Skip to main content

Legal

Privacy policy

Affido holds three kinds of data: who you are, what your product looks like, and — if you enable signed-in scanning — a credential for your own software. This page says what happens to each, who else sees it, and how to get rid of it.

Last reviewed September 2026

What we collect

Account
Your email address, the name of your organisation, and who you invite. We do not store passwords — sign-in is a one-time emailed link.
Products and evidence
The URLs you ask us to scan, the page content our crawler retrieves, the findings and reports derived from it, your answers to conformance questions, and the questionnaires you paste in.
Credentials
If you enable signed-in scanning, the username and password, session cookies, API key or HTTP Basic credentials you supply for your own product.
Billing
Handled by Stripe. We store a customer identifier and your plan status; we never see or store card numbers.
Operational
Server logs, job records and API usage counts, kept to run and debug the service.

We do not run advertising or analytics trackers. The only cookie set is the one that keeps you signed in.

Credentials, specifically

Handing a vendor a working login to your own product is the most consequential thing you can do here, so this is what happens to it.

  • It is encrypted with AES-256-GCM before it reaches the database, bound to the product it belongs to. A stored credential copied to another product fails to decrypt rather than crossing between customers.
  • It is write-only. Nothing in the application reads one back, and there is no screen, export or support tool that will show it to you or to us again.
  • Everything the crawl collects is stripped of your credential’s values before it is stored or sent for analysis. Products routinely echo a token back on a settings page, and without this it would end up in a report you email to a buyer.
  • It is never sent to the model, never written to a log, and removed from error messages.
  • Deleting it from product settings removes it immediately. Use a dedicated read-only test account with the least access that reaches the screens you need attested.

Who else processes your data

We use a small number of subprocessors. Page content is sent to Anthropic for analysis; that is the part of the service that judges what automated testing cannot.

Anthropic
AI analysis of page content, conformance drafting, questionnaire answers. Receives crawled page structure and text, with credentials redacted.
Railway
Hosting and the database. Holds everything at rest.
Stripe
Payments. Receives your email and billing details directly.
Resend
Transactional email — sign-in links, scan results, invites.

We do not sell your data, and we do not use your product’s content to train models.

What is public, and only because you made it so

A report share link and a hosted accessibility statement are readable by anyone with the URL — that is what they are for. Nothing is published until you publish it, and unpublishing or archiving the product stops the link working. Everything else in your account is private to your team.

How long we keep it

Account and product data is kept while your account is open. Sign-in links expire after twenty minutes and are purged; sessions expire after thirty days. Operational logs are kept for a short period for debugging.

Delete a product to remove its scans, findings, reports, statements and credentials. Ask us to close your account and we will delete the rest, except anything we must keep for tax or accounting purposes.

Your rights

Depending on where you are, you may have the right to access, correct, export or delete your personal data, and to object to processing. Most of this you can do yourself from the dashboard; for the rest, write to us and we will act within thirty days.

If you are in the UK or EU, our lawful basis is performance of our contract with you for the service itself, and legitimate interests for security and operational logging.

Who we are

CTL-ALT-DEFEAT, LLC is the controller of the personal data described on this page. Privacy requests — access, correction, deletion, or a copy of your data — go to support@notifications.usegoodform.co, and we answer within 30 days.

Privacy policy · Affido