Privacy policy

What we collect, why, where it goes, how long it stays, and how to have it removed.

Last updated 28 September 2026.

1. Who is responsible

Variantly, the operator of variantly.app, is the controller of the personal data described in this policy. Write to privacy@variantly.app for any request under it.

2. What we collect, and why

Your account: your work email address, the name you choose to set, and a session cookie (vt_session) that keeps you signed in. Basis: performing our contract with you, or our legitimate interest in running the free tools.

Captures of your product: screenshots, accessibility trees, screen-reader transcripts, focus traces, rule output and, for recorded journeys, short videos of the pages we test. These are captures of your product, not of your users. We never scan pages behind your customers' accounts, only the test account you give us. Basis: performing our contract with you.

The test account: its username, and its password sealed with AES-256-GCM under a key held only by our worker process. We never display it, and you can revoke it at any time. Basis: performing our contract with you.

Billing: company name, billing email, VAT or tax ID, plan and invoices. Card details are handled by Stripe and never reach us. Basis: performing our contract with you and our legal obligations on invoices.

Product analytics: which screens are used and which buttons are clicked, and the counts on your Overview (views of your public page, downloads, reviewer checks). Events carry a random identifier, or your account's identifier once you sign in, never your name or email address. The one exception: when you ask on checkout to be emailed when paid plans open, that request is kept with your account, so we know whom to write to. We use no third-party advertising or tracking. Basis: our legitimate interest in improving the product, and your request for the email.

Emails: receipts, drift alerts, nightly summaries, expiry and renewal notices, and one directory notification to a company whose published report we index. If you asked for it on checkout, one email when paid plans open. One short survey about our price, once, after you claim a page or finish a free scan. Your answers are stored with your account and used only by us. Every alert email says how to change who receives it or stop it.

3. The reviewer check

A file you upload to the reviewer check (DOCX, PDF, YAML or JSON) is read in memory, checked, and discarded. We do not store the file or its contents. Only the verdict counts, without the file, are recorded as an event.

4. Who else processes it

We use a hosting provider for the web app and worker, a managed Postgres provider, an object-storage provider for captures, Stripe for payments, a transactional email provider, a product analytics provider in the United States, and Anthropic for the AI tier. Anthropic receives captured page evidence (accessibility trees, transcripts and rule output) for the rows it proposes and returns a proposal; it never receives your test account. Each provider is bound by a data processing agreement, and the current list with regions is on the security page. We do not sell personal data.

5. How long we keep it

Captures that a published report rests on are kept for the life of that version, and for twelve months after a plan ends so that a frozen page still shows its evidence. Nightly captures that no report rests on are deleted after ninety days. Account, billing and invoice records are kept for as long as invoicing law requires. The sealed test-account credential is deleted when you remove it or when the plan ends.

6. Your rights

You can see, correct, export or delete your account data, withdraw a published version, and remove your company's directory page after verifying its domain. Where the GDPR or the UK GDPR applies, you also have the rights to restrict or object to processing, to data portability, and to complain to your supervisory authority. We answer every request within thirty days.

7. Cookies and similar technologies

Three cookies, each needed for the service to work. The session cookie (vt_session) signs you in. The owner cookie (vt_owner) keeps an anonymous draft with the browser that started it until the company claims it. When you continue with Google, a sign-in cookie (vt_oauth) ties Google's answer to your browser; it lasts ten minutes at most and is deleted when you come back from Google. There are no advertising cookies, and the public report pages set no cookies at all.

One further item is stored in your browser, in session storage rather than as a cookie. If you arrive through a link that names one of our launch channels (for example, a link ending in ?ref=hn), we store that channel's name under the key vt_ref, so that we can tell which channel led to a free scan, a reviewer check, a page claim or a payment made during the same visit. It contains only the channel name and nothing that identifies you or your device. It is deleted when you close the browser tab, and it is sent to us only with those forms, where it is recorded with the product analytics event described in section 2. A link naming anything other than one of our channels stores nothing. It is not needed for the service to work, and blocking it changes nothing else. Basis: our legitimate interest in knowing which channels bring visitors.

8. Changes to this policy

We post changes here with their date and email account holders about material ones.