Legal

Privacy policy

Last updated: 20 April 2026

Plain-English summary

What we collect

Scan data

When you submit a URL to /api/scan(via the web form, CLI, Action, or any of the platform plugins), we fetch that URL with a headless browser, run axe-core against it, and return the result. We do not cache or store the scanned page's HTML, screenshots, or the scan result on our server. The result lives in the HTTP response only.

Anonymous usage metrics

We count per-day and per-all-time:

None of this is tied to a named individual. We do not set any third-party analytics cookies. The CLI sends one anonymous ping per scan ({source: 'axle-cli', event: 'scan_complete'}) which you can disable with AXLE_NO_TELEMETRY=1.

Account / billing data (paid plans only)

If you subscribe to Team or Business:

Card data is held by Polar. We never receive it.

Published statement contents

When you click "Publish verified" on the statement generator, everything you filled into the form — organization name, coordinator details, adjustments list, reporting channels — is stored and made publicly available at /s/<id>. Don't publish anything you wouldn't want indexed by Google.

What we never do

Subprocessors

We rely on the following infrastructure vendors:

Data retention

Your rights

If you are in the EU, UK, Israel, or another jurisdiction with a right-to-access / right-to-delete regime, email asaf@amoss.co.il. We will respond within 30 days. Given the minimal data surface, most requests can be handled by simply deleting your API key record and any statements you've published.

Contact

Privacy-related questions: asaf@amoss.co.il.