Legal

Privacy policy

Last updated: September 28, 2026

WP Accessibility Fixer is a service by YLabs (“we”, “us”), operating the wpaccessibilityfixer.com website and the WP Accessibility Fixer MCP service at mcp.wpaccessibilityfixer.com. This policy explains what we collect, why, how long we keep it, and what we never do with it. The short version: we don’t keep copies of your content: for undo, we keep only the value each fix changed, never a whole post.

Your site content

  • When you ask for a check, our server reads your published pages and posts and your homepage from your site. The results of a check are kept in our server’s memory for up to 24 hours, so that reports and the progress count work. They are not written to our database.
  • When your assistant asks for a preview of a fix, the proposed change (for example the new alt text) is held in our server’s memory, so that your yes saves exactly what you saw. It is deleted within about 30 minutes, or when the change is saved. It is not written to our database.
  • When you confirm a fix, our server writes the change straight to your site. We do not keep copies of your posts or pages.
  • Alt text and link text are written by your own AI assistant; WP Accessibility Fixer saves what it writes to your site.
  • We do not use your site content to train AI models.

What we collect and why

Account information

Your WP Accessibility Fixer sign-in uses the same account system as our other products, WPWriter, WP Agent and WP Image Fixer. When you sign in, we keep your email address and, where your sign-in method provides it, your name. Where a password is used, it is stored only as a secure hash. We use this to sign you in and to send the account emails described below.

Site connection

For each site you connect, we store its address and name, the WordPress username that approved the connection, and the WordPress Application Password it created. The Application Password is stored encrypted at rest and is used only to perform the actions you request through your assistant. We never receive or store your WordPress login password.

The Application Password’s name in WordPress includes your account email in a shortened form (its first two letters and its domain, for example de…@example.com), so that WordPress’s approval screen shows which account the site will join. Other administrators of your site can see that name.

While a new connection is being completed, the new Application Password is held encrypted in our database until the connection link expires (15 minutes), and then deleted. If a confirmation page is shown and you choose “No, this is not my account”, no site connection is saved, and we ask your site to delete that Application Password.

Fix records

For each change we make: which site and which media item, post or page, the kind of fix, the value before and after (an alt text, or the one image, heading or link element that changed, never a whole post), and when it was made or undone. Marking an image as decorative is recorded the same way. This is what makes undo work and counts your monthly free fixes.

Audit log

For each tool call: which tool ran, on which site, whether it succeeded and, if not, the reason and the first part of the error message, how long it took, the size of the answer, the assistant client name, the user agent and the IP address. We use it for support, for the usage limits, to prevent abuse, and to see where people get stuck.

Sign-in and connection links

Short-lived records that make sign-in and connection links work. A connection link expires after 15 minutes and can be used only once.

Support messages

If you email us, we keep your message and our reply to help you.

What we don’t do

  • We don’t sell or rent your personal data. Ever.
  • We don’t read or mine your site content beyond what you ask WP Accessibility Fixer to do.
  • We don’t add scripts, widgets or trackers to your site.
  • We don’t share your data with advertisers.

How long we keep it

  • Check results: up to 24 hours, in memory only.
  • Previews of a fix: about 30 minutes, in memory only.
  • A connection waiting for your confirmation: until its link expires (15 minutes).
  • Account, site connections and fix records: for as long as your account exists, because undo depends on them. When your account is deleted, they are deleted with it.
  • Encrypted Application Password: until your account is deleted or you ask us to remove the site. Revoking it in wp-admin → Users → Profile → Application Passwords makes it useless immediately, even before we delete it.
  • Audit log: kept for 90 days, then deleted automatically (the deletion runs every hour). It is deleted straight away when your account is deleted.
  • Sign-in and connection links: expire within minutes and can no longer be used.
  • Support emails: kept in our support mailbox as long as needed to resolve your request and for our records. You can ask us to delete them.

Service providers

We rely on a small number of processors to run the service. Each receives only what is needed for its function:

  • Hosting infrastructure for our servers and database.
  • Cloudflare, for DNS, security and delivery of our website and service; traffic to wpaccessibilityfixer.com and mcp.wpaccessibilityfixer.com passes through it.
  • Mailgun, our email service provider (transactional email, sent from servers in the United States): your email address and the content of the emails we send you.
  • Google, only if you choose to sign in with Google.

ChatGPT, Claude and other AI assistants are not our processors: they are your own tools. What you type there, and the results WP Accessibility Fixer returns to the assistant (for example page titles and the elements a check found), are handled by that provider under its own privacy policy.

Email

We send account email only: the confirmation code when you sign up with an email address, sign-in confirmations and password resets. We send no advertising email.

Cookies and analytics

This website uses no tracking scripts, no analytics and no advertising cookies.

Your rights and deleting your data

Depending on where you live (including under the GDPR), you may have rights to access, correct, export or erase your personal data, and to object to its processing. Write to [email protected] and we will honor them.

To delete your account and its data, email us from your account address. We complete deletion requests within 30 days, except records we must keep for legal reasons. Because the account is shared with WPWriter, WP Agent and WP Image Fixer, tell us if you use those products too. Deleting your account never changes your site.

Security

Data is encrypted in transit (HTTPS/TLS), Application Passwords are encrypted at rest, and access to our systems is restricted. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

International transfers

Your information may be transferred to and kept on servers outside your state, province or country, for example in the United States, where data protection laws may differ. When one of our service providers processes personal data outside the European Economic Area or the United Kingdom, the transfer is covered by the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, which are part of that provider's data processing agreement.

Children

WP Accessibility Fixer is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you become aware that a child has given us personal information, please contact us.

Changes

If we make material changes to this policy, we will note it here by updating the date above and, for significant changes, tell you in the service or on this website before they take effect.

Contact

YLabs · [email protected] · Contact page