Skip to main content
Pulxon
Menu

Privacy policy

Last updated September 24, 2026.

Pulxon checks websites for accessibility problems and provides an accessibility widget. This policy explains what we collect when you use pulxon.com, the dashboard, the API and the widget, why, and what you can do about it. The short version: we collect what the product needs to work, we do not sell or share personal information for advertising, and there are no advertising or analytics trackers on pulxon.com.

What we collect and why

When you check a page for free

  • The address you check and the device type. Our scanner opens that public page in a browser and stores the result and screenshots of the page. If the public page shows personal information, it can appear in those screenshots.
  • A one-way hash of your IP address, to limit how many checks one visitor can start. We do not store the IP address itself for this.
  • A bot check by Cloudflare Turnstile, which processes your IP address and browser signals on Cloudflare’s side to tell people from bots.

When you ask for the full report by email

Your email address, to send the report, and whether you ticked “Send me occasional product updates”. We only send product updates if you ticked it, and every update lets you unsubscribe.

When you create an account

  • Your email address and name, and the sign-in links we email you.
  • If you sign in with Google: your name, email address and profile picture address from Google.
  • For each sign-in session: a session cookie, and the IP address and browser name the session started from, to keep your account secure.
  • What you add: website domains, widget settings, the pages you monitor and their results, accessibility statements, and API keys. We store only a fingerprint (hash) of each API key, never the key itself.

When you connect Google Search Console

Only if you choose to connect it for a website on a paid plan. We ask Google for read-only access to Search Console and read the list of your properties and, for the property you pick, the search clicks and impressions of each page of that website over 28 days. We use them only to rank that website’s accessibility issues and to suggest pages to monitor. We keep Google’s access token encrypted. Disconnecting deletes the data and asks Google to cancel our access; you can also remove it in your Google account.

Pulxon’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, do not sell it, and people at Pulxon do not read it except to fix a problem you ask us about, for security, or where the law requires it.

When you ask for an AI fix suggestion

Only when you press “Suggest a fix” while signed in. We send the failing element’s HTML from the checked page, the rule it fails and our fix guidance to Anthropic, whose Claude model writes the suggestion. We keep the suggestion with the check (and delete it with the check after 90 days) and count how many you ask for each day. Nothing about you other than that count is sent or kept.

When you use the API or the MCP server

The pages you check and the time each key was last used. Checks started through the API are stored like any other check. Up to 30 checks an hour are counted per account.

The widget on your visitors’ websites

The widget sets no cookies, and Pulxon keeps no record of the people who visit the websites that install it beyond the short server logs described below. A visitor’s choices, such as bigger text or a color mode, stay in their own browser’s local storage. When the widget loads, the visitor’s browser fetches its script, language files and the site’s settings from our servers, which, like any web server, see the visitor’s IP address and browser name in their logs. We also record the first web address where a site’s widget was seen, to confirm the installation to the site owner. Reading text aloud uses the speech voices of the visitor’s own browser; Pulxon receives nothing from it.

On every request

Our servers keep a short log of requests (IP address, the address requested, the time and the browser name) to run the service and to investigate abuse and errors.

Cookies and local storage

pulxon.com uses only cookies it needs to work:

  • A session cookie, once you sign in, so you stay signed in.
  • A short-lived cookie while you connect Search Console, so Google’s answer can be matched to your browser.
  • Cookies Cloudflare Turnstile may set for its bot check.

There are no advertising, analytics or social media cookies. The widget sets none at all.

Who helps us process it

We use a few service providers, who process data on our behalf and only for these purposes:

  • Our hosting provider, which runs our servers and database.
  • Cloudflare, for DNS, the Turnstile bot check, and storage of screenshots and reports (R2).
  • Resend, which delivers our emails.
  • Anthropic, only when you ask for an AI fix suggestion.
  • Google, only if you sign in with Google or connect Search Console.

We do not sell personal information and do not share it for cross-context behavioral advertising. We disclose information when the law requires it, or to protect the security of the service and its users.

How long we keep it

How long each kind of data is kept
DataKept
Page checks, their results, screenshots and AI fix suggestions90 days, then deleted automatically
Email address for a report, without consent to product updates90 days, then deleted automatically
Email address with consent to product updatesUntil you withdraw consent
Sign-in linksUntil used or expired (minutes)
Sign-in sessions, with IP address and browser name30 days after the last use, then deleted automatically
Rate-limit counters (hashed IP address)2 days
Account, websites, widget settings, monitoring history, statements, API keysUntil you delete them or your account
Search Console clicks per pageReplaced every 7 days; deleted when you disconnect
Server logs (IP address, requested address, browser name)Overwritten as they grow, at most 30 MB per service
Daily database backupsUp to 30 days, so deleted data is gone from backups within 30 days

Your choices and rights

  • Delete your account at any time in the dashboard. It removes your account, websites, settings, monitoring history, statements, API keys and Search Console connections at once. The page checks themselves are deleted with all other checks after 90 days.
  • You can ask us what we hold about you, for a copy, or to correct or delete it, including an email address you gave for a report. California residents have these rights under the CCPA, and people in other places may have similar rights. We will not treat you differently for using them.
  • Write to [email protected] from the address concerned. We may ask you to confirm the request from that address, and we answer within 45 days.

Security

Connections to Pulxon use HTTPS. Access tokens from Google are encrypted, API keys are stored only as hashes, and IP addresses used for rate limits are hashed. No system is perfectly secure; if a breach affects your personal information, we will tell you as the law requires.

Children

Pulxon is a service for businesses and is not directed at children under 16. We do not knowingly collect their information.

Where the data is

Our servers and service providers may process data in the United States, the European Union and other countries, with the safeguards their terms provide.

Changes and contact

When we change this policy, we update the date at the top; if a change matters for how we use your information, we tell account holders by email first. Questions: [email protected].