We use Google Analytics to understand how visitors use this site. Accepting sets an analytics cookie; declining means we don't set one. See our Privacy Policy.

AltAuditorScan your site
← Back to AltAuditor

Privacy Policy

Last updated: September 18, 2026

Who we are

AltAuditor ("we", "us") is operated by Nenad Kozoder, an individual, registered at Stojana Protica 5, Kragujevac, Serbia. For the purposes of data protection law, we are the data controller for the personal data described in this policy.

Questions about this policy or your data can be sent to hello@altauditor.com.

What we collect

Account & sign-in.If you create an account, we collect your email address to send you a magic sign-in link (via Supabase Auth). We don't use passwords.

Free scan (no account needed). The free scan at /scan collects the website URL you submit, the email address you enter, and your IP address (used only to rate-limit abuse). We store the scan results (image counts, pages scanned) tied to that email address.

Connected CMS credentials.If you connect a Sanity or Payload project, the API token/key you provide is stored in our database, tied to your account, and access-restricted so only your account can read it. It is not shared with anyone except the CMS itself, to make the read/write calls your project needs. It receives the same storage protection (encryption at rest) as the rest of our database, but isn't separately encrypted at the application layer beyond that.

Images.When you connect a CMS or run a scan, we don't keep copies of your image files on our servers. Each image is fetched on demand, resized, sent to our AI vision provider to draft alt text, and then discarded -- we only store the resulting metadata (URL, dimensions, a content hash, and the alt text itself).

Who we share it with

We use a small number of service providers ("sub-processors") to run AltAuditor. None of them can use your data for their own purposes.

  • Supabase -- our database and authentication provider. Stores your account, project, and image data.
  • Vercel -- hosts the application.
  • Upstash (QStash) -- runs the background jobs that generate and write back alt text.
  • OpenAI or Google -- whichever AI vision provider your project is configured to use receives the images you ask us to process, in order to draft alt text. It does not receive your CMS credentials or account email.
  • Paddle-- our payment processor and Merchant of Record. Handles billing, invoicing, and refunds; receives what's needed to process a payment.
  • Resend -- sends transactional email (magic links, scan results, account notifications).

We don't sell your data, and we don't use it for advertising.

Analytics

We use Google Analytics 4 to understand how visitors use our site. GA4 sets cookies and can constitute personal data under GDPR, so we don't load it until you accept the cookie banner shown on your first visit. If you decline, no analytics cookie is set and GA4 never loads for you.

How long we keep it

Proposed retention policy, pending confirmation -- treat the periods below as a draft, not a final decision.

  • Account data(email, projects, images, alt text): kept while your account is active. If you delete your account, we delete this data within 30 days, except where we're legally required to keep records longer (e.g. billing records for tax purposes).
  • Free scan data (no account): kept for 12 months, then deleted.
  • CMS credentials: deleted immediately when you disconnect a project.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, email hello@altauditor.com-- we'll respond within a reasonable time.

Changes to this policy

We may update this policy as the product changes. We'll update the date at the top of this page when we do.