Privacy
Privacy policy
What we collect, why, where it lives and how long we keep it. Last updated 4 August 2026.
This website collects nothing
klarvoaccess.com sets no cookies, runs no analytics script, loads
no third-party resources — not fonts, not images, not tag managers — and therefore needs no
consent banner. That is enforced by a build gate: if any third-party host appears in the built output, the site
does not deploy.
Our hosting provider produces aggregate, server-side request statistics — counts of page views, referrers and response codes — which we use to understand what people read. Those statistics are not linked to you, are not combined with anything else, and involve no identifier stored on your device. We also use Google Search Console, which reports aggregate search queries and impressions for our own pages and never gives us anything about an individual visitor.
The free scan
When you run a public scan, we store:
- The URL you submitted, and the pages the scan discovered from it.
- The accessibility findings, including short markup snippets of the failing elements.
- Timing and status, so the scan can be resumed and shown to you.
Public scan records expire and are deleted after thirty days. A scan link is unguessable, but it is not secret: treat it as shareable, because that is what it is for. We rate-limit scans per requesting address and per target site, and we record the requesting address for that purpose only.
We will not scan a private, internal or non-public address. The engine rejects those before any browser starts — both for your safety and for ours.
If you have an account
We hold what an account needs and little else:
- Your email address, used to sign you in (a magic link — there is no password to leak) and to send service email.
- Your organisation and the sites you connect, including a hashed per-site key. The key material itself is derived on demand and is not stored.
- Your scans, findings, fixes, review decisions and conformance records.
- Billing status — plan, period, and Stripe's customer and subscription identifiers. Card details go to Stripe and never reach us.
Data is isolated per organisation at the database level, not merely in the application. Another customer cannot read your scans, and neither can an unauthenticated request.
What the plugin sends
The WordPress plugin discloses this in its own readme, and it is worth repeating here because it is the question people most want answered:
- When you pair a store: the store URL and a one-time connection token you generated. No customer or personal data.
- Afterwards: our engine fetches your store's public pages as an ordinary web request, and pushes fixes and accessibility-statement content back to the plugin over an authenticated connection. The plugin does not send us your customers' personal data.
- On the Scale plan, if you enable it: credentials you supply for a test customer account, so the scanner can reach signed-in pages. They are stored encrypted, used only for that purpose, and you can remove them at any time.
Scanning renders your pages in a headless browser. If a page you ask us to scan contains personal data, that data may appear in a stored markup snippet. Do not point the scanner at a page containing other people's personal data that you would not want captured — and tell us if it happens, and we will delete it.
Where AI is involved
Where a fix needs judgement — alternative text for an image, a label for a control — we send the relevant page context, and for images the image itself, to Anthropic's models, and then have a second model audit the result. We do not send your customer data. The models are used through a commercial API and the content is not used to train them. Anything the audit is not confident about is routed to your review queue rather than applied.
Who processes data for us
| Processor | What for | Where |
|---|---|---|
| Cloudflare | The scanning engine, page rendering, queues, cache and evidence storage (R2). | EU/global network |
| Supabase | Accounts, tenancy, sites, scans, findings, fixes and review items (PostgreSQL). | EU region |
| Netlify | Hosting for this website and for the dashboard. | Global CDN |
| Stripe | Payments, subscriptions and invoices. We never see or store your card details. | EU/US |
| Resend | Transactional email: sign-in links, regression alerts, billing notices. | EU/US |
| Anthropic | Drafting alternative text and labels, and auditing those drafts with a second model. | US |
Where a processor is outside the European Economic Area, the transfer relies on the European Commission's standard contractual clauses.
How long we keep things
- Public scans: thirty days, then deleted.
- Account data, scans and fixes: while your account is open, and for thirty days after you close it.
- Conformance records: retained as an append-only history, because their value is that they cannot be quietly rewritten. You can export them, and you can ask us to delete them.
- Invoices and billing records: as long as tax law requires.
- Email logs: ninety days.
Your rights
If you are in the UK or the EU you have the right to access your data, to have it corrected, to have it deleted, to restrict or object to processing, and to receive it in a portable form. Email hello@klarvoaccess.com and we will act within one month, usually much sooner. You can also complain to your national supervisory authority.
The lawful bases we rely on are: performance of a contract, for everything an account needs; legitimate interests, for security, rate limiting and aggregate statistics; and consent where we ever ask for it, which at present we do not need to.
Security
Data in transit is encrypted. Per-site keys are stored as hashes, never in plain text. Database access is restricted per organisation at the row level. Payment details never touch our systems. If we ever suffer a breach affecting your data, we will tell you and the relevant authority — promptly, and with what we actually know rather than a reassuring summary.
Children
The service is for businesses. It is not directed at children and we do not knowingly collect their data.
Changes
We will update this policy as the service changes, and the date at the top will change with it. If a change materially affects how we handle your data, we will email account holders before it takes effect.
Contact
hello@klarvoaccess.com for anything in this document, including a request to delete something.