above, events for the repositories you connect (such as pull requests, installation changes, and Marketplace purchases), and the contents of the files we need to review.
- Google sends us the sign-in details above.
- Stripe sends us subscription and payment events.
- Resend, our email provider, tells us when a message bounced or was reported as spam, so that we stop sending to that address.
Information we process for our customers
Some of what we handle is not about you but about the people who use your website or your repositories. For that information you are the controller and we act as your processor, on your instructions and under our Terms of Service. A data processing agreement is available on request, and the services we use to do this work are listed on our Subprocessors page.
Pull request reviews. To review a pull request we read the changed files and related code from your repository, look for accessibility issues, and post comments back to GitHub. We keep the results (repository, pull request, commit, file, line, and rule) and do not store copies of your source code. Our staff do not read your private repositories except to provide support you have asked for.
Flows and site scans. When a Flow or scan runs, our browser loads pages on your site, follows the journey you described, and checks each page. We keep the results, excerpts of the page markup we flagged, screenshots, and cropped images of the elements with problems. Images can include whatever was on screen, including content your site shows to a signed-in user. Screenshots from routine passing runs are deleted after seven days; runs that need your attention keep theirs until you delete them.
Signing in to your site. If a journey is behind a login, you invite a test mailbox we own, an @accesslint.email address, as a user of your site, and we sign in through the links or codes your site sends it. We never ask for or store your site’s passwords. Mail received by the mailbox is deleted within 24 hours, and the signed-in session is kept, encrypted, until you remove the domain or change its sign-in settings.
Free scanner. Anyone can scan a public page at app.accesslint.com/scan without an account. We keep the URL and the findings, and for seven days a snapshot of the page and images of the elements we flagged. A scan is not linked to a person unless you were signed in. Scans of public repositories work the same way.
Our testing agent. The browser that does this work identifies itself in its user agent, links to a page describing what it does and how to block it, and honors robots.txt. Flows only run against domains whose owner has verified control of them. If you operate a website and have a question about visits from our agent, write to us.
How we use information, and our legal bases
Where the GDPR or the UK GDPR applies, we must have a legal basis for each use of your personal information. The table lists each purpose, the information involved, and the basis we rely on.
| Purpose | Information | Legal basis |
|---|---|---|
| Create your account, sign you in, and give you access to the right workspaces | Sign-in identity, session, workspace and organization membership | Performance of a contract |
| Run the reviews, Flows, and scans you ask for and show you the results | Repository contents, domains, flows, results, screenshots, test mailbox mail | Performance of a contract; your instructions, where we act as your processor |
| Bill you and send receipts, trial, and payment notices | Billing identifiers, subscription status, email address | Performance of a contract; legal obligation for tax and accounting records |
| Send service email, such as sign-in links, setup messages, and alerts about your runs | Email address, run results | Performance of a contract; legitimate interest in telling you about a failure |
| Send product news | Email address, consent record | Consent, which you can withdraw with the unsubscribe link in every message |
| Keep the service secure and working | IP address, logs, user agent, error reports | Legitimate interest in protecting the service and its users |
| Understand how the product is used and improve it | Pseudonymous analytics identifier, pages and features used, plan, session replays | Consent on our marketing site in the EEA, UK, and Switzerland; legitimate interest elsewhere and for signed-in product usage |
| Answer your questions | What you send us | Legitimate interest in supporting you; performance of a contract where you are a customer |
| Stop sending to addresses that bounce or complain | Email address, reason | Legitimate interest in deliverability; legal obligation under anti-spam law |
| Comply with the law and enforce our terms | Whatever is relevant to the request | Legal obligation; legitimate interest |
We do not use your information to make automated decisions that have legal or similarly significant effects on you.
Cookies
A cookie is a small piece of data a website stores in your browser. We use a few, listed here with the similar browser storage our sites use. “Essential” entries are needed for the site to work and need no consent; the rest are analytics.
| Name | Set by | Purpose | Kind | Lasts |
|---|---|---|---|---|
_access_lint-app_session | app.accesslint.com | Keeps you signed in and protects forms against cross-site request forgery | Essential | Until you close your browser or sign out |
accesslint_consent | www.accesslint.com | Remembers whether you accepted or declined analytics | Essential | 180 days |
__stripe_mid, __stripe_sid | Stripe, on app.accesslint.com | Fraud prevention for payments | Essential | 1 year, 30 minutes |
AMP_… cookies and related browser storage | Amplitude, on .accesslint.com | A random device identifier, the current session, the campaign that brought you here, and a short buffer for session replay | Analytics | Up to 1 year |
“Manage cookies” in the footer of www.accesslint.com lets you change your analytics choice at any time; withdrawing consent removes Amplitude’s cookies and stored data. Your browser also lets you block or delete cookies, though blocking the session cookie will sign you out. The Cloudflare Turnstile widget may store data in your browser while it completes a challenge, under Cloudflare’s privacy policy.
We do not respond to “Do Not Track” signals, because there is no agreed standard for what they should mean. We do not sell or share personal information, so there is nothing for a Global Privacy Control signal to opt you out of; your analytics choice is controlled from “Manage cookies”.
Analytics
We use Amplitude, a product analytics service hosted in the United States, to understand how our sites and app are used: pages viewed, sessions, features used, and plan, keyed to a random device identifier and, when you are signed in, to a pseudonymous user identifier. We do not send Amplitude your email address. On some pages Amplitude also records a session replay, a reconstruction of what was on screen; sensitive text and images are masked or left out, and replay is not recorded for visitors in Europe. The marketing site and the app share the identifier so that a visit and a sign-up can be connected.
Where the law requires opt-in, in the EEA, the UK, and Switzerland, our marketing site does not load Amplitude until you accept. Elsewhere it is on by default and you can opt out from “Manage cookies”. Inside the app, analytics of signed-in usage runs as first-party measurement under our legitimate interest. The app does not yet have an analytics switch of its own; you can block the Amplitude script in your browser, and you can object to this processing by writing to us.
How we share information
We share personal information only in the ways below. We do not sell it, and we do not share it for advertising.
Service providers. Companies that host or help run the service, under contracts that limit what they may do with the data. Each one is named on our Subprocessors page with what it can receive and where it processes data. Today they are:
- Heroku (Salesforce), United States: application hosting, database, and job queues.
- Amazon Web Services, United States: storage for screenshots and other test images.
- GitHub, United States: sign-in, repository access, Marketplace billing, and hosting for www.accesslint.com.
- Google, United States: the Continue with Google sign-in.
- Stripe, United States: payments and billing.
- Resend, United States: sending our email, and receiving mail at the test mailboxes.
- Amplitude, United States: product analytics and session replay.
- Anthropic, United States: AI models used by Flows. See “Use of AI models”.
- Browserbase, United States: hosted browsers that run some Flows.
- Cloudflare, global network: bot challenges, DNS resolution for our testing agent, and delivery of a charting library on our benchmark pages.
- Sentry, European Union: error tracking.
- Better Stack, European Union: logs and uptime monitoring.
At your direction. Review comments are posted to your pull requests on GitHub, where anyone with access to the repository can read them. If you connect the AccessLint chat connector to Claude.ai, ChatGPT, or another client, the results you ask for are delivered to that client and handled under its provider’s policy. If you share a report link, anyone with the link can open it.
Within your workspace. Other members of a shared workspace can see what you do in it, such as which findings you dismissed.
Legal reasons. When required by law, subpoena, or court order, or when we believe it necessary to investigate or prevent fraud, abuse, a security incident, or harm to a person, or to enforce our terms. Where the law allows, we will tell you before disclosing your information.
Business transfers. If AccessLint is acquired by or merges with another company, your information may transfer with it. We will notify you before your information becomes subject to a different privacy policy.
Aggregated or de-identified data, such as how many scans ran last month or which accessibility rules fail most often, which does not identify you.
Use of AI models
Flows use AI models from Anthropic to interpret the journeys you write and to locate elements on the pages being tested. For that we send the text you wrote and content from those pages. We do not send credentials, and Anthropic does not use this data to train its models.
International transfers
We are based in the United States, and most of our service providers process data there. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to the United States. Where a provider is certified under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions we may rely on that certification; otherwise we rely on the European Commission’s Standard Contractual Clauses, with the UK and Swiss addenda, as incorporated into that provider’s data processing agreement. A copy of the relevant clauses is available on request.
How long we keep information
We keep personal information only as long as we need it for the purposes above, and then delete it. The specific periods are:
| Information | How long we keep it |
|---|---|
| Your account and workspaces | Until you delete your account. Deleting it from your settings removes you and every workspace only you belonged to, immediately. Uninstalling the GitHub App, or a subscription ending, schedules a workspace for deletion 30 days later unless it still has an active plan. |
| Email sign-in attempts that were never completed | 7 days. |
| Screenshots and images from Flow runs | 7 days for routine passing runs; otherwise until you delete the run or the flow. |
| Page snapshots and images from scans | 7 days. The URL and the findings stay so that the report link keeps working. |
| Mail received at a test mailbox | Up to 24 hours. |
| A signed-in session for a domain | Until you remove the domain or change its sign-in settings. |
| Server logs and error reports | 90 days. |
| Analytics events | Up to 24 months, after which they are deleted. Aggregated statistics that do not identify you are kept indefinitely. |
| Billing records | Stripe keeps invoices and payment records for as long as tax and accounting law requires, even after you delete your account. |
| Bounce and spam-complaint suppression list | Kept, so that we do not send to that address again. |
| Marketing consent records | While you are subscribed; deleted with your account. |
| API keys and chat connector tokens | Until you revoke them. |
| Support correspondence | As long as needed to resolve your request and keep a record of it. |
| Analytics consent cookie | 180 days. |
Security
All traffic to our sites uses TLS. Access tokens, sessions, and other sensitive data are encrypted at rest. Card numbers are handled by Stripe and never touch our servers. Access to production systems is limited to the people who run the service. No system is perfectly secure; if we learn of a breach that affects you, we will notify you and the relevant authorities as the law requires.
Your rights and choices
These apply to everyone, wherever you are:
- Export your data. Settings › Export downloads a copy of the personal data we hold about you.
- Delete your account. Settings deletes you and every workspace only you belonged to, including their data, immediately. A Stripe subscription is cancelled as part of this. A paid GitHub Marketplace plan has to be cancelled on GitHub first, because GitHub owns that billing relationship; the page links you to the right place.
- Correct your details. Your name, username, and email come from GitHub or Google and update the next time you sign in. For anything else, write to us.
- Marketing email. Every message carries an unsubscribe link, and we honor it at once.
- Analytics. “Manage cookies” in the footer of www.accesslint.com.
If you are in the EEA, the UK, or Switzerland
You have the right to access the personal information we hold about you, to have it corrected or erased, to restrict or object to our processing of it (including any processing based on legitimate interests, and direct marketing at any time), to receive it in a portable format, and to withdraw any consent you have given, without affecting what was done before you withdrew it. The tools above cover most of these; for anything they do not, write to us and we will respond within one month. You also have the right to complain to your local data protection authority, or to the UK Information Commissioner’s Office if you are in the UK.
If you are in California or another US state with a privacy law
You have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, and to receive it in a portable format, all of which this policy and the tools above provide. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer anything about you, so there is no sale or sharing to opt out of. We will not discriminate against you for exercising any of these rights. You may use an authorized agent, in which case we will ask for proof that you authorized them. If we decline a request, we will say why, and you may appeal by replying to our response.
How we verify requests
The tools in your settings act on the account you are signed in to, which is the verification. For a request by email, we will write back to the address on your account, or ask you to sign in, before we act on it.
Children
Our services are for businesses and developers and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, write to us and we will delete it.
Other websites
Our sites link to other sites, and our testing agent visits sites our customers ask us to test. This policy does not cover those sites; each has its own privacy practices.
Changes to this policy
We may update this policy from time to time. We will post the new version here with a new effective date. If a change is material, we will tell you by email to the address on your account or by a prominent notice on our site before it takes effect. Earlier versions are available on request.
Contact
Questions, requests, and complaints about this policy can be sent to support@accesslint.com or by post to:
AccessLint
350 Northern Blvd
STE 324 -1142
Albany, NY 12204-1000
United States
See also our Subprocessors page and our Terms of Service.