Privacy Policy
Last updated: October 6, 2026.
This is a marketing site — no payments taken here
wcagcheckr.com tells you about the wcagcheckr browser extension and what it costs. We don’t take payment on this site — you install the free extension and upgrade inside the app, so no card or billing details are ever entered here.
Site visitors
We aim to collect as little as possible. We do not sell personal data. If we use analytics, it’s privacy-respecting and aggregate — to understand overall traffic, not to track individuals.
The extension — what does and doesn’t leave your browser
The core audit — axe-core plus our analyzers — runs entirely in your browser. For that audit, your private, internal, and pre-launch pages are not sent to us or anyone else.
The exception is the optional AI features. They are off by default and require your own Anthropic API key. When you enable them, the extension sends the relevant page content — text, DOM snippets, and screenshots of the pages you audit — directly to Anthropic’s API using your key, so its model can evaluate what a rules engine can’t. So if you turn AI on while auditing a private or internal page, that page’s content leaves your browser to Anthropic, a third party, under your own account and Anthropic’s terms. We don’t receive it, but Anthropic processes it on your behalf — Anthropic is a sub-processor for the AI features. With AI off, no page content goes to Anthropic.
Account, licensing, and forensic anchoring run through our backend at api.wcagcheckr.com. Here is the complete list of what the extension sends there, and when:
- Licence sync — your licence token and a random device ID when you activate or validate a licence. The extension checks in with the licence server and will not run without a recent sync, on the free tier as well as paid.
- Tier configuration — a request for the current plan feature table, carrying the product name only; it is how plan changes reach the extension without a new release.
- In-app messages — a random device ID and the extension version when the extension checks for product messages, which happens on the free tier too.
- Scheduled-audit alerts — only if you switch on email or webhook alerts for a scheduled audit: the audited URL, the violation counts, and up to ten of the new findings (WCAG criterion, impact, CSS selector and a short description) so the alert can say what changed.
- Forensic anchoring (paid) — a cryptographic hash of the audit, the audited URL and the capture time when you seal an audit — not the audit's content.
- Crash diagnostics — off by default; if you opt in, the error message and stack trace with URLs, email addresses and licence tokens redacted.
Everything else — audit results, baselines, DOM snippets, settings — stays on your device. There are no analytics or tracking SDKs in the extension.
Contact
Questions about privacy? Email cliff@locustware.com.