01Introduction
This policy explains how Accessible.org, LLC, a Texas limited liability company ("we", "us"), handles personal information in connection with StrongPrivacy: the website at strongprivacy.com, the dashboard, the free scan, and the consent runtime, Shopify app and WordPress plugin that customers install on their own websites.
Questions or requests about your information go to info@accessible.org.
02Nature of the platform and our role
StrongPrivacy handles two different kinds of personal information, and our role differs between them:
- Information about our customers and site visitors (your account, your billing, your visit to strongprivacy.com). We decide how this is used, so we are its controller, and this policy covers it.
- Information about visitors to our customers' websites (the consent choices their visitors make). Our customer decides how this is used and is its controller; we process it on the customer's behalf under the data processing addendum. If you visited a website that uses StrongPrivacy and have a question about your choices there, contact that website; section 4 explains what the runtime stores.
03Information we collect
Account information. Your name, email address and password when you create an account, stored as a salted scrypt hash and never in readable form; the workspace name you choose; your role in the workspace; and invitations you send or accept.
Content you submit. The websites you register, the business name, contact email and policy links you give for them, the consent configurations you publish, the scans you run and their results, notes, data-request records and exports.
Billing information. Your plan and subscription state. Card payments are handled by Stripe, which receives the workspace owner's email and organization name; we never see or store full card numbers. Shopify App Store subscriptions are billed by Shopify, which shares your shop's name and domains with us.
The free scan. The web address you enter, and what the scan observes on that site: the third parties it contacted, cookie names and domains, and the pages it reached. The scan record does not require an account, name or email. The request still reaches our hosting and security systems, whose access logs can receive an IP address as described below.
Early access and contact. Early-access requests and support messages are emails you send us from your own mail program, so we receive whatever you include in them. The website does not store what you type into the early-access form.
Automatically collected information. Application request handling and hosting access logs can receive the IP address and requested address of a request. The application also uses IP addresses for a few minutes to limit abusive traffic. As of this policy's last-updated date, the application dependency and data-flow review found no analytics, advertising or behavioural-tracking tools on strongprivacy.com. This is an operational fact that must be rechecked when deployment dependencies change; current browser storage is listed in the cookie policy.
04The consent runtime on customer websites
When a visitor to a customer's website makes a consent choice, the StrongPrivacy runtime stores that choice on the visitor's device and sends a consent record to us for the customer. The record holds a random pseudonymous key generated in the visitor's browser, the categories chosen, the region the rules were applied for, the configuration version, whether the choice came from the banner or the preference center, and the time.
Consent records do not contain the visitor's IP address, browser details, name or email. The region comes from a country code supplied by the hosting edge, which can infer location from the network request, rather than from a raw IP value written into the consent record. Each record is chained to the previous one with a cryptographic hash so that later changes can be detected.
05How we use your information
- To provide the Service: run your workspace, publish your configuration, record consent, run scans and produce exports.
- To keep it secure: authenticate you, detect and limit abuse, and keep an audit trail of sign-ins, changes and exports.
- To bill you and manage your subscription.
- To send service email: address confirmation, password resets, invitations and, if you turn them on, operational alerts about your sites. We do not send marketing email or newsletters.
- To answer your requests and support questions.
- To meet legal obligations and enforce our terms.
06Use of artificial intelligence
Nox is an optional dashboard assistant, disabled by default. If the feature is available, a workspace owner must review the selected provider and model in Settings and enable it before a question can be processed. Changing the provider or model requires a new owner review.
When you send a question, we send that question, recent messages from the same conversation, and selected summaries of saved workspace information to the configured AI provider. Summaries can include site names and status, scan coverage and finding titles, saved consent settings, and scan allowance. We exclude raw visitor consent records, HAR captures, cookie and storage values, raw request evidence, integration secrets, and unsaved form fields. Information you type into a question is still sent, so avoid entering personal or secret information.
A workspace can separately enable scan briefings. Where it has, we also send selected summaries of a verification scan to the same provider when that scan finishes, without anyone asking, and store the short briefing the provider returns on the scan. The same exclusions apply, the briefing contains no questions, and no scan is sent for a briefing unless a workspace owner has enabled the option. A weekly digest option does the same once a week across the whole workspace and is shown in the dashboard only; nothing is emailed. Where evidence comparison or technology classification are enabled, the names of third-party providers a scan discovered are included in what we send. Where regression alerts are enabled and a workspace owner has turned them on, we email that briefing to workspace owners; that is the only Nox output we send by email. Where privacy summaries are enabled, we draft a description of a site on request from the same information and keep it for the same period.
Supported configurations use OpenAI, Anthropic (Claude), or OpenRouter and its specified destination provider. The selected choice is shown before opt-in. We do not use these conversations to train our own models. The provider’s processing and retention terms must be verified for the deployed account; disabling provider-side conversation storage is not a promise of zero provider retention. See the provider register and Nox guide.
Conversations are private to your account in the selected workspace, expire 30 days after creation, and can be deleted earlier from Nox history. A scan briefing belongs to the workspace rather than to one person, is visible to everyone who can read that scan, and expires on the same schedule. Aggregate usage counts are kept separately and do not contain message content. Turning Nox off stops new questions and pending work; it cannot recall information already sent to a provider.
07How we share your information
We do not sell personal information or share it for advertising. We share it only:
- with service providers that run StrongPrivacy for us. The current subprocessor draft identifies the providers visible in the reviewed design, but must be completed with the final deployment and contracts before production processing begins;
- with Stripe or Shopify, to take payment, and with Shopify, when you connect a store;
- when the law requires it, or to protect the rights, safety or security of our customers, the public or us; and
- with a successor if StrongPrivacy is sold or merged, under the same protections, with notice to you.
08Data ownership and portability
The records StrongPrivacy keeps for your sites belong to you. While your workspace is active you can export consent evidence, sites, scans, integrations and policies as CSV from the dashboard, and read consent records through the API with an API key.
09Data retention
- Consent records, scan reports and audit events: the application assigns a 12-, 24- or 36-month workspace window, depending on the plan and the owner's setting, and its retention worker deletes records beyond that window. Moving to a lower plan never shortens a window already in force. The operator must verify the production worker schedule and backup expiry before approving this draft policy.
- Free scan results: deleted within 24 hours.
- Sign-in sessions: 7 days, and ended at once when you sign out or change your password. Confirmation and reset links expire after 24 hours and 1 hour; invitations after 7 days.
- IP addresses used to limit abuse: no longer than 15 minutes. Hosting and application access logs are retained according to the configured provider and deployment retention settings for security and troubleshooting. The exact maximum must be entered in the completed vendor register before this draft policy is approved; ask info@accessible.org for the current setting.
- Account and workspace information: for as long as the account is open. There is currently no automatic deletion merely because an open account is inactive. When a paid plan ends, the workspace moves to the Free plan and records remain subject to its configured retention window. The owner can request workspace deletion at any time.
- Payment records: as long as tax and accounting law requires.
To close your account and delete your workspace, email info@accessible.org from the address on the account. We confirm the request with the workspace owner, delete the account and workspace data within 30 days, and tell you when it is done. Export anything you need first.
10Data security
We protect information with measures including:
- salted scrypt password hashing;
- signed, HTTP-only session cookies that can be revoked immediately;
- AES-256-GCM encryption of stored connector credentials, such as Shopify tokens and WordPress secrets;
- workspace queries scoped to the authenticated workspace;
- signature or shared-secret verification on the supported signed Stripe, Shopify and WordPress integration messages before state changes are applied;
- rate limits, an audit trail of sign-ins, changes and exports, and strict security headers; and
- scans run in an isolated browser that can reach only public addresses.
No system is perfectly secure. If a breach affecting your personal information occurs, we will tell you without undue delay, as the law requires. More detail is in the trust center.
11Your rights
Depending on where you live, including under the GDPR and UK GDPR in Europe and the United Kingdom and under California law, you may have the right to:
- access the personal information we hold about you;
- correct it;
- delete it;
- receive a copy in a portable format;
- restrict or object to how we process it; and
- withdraw consent where we rely on it.
Email info@accessible.org to use any of these rights. We may need to confirm your identity. We answer within the period required by the law that applies—for example, generally one calendar month under the GDPR and UK GDPR, subject to their extension rules. We will not treat you differently for using a right where the law prohibits that treatment. You may also complain to the relevant data protection authority.
Where our legal basis matters under the GDPR, we rely on performing our contract with you (to run the Service), our legitimate interests (to secure it and prevent abuse), and legal obligations (to keep billing records).
12Additional provisions
Children. StrongPrivacy is a business service and is not intended for anyone under 16. We do not knowingly collect information from children; if you believe we have, contact us and we will delete it.
International transfers. Accessible.org, LLC is based in the United States, and our service providers may process information in the United States and other countries. The current data processing addendum is a draft and does not claim that unsigned transfer schedules are already in place. Before a restricted transfer from Europe or the United Kingdom, the applicable parties, subprocessor locations, SCC module and options, annexes, UK Addendum or other valid safeguard, and any required transfer assessment must be completed and verified.
Changes. We will post any change to this policy here and update the date at the top. If a change is material, we will tell account holders by email before it takes effect.
Questions, or requests for a prior version of this document, go to info@accessible.org.