Privacy

How this workspace handles data

Last updated: 8 September 2026.

Product URLs and report input

Submitted public URLs are fetched by the application and, when configured, an isolated accessibility worker. Do not submit private, authenticated, internal, or confidential URLs.

Browser-local data

Report history, finding review notes, evidence metadata, reminders, and beta metrics are stored in this browser using local storage. Clearing site data removes those local records.

Signed-in account workspace

If you sign in, product records, scan reports, findings, generated Evidence Packs, and review reminders are also stored in a private account workspace so you can reopen them on another device. Browser roles do not receive direct database access; account workspace requests are handled by authenticated server routes. Signing out does not delete saved account records.

Analytics

Production uses cookie-free Vercel Web Analytics for aggregate page views. ComplyFolio also stores a small set of aggregate conversion and Web Vitals events in its private database without a user identifier. For campaign measurement, these events may include bounded UTM source, medium and campaign values, the referring hostname only, and the first landing path for the browser session. Query strings and referrer paths are discarded. These events exclude submitted product URLs, report IDs, email addresses, supplier documents, upload tokens, and free-text notes. Detailed workspace events remain local unless a separate remote event endpoint is configured and you have granted analytics consent.

Supplier and evidence workflows

Protected supplier links use encrypted, expiring capabilities delivered in the URL fragment so the token is not sent in the initial HTTP request. Files uploaded to private storage remain quarantined until the configured self-hosted ClamAV worker records a clean result. Infected files are rejected and removed from private storage when deletion succeeds; failed scans remain unavailable for download or acceptance until retried.

Founding pilot enquiries

If you request the human-reviewed founding pilot through the configured email or booking channel, that provider processes the contact details and information you submit. Send only a public product URL and the minimum context needed for a scope decision. Do not include passwords, customer data, payment information, or confidential supplier files in the initial enquiry.

Contact

Privacy questions: hualunlan@gmail.com.