plumb

Legal

Privacy Policy

Last updated: May 2026

Plumb (“Plumb,” “we,” “our”) provides automated accessibility scanning and report generation services. This Privacy Policy explains what information we collect, how we use it, and the choices you have. We've tried to write it like a human, not a lawyer.

1. Information we collect

Account information

When you create an account, we store:

  • Email address — used for sign-in (we send magic links via Resend), for product updates you can opt out of, and to deliver completed scan reports.
  • Subscription status — your tier (free, Standard, Pro), Stripe customer ID, and billing-period dates. We do not store credit-card numbers or CVCs; payment data lives entirely with Stripe.

Scan inputs and results

When you submit a URL for scanning, we store:

  • The seed URL and the list of pages discovered or selected for audit.
  • Page screenshots captured during the audit (rendered in our headless Chromium environment — we do not load any of your authenticated state).
  • Scan results — accessibility findings, AI commentary, and the final PDF report we generate.

Operational data

We log standard application metrics: timestamps, scan duration, success/failure status, and IP-based rate-limit counters. This data is used for reliability and abuse prevention only.

2. How we use your information

  • To deliver the service you signed up for — running scans, generating reports.
  • To send you transactional email: magic-link sign-in, completed scan delivery, billing receipts, and security alerts. We don't send promotional email unless you explicitly opt in.
  • To enforce per-tier usage limits (per-scan page caps, monthly page budget, concurrent scans).
  • To improve the product. Aggregated metrics — average scan duration, common failures, popular WCAG levels — are reviewed in our internal admin dashboard. Individual scan content is not used for product analytics.

3. AI processing

Paid-tier scans send page HTML, axe-core findings, and screenshots to a third-party AI provider for augmented review. We use enterprise-grade AI subprocessors that operate under SOC 2 / industry-standard data agreements; by default these providers do not train models on API content. The current list of subprocessors is available on request — email legal@plumbcompliance.com.

We do not send your credentials, cookies, or session state to AI providers. Only the publicly accessible content of pages you asked us to scan is transmitted.

4. Data sharing

We do not sell your data. We share information only with the third parties needed to operate the service:

  • Stripe — payment processing and subscription management.
  • Resend — transactional email delivery.
  • Microsoft Azure (Blob Storage) — hosts generated reports and scan JSON, served to you via short-lived (5-minute) presigned URLs.
  • Third-party AI providers — augmented page review, as described in section 3.

5. Data retention

  • Scan reports and screenshots are retained for the lifetime of your account, accessible from your dashboard. You can delete individual scans at any time. On account closure, we delete all scan content within 30 days.
  • Account data (email, subscription) is retained while your account is active and for up to 90 days after closure for billing reconciliation.
  • Operational logs are retained for 30 days, then aggregated and anonymized.

6. Your rights

Regardless of where you live, you can:

  • Access the personal data we hold about you — request a copy by emailing us.
  • Correct or delete your account and all associated scans.
  • Export your scan history in JSON format.
  • Opt out of any non-transactional email at any time (you'll always receive sign-in links and report-ready notifications while you have an active scan).

Plumb is a US-only product. If you're in California, the CCPA / CPRA gives you the right to know what we collect, to delete your data, to correct inaccurate data, to opt out of any sale of personal information, and to limit the use of sensitive personal information. We don't sell personal information. California residents can email us at the address above to exercise any of these rights.

7. Security

Passwords are not stored — sign-in is exclusively via magic-link email. Reports are stored in encrypted-at-rest blob storage and served via short-lived presigned URLs (5-minute TTL). Sessions use HttpOnly cookies with SameSite=Lax. We use industry-standard TLS for all traffic.

That said: no system is unbreakable. If we ever detect a breach affecting your account, we will notify you within 72 hours of confirmation, per applicable law.

8. Children

Plumb is a B2B compliance product. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be sent to your account email at least 30 days before they take effect. The “Last updated” date at the top of this page is authoritative.

10. Contact

For privacy questions, data requests, or to exercise any of the rights above, email privacy@plumbcompliance.com.


See also: Terms of Service