Privacy Policy

Last updated: April 2026

1. Information We Collect

We collect information necessary to provide the Service, including: account information (name, email address) provided during registration through Clerk; code you submit for accessibility analysis; usage data such as the number of fixes performed; billing information processed through Stripe (we do not store your full payment details); and basic analytics such as page views and feature usage.

2. How We Use Your Information

We use the information we collect to: provide and improve the accessibility fixing service; process your code through AI models to generate accessibility improvements; manage your account, subscription, and usage limits; communicate with you about your account or the Service; and detect and prevent abuse or violations of our Terms of Service.

3. Code Processing and AI

When you submit code to fixa11y, it is sent to third-party AI services (currently Anthropic) for processing. This means your submitted code is transmitted to and processed by external AI infrastructure. We recommend that you do not submit code containing secrets, credentials, API keys, personally identifiable information, or proprietary code you are not authorized to share. We do not use your submitted code to train AI models, but our third-party AI providers may have their own data handling policies.

4. Third-Party Services

We rely on the following third-party services to operate fixa11y: • Clerk — authentication and user management. Clerk processes your login credentials and profile information. • Stripe — payment processing. Stripe handles all billing and payment card information. • Supabase — data storage. We use Supabase to store account data, usage records, and subscription information. • Anthropic — AI code processing. Code you submit is sent to Anthropic's API for accessibility analysis and fix generation. Each of these services has its own privacy policy governing how they handle your data.

5. Data Retention

We retain your account information for as long as your account is active. Usage records and scan history are retained to provide you with historical data and to enforce plan limits. If you delete your account, we will remove your personal information within a reasonable timeframe. Some data may be retained in backups or logs for a limited period as required for operational or legal purposes.

6. Data Security

We implement reasonable technical and organizational measures to protect your information. All data in transit is encrypted via TLS. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, or delete your information. You can manage most account data through your account settings. For additional requests, contact us using the information below.

8. Cookies and Tracking

We use essential cookies for authentication and session management. We do not currently use advertising or third-party tracking cookies.

9. Children's Privacy

The Service is not intended for use by children under the age of 13. We do not knowingly collect information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Continued use of the Service after changes constitutes acceptance of the revised policy. We will make reasonable efforts to notify users of significant changes.

11. Contact

If you have questions about this Privacy Policy or how your data is handled, please contact us at [support email placeholder].

This privacy policy represents basic product scaffolding and has not been reviewed by legal counsel. Customize as needed for your business.