Privacy Policy — Web Accessibility Scanner

Last updated: 24 September 2026 The short version Web Accessibility Scanner has no servers, no accounts and no analytics, and transmits nothing anywhere. Everything it does happens locally in your browser. Some things are saved on your own device so they survive a restart — your settings, recent scans, any flows you record, and any manual review results you write down. Each of those is described below, including what it can contain and how to delete it. What the extension…

Last updated: 24 September 2026

The short version

Web Accessibility Scanner has no servers, no accounts and no analytics, and transmits nothing anywhere. Everything it does happens locally in your browser.

Some things are saved on your own device so they survive a restart — your settings, recent scans, any flows you record, and any manual review results you write down. Each of those is described below, including what it can contain and how to delete it.

What the extension accesses

When you press Scan page, Scan one element, or choose a scan from the right-click menu, the extension reads the rendered content of that tab — the page's elements, attributes and computed styles. This is necessary to evaluate accessibility: properties such as colour contrast, focus order and accessible names cannot be determined without reading the rendered page.

This reading happens only when you explicitly ask for a scan. The extension does not scan pages in the background, does not monitor your browsing, and does not read pages you have not asked it to scan.

Frames and embedded content

A page scan also reads inside the frames embedded in that page, including frames served by other companies — an embedded checkout, a video player, a map, a chat widget. This is necessary because an accessibility failure inside an embedded widget is invisible from the outside, and a scan that skipped them would report the page as clean when it is not.

The same rules apply: it happens only when you ask for a scan, and nothing read from a frame leaves your device. You can switch frame scanning off in Settings, in which case only the top document is read.

The extension also reads inside open shadow roots, which is how modern web components are built. This can also be switched off.

What happens to that content

The results are shown in the extension's panel and in a report tab.

To hand a finished scan to the report tab, it is held briefly in your browser's session storage. Session storage is cleared when you close the browser, and it holds one scan at a time — each new scan replaces the last. Nothing from it survives a restart.

If you press an Export button, the file is saved by your own browser to your own machine. The extension does not upload it anywhere.

What is stored on your device

Your settings — always

Your preferences: the conformance standard you chose, which features are switched on, and your light/dark preference. These contain no page content.

Your ignore list — always

The issues and rules you have marked as not applicable, so your choices survive a restart. It contains rule identifiers and CSS selectors.

Your licence key, if you enter one

If you activate a licence key, the key itself is stored on your device so the extension knows it on the next launch. It is never transmitted — activation is checked locally, with no network request — and it is removed when you press Remove key or uninstall the extension.

The key is not personal information and is not linked to an account, because there are no accounts.

Scan history — on by default, and switchable off

The last 10 scans are kept so you can reopen a report and compare results before and after a fix.

Each stored scan contains the page address and title, the time of the scan, the list of accessibility findings, and for each finding a short snippet of the offending element's opening HTML tag (for example <button class="icon-button">) plus a CSS selector pointing at it.

This means a stored scan does contain small fragments of the pages you scanned. Scanning a page that displays personal or confidential information could place identifying text into that history — for instance if a value appears in an element's aria-label or in visible text within a captured snippet. Because frames are scanned too, a stored scan can contain fragments from embedded third-party content as well as from the page itself.

Older scans are dropped automatically once there are more than 10. You can delete any single scan, clear the whole history, or switch the setting off — switching it off deletes everything already stored. Removing the extension deletes it too.

Recorded user flows, if you record one

If you record a flow, the steps you performed are stored on your device so the flow can be re-run: for each step, what kind of interaction it was, a CSS selector for the element, and a short label such as button "Save".

Text you type into a field is recorded, up to the first 200 characters, because a flow cannot be replayed without it. That text is stored on your device along with the rest of the flow.

Fields judged sensitive are skipped: the value is dropped and the step is marked as omitted instead. That covers password and hidden fields, fields whose autocomplete marks them as a password, payment card or one-time code, and fields whose name, id or label suggests a secret (pass, secret, token, otp, cvv, cvc, card, ssn, pin).

That detection is a safeguard, not a guarantee — a field holding something private but named in a way the rules do not recognise would have its value recorded. If you are working with real personal data, record flows against test data, or leave flow recording switched off.

Flows are deleted when you delete them or uninstall the extension.

Scanning several pages at once

Scan site offers the pages linked from the page you are on, and scans the ones you tick. It reads the href of every link on the current page to build that list; reading links is not visiting them, and nothing is opened until you press start.

Only pages on the same site are offered, links are followed one level deep, and at most 25 pages are visited in a run. Links whose address suggests they act rather than show a page — a sign-out, a delete — start unticked and say why. Your tab visits each page in turn and returns to where you started when the run ends, including when you stop it early.

Each page is scanned the same way a single-page scan is, and the combined result is held in the panel for as long as it is open. It is not written to scan history unless you export it.

This is still your browser, signed in as you. A link that looks like an ordinary page can sign you out or change something, and no tool can tell that from the markup. Read the list before starting, and on an application with destructive links, scan a test account.

Manual review results, if you record any

The Manual checks view is a worklist of accessibility checks a scanner cannot decide — whether alt text describes its image, whether captions are accurate, whether reading order still makes sense. Nothing is stored until you record something.

When you mark a check as passing, failing or not applicable, or write a note against one, that result is stored on your device so the review survives a restart and can be handed over. Each stored review contains:

  • the page address, without the query string or the hash — https://example.com/invoices,

not https://example.com/invoices?customer=12345;

  • for each check you answered: the verdict, the time you recorded it, and your note.

Notes are free text. They contain exactly what you typed, up to 2,000 characters per check, and the extension does not inspect or filter them. If you write "the customer name on this invoice has no label", that sentence is stored. Treat a note the way you would treat a comment in a ticket.

Reviews are kept for up to 25 pages. Once there are more, the least recently updated is dropped. Nothing about a review is transmitted.

You can delete the review for the page you are on with Reset in the Manual checks view, delete every saved review from Settings → Manual reviews, or remove the extension, which deletes them all.

Source mapping

When you ask where an issue lives in your code, the extension reads your project's source files from the development server that is already serving the page — the same origin, no new network destination. What it reads is shown in the panel and is not written to scan history or anywhere else.

What is transmitted

Nothing, to anyone. There is no backend service, no telemetry, no crash reporting, no analytics and no third-party SDKs. The accessibility engine and all rules are bundled with the extension and run entirely on your device.

The extension makes exactly one kind of network request, and only when you ask it to: Find in source reads a source file from the server that is already serving the page you are looking at, as described above. It is the same origin the page came from, it is a read, and nothing is sent anywhere else. This section previously said "no network requests of any kind", which was wrong -- the Source mapping section two paragraphs up has always described this one.

Licence activation is included in this: keys are verified locally, not against a server.

Third parties

None. No data is shared with, sold to, or disclosed to any third party, because no data leaves your device.

Permissions and why they exist

  • scripting — runs the accessibility checks inside the page you chose to scan, and inside

its frames.

  • storage — saves your settings, ignore list, licence key, saved flows, scan history and

manual review results locally on your device.

  • contextMenus — adds the right-click scan entries.
  • Access to websites you scan — the extension scans whatever site you are looking at: a

local dev server, a preview build or a live site, so it cannot know those addresses in advance. Access is used only to perform a scan you explicitly requested, on the tab you are looking at.

Children

The extension is a developer tool and is not directed at children. It collects no personal information from anyone, including children.

Changes

If this policy changes, the updated version will be published here and the date above revised. Any change that would affect what data is collected or transmitted will also be called out in the extension's release notes.

Contact

<!-- REQUIRED BEFORE SUBMISSION: the Chrome Web Store will not accept a listing without a working contact address here, and this file must be reachable at a public URL. -->

[CONTACT EMAIL — replace before publishing]