Accessibility Cloud Companion privacy Policy2026-07-25T00:03:53+02:00

Last updated: 2026-07-24

This Privacy Policy describes how Accessibility Cloud AB (Swedish reg. no. 559345-6204) processes data in connection with the Accessibility Cloud Companion browser extension (the “Extension”). It complements, and does not replace, the general Accessibility Cloud Privacy Policy.

How the Extension works

Accessibility Cloud Companion is a browser extension for Accessibility Cloud customers. It runs accessibility scans locally in the browser (like Accessibility Cloud Lite), supports manual accessibility audits of the pages the user chooses to audit (component detection, guided conformance tests, and auditor verdicts, notes, and findings), provides disability simulations (visual, motor, cognitive, and a screen-reader simulation), lets the user capture results from pages that are not reachable by the hosted crawler (localhost, pre-production environments, VPN-gated sites), and lets the user capture cookies, localStorage, sessionStorage, and recorded user flows for use with Accessibility Cloud scan settings. All captured data is stored locally in the browser and is only ever transferred over an extension-to-web-app bridge that is restricted, at the browser level, to https://app.accessibilitycloud.com.

The Extension never scans, audits, or captures pages on its own. Every scan, capture, audit step, and simulation is started by the user. The Automatic capture mode walks same-origin links from the page the user is on and captures up to a user-configured number of pages, but only after the user explicitly starts it, with visible progress and Stop / Pause controls.

Categories of data processed

  • Website content of pages the user actively scans. The content script reads the DOM of the active tab to identify accessibility issues. This content is processed locally in the browser.
  • Captured scan bundles. When the user presses Capture page (or runs an Automatic capture walk), the current page’s scan results and a viewport-sized screenshot are stored in local extension storage, keyed by origin. Data never leaves the device except over the trusted bridge to app.accessibilitycloud.com. Each time the user opens the Capture surface, the Extension shows a mandatory notice instructing them not to capture pages showing identifiable personal data (and to use test accounts or anonymized data instead); continuing requires explicitly acknowledging that capturing personal data anyway is the user’s own legal responsibility.
  • Audit records. When the user audits a site, the Extension stores, per site origin: the detected page components (CSS selectors and short text excerpts from the page, such as headings or link text, used to label them), automated check results, the user’s own test verdicts and written notes, custom findings the user writes, and any screenshots or images attached to them: element screenshots the user captures from the audited page and images the user pastes or uploads into a finding’s notes. All of this is stored locally in extension storage (screenshots and attached images in the browser’s local IndexedDB store) until the user clears the audit or uninstalls the Extension, and is only ever transferred over the trusted bridge described below.
  • Focus-indicator inspection captures. The keyboard focus-indicator test takes viewport screenshots of the page before and after focusing each element to detect whether a visible focus indicator appears. These captures are held in memory in the inspected page only; they are discarded when the page is reloaded or the inspection is re-run, are never written to extension storage, and never leave the device.
  • Simulations. Disability simulations run entirely inside the current page and store nothing. The screen-reader simulation additionally reads page text aloud through the browser’s built-in text-to-speech engine (the tts permission); the narrated text is handed to the browser / operating-system speech engine and is not sent to Accessibility Cloud.
  • Clipboard copies of localStorage, sessionStorage, and cookies. When the user explicitly clicks Copy on one of the corresponding Utilities rows, Companion reads the current values from the active tab (cookies via the cookies permission, which includes HttpOnly cookies), serialises them to JSON, and writes the JSON to the system clipboard. These values are not persisted in extension storage and are not available over the trusted bridge; they exist only on the system clipboard after the explicit user action, and the user is expected to paste them into Accessibility Cloud scan settings by hand.
  • Recorded user flows. When the user records a flow via the Utilities tab, the recording is stored in local extension storage under a stable flow id. It is only transmitted when the user copies it to the clipboard or the Accessibility Cloud web app pulls it over the trusted bridge.
  • Account data (optional). If the user chooses to connect the Extension to an Accessibility Cloud account, the account-related personal data described in the general Privacy Policy applies.

The Extension does not collect personally identifiable information beyond what the user explicitly captures, authentication credentials beyond what the user explicitly captures via the cookie utility, financial data, health data, location data, browsing history outside the tabs the user actively scans, or user-activity signals such as keystrokes, mouse movements, or scroll behaviour outside an active flow recording or an accessibility test the user is running (for example, the tab-order test records which page elements receive keyboard focus while it is active).

Purposes, legal bases, and retention

Processing activities related to the Extension
Purpose Legal basis (GDPR Art. 6) Retention
Providing the accessibility-scanning and capture functionality of the Extension. Performance of a contract, or legitimate interest where no contract exists (Art. 6(1)(b) and (f)). Website content is processed in memory for the duration of a scan, audit step, or simulation and is not retained beyond what the user captures. Captured scan bundles, audit records (including notes, findings, screenshots, and attached images), and flow recordings remain in local extension storage until the user clears them or uninstalls the Extension. Focus-indicator inspection captures exist only in page memory and are discarded on reload. localStorage, sessionStorage, and cookie values copied to the clipboard are not retained by the Extension at all.
Transferring captured data to the user’s Accessibility Cloud account. Performance of a contract (Art. 6(1)(b)). Transfer occurs over a browser-enforced channel restricted to https://app.accessibilitycloud.com. Once transferred, the general Privacy Policy applies.

Permissions requested by the Extension

The Extension requests the minimum browser permissions required for its functionality:

activeTab, scripting
Used to inject the analysis script, storage readers, and flow recorder into the tab the user has explicitly chosen to work with.
storage, unlimitedStorage
Used to store captured scan bundles, audit records, screenshots, flow recordings, and user-interface state locally on the user’s device. unlimitedStorage lifts the browser’s default local-storage quota so that screenshot-heavy audits of large sites do not fail mid-way; it does not grant access to any additional data.
sidePanel, tabs
Used to display results in the browser side panel and to refresh them when the user switches or reloads tabs.
cookies
Used by the Capture cookies utility to read the active tab’s cookies (including HttpOnly cookies) so they can be reused in Accessibility Cloud scan settings. Reading happens only on explicit user action.
clipboardWrite
Used when the user explicitly presses a Copy action on a captured snapshot or recording.
tts
Used by the screen-reader simulation to narrate page content aloud through the browser’s built-in text-to-speech engine. Narration happens only while the user runs the simulation.
Host access to all URLs
Required because the user may audit any page, including pages behind authentication, on internal networks, or on localhost. This permission is used solely to operate on the tab the user is actively inspecting.

Data sharing

The Extension does not transmit page content, scan results, URLs, storage snapshots, cookies, flow recordings, or any other processed data to Accessibility Cloud servers or any third party, except:

  • The bridge to the Accessibility Cloud web app. The Chrome externally_connectable manifest field restricts inbound extension messages to the single origin https://app.accessibilitycloud.com. When the user is signed into that web app and initiates an import, the web app can read captured scan bundles, audit findings (including their screenshots and attached images), and flow recordings from the Extension over this channel.
  • The system clipboard. When the user explicitly presses a Copy action, the relevant snapshot is written to the system clipboard.
  • The browser’s text-to-speech engine. While the user runs the screen-reader simulation, the narrated page text is passed to the speech engine provided by the browser or operating system. Which engine handles it (and whether that engine is local or cloud-backed) is determined by the browser and operating-system configuration, not by the Extension.

No analytics, telemetry, advertising, or tracking code is included in the Extension.

User rights

The rights set out in the “User rights” section of the general Privacy Policy apply to any personal data processed in connection with the Extension. Because captures are stored only on the user’s device, users can exercise their right to erasure in relation to that data by clearing the Extension’s storage or uninstalling the Extension.

Contact

Accessibility Cloud AB
c/o No18, Nybrokajen 7
111 48 Stockholm, Sweden
Email: privacy@accessibilitycloud.com