Skiplink

Privacy

What Skiplink collects, why, where it goes and how to get rid of it. Short, because there is not much of it.

Last updated 27 August 2026.

The short version

Who is responsible

Skiplink is operated by the entity named at the bottom of this page, which is the controller for the data described here. Questions and requests go to privacy@skiplink.app and are answered within 30 days.

What we collect

DataWhyLegal basis
Email address and account id, from Google sign-in To tie your reports and monitored sites to you, and to let you sign back in Performance of a contract
Alert address, if you turn on monitoring To send the alert you asked for Performance of a contract
Findings: URL, WCAG criterion, CSS selector, measured value and its threshold, timestamps The dated record that is the product Performance of a contract
Server logs from the report pages and the API: IP address, user agent, time, path Keeping the service up and stopping abuse Legitimate interests

Findings usually describe public web pages and are not personal data. If a page you audit happens to contain someone's name in an element we quote back to you, that quote is part of your findings and you control it — delete the report and it is gone.

What we never collect

Where it is stored

Findings, accounts and monitoring settings are held in Google Cloud Firestore in Frankfurt (europe-west3). The server-side crawler and the report pages run in the same region. Alert emails are sent through Resend in Ireland (eu-west-1).

Both providers are incorporated in the United States, so standard contractual clauses apply to them even though the data sits in the EU. We would rather write that plainly than claim data never leaves the EU and have to explain the asterisk later. The full list, with what each provider sees, is on the sub-processors page.

How long it is kept

WhatKept for
Shared report links and the findings behind them30 days, then deleted by a daily job
Whole-site scan results60 days
Monitoring baselines and settingsUntil you stop monitoring the site
AccountUntil you ask us to delete it
Server logs30 days
Local audit history in your browser8 weeks, and you can clear it yourself at any time

Your rights

Under the GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, object to processing based on legitimate interests, and ask for it in a portable form. Write to privacy@skiplink.app.

Deleting your account removes the findings, monitored sites and share links attached to it. Anything already downloaded as HTML or CSV is on your own machine and stays there.

You can also complain to your national data protection authority. We would prefer you told us first, but it is your right either way.

Shared reports

A share link is unlisted, marked noindex, and expires after 30 days. The identifier in the URL is the credential — anyone who has the link can open the report, so treat it the way you would treat the report itself. You can revoke a link at any time from the extension, which takes effect immediately.

Changes

If this page changes in a way that affects what we do with your data, the date at the top changes and account holders are told by email. We do not quietly widen it.