Privacy
How this workspace handles data
Last updated: 22 July 2026.
Product URLs and report input
Submitted public URLs are fetched by the application and, when configured, an isolated accessibility worker. Do not submit private, authenticated, internal, or confidential URLs.
Browser-local data
Report history, finding review notes, evidence metadata, reminders, and beta metrics are stored in this browser using local storage. Clearing site data removes those local records.
Analytics
Production uses cookie-free Vercel Web Analytics for aggregate page views. ComplyFolio also stores a small set of aggregate conversion and Web Vitals events in its private database without a user identifier. These events exclude submitted URLs, report IDs, email addresses, supplier documents, upload tokens, and free-text notes. Detailed workspace events remain local unless a separate remote event endpoint is configured and you have granted analytics consent.
Supplier and evidence workflows
Protected supplier links use encrypted, expiring capabilities delivered in the URL fragment so the token is not sent in the initial HTTP request. If private storage is configured, files are uploaded to signed targets and remain unavailable for download or acceptance unless their recorded malware status is clean. This version does not run malware scanning itself.
Contact
A dedicated privacy contact address will be published when the public support channel opens.