← BackRedFlag

Privacy Policy

Last updated: 15 July 2026

Who we are

RedFlag ("we", "us", "our") is a WCAG accessibility auditing tool consisting of a Chrome extension and a web dashboard at redflagstatus.com (the "Service"). RedFlag is operated by Qern Pty Ltd, a company based in the Australian Capital Territory, Australia (ABN 68 697 076 832). Qern Pty Ltd is the data controller for the personal information described in this policy.

This policy explains what personal information we collect through the Service, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It should be read together with our Cookie Policy and our Terms of Service.

Personal information we collect

Account and identity data. When you sign up we collect your email address and a password, which Supabase Auth stores in hashed form — we never see or store your password in plain text. If you enable two-factor authentication, Supabase stores a TOTP authenticator secret; we do not have separate access to it. We do not collect your name, physical address, or phone number to create an account.

Billing data. If you upgrade to Pro, Stripe collects and processes your payment details (card number, billing address) directly — we never see or store your full card number, CVV, or bank details. Stripe shares back a customer ID, subscription ID, subscription status, price/amount, and currency so we know which plan you're on. Stripe's privacy policy is at stripe.com/privacy.

Scan and accessibility data. When you scan a page (via the extension or a full-site crawl), the domains, page URLs, and violations found — axe-core rule IDs, WCAG success criteria, CSS selectors, HTML snippets, severity, and, for worker-captured crawls, a per-element screenshot — are saved to your dashboard if you are signed in. This is your data about websites you scan; you can delete it at any time.

AI Label Review data. If you run the optional "Review Labels" feature, the extension sends each reviewable element to our server using only five fields: CSS selector, HTML tag name, ARIA role, accessible name, and any associated <label> text. We run deterministic checks first, then forward only the subset that still needs human-style judgement to Google Gemini. Page URLs, page indexes, and full element HTML are never sent to Gemini. Flagged results, and any verdict or note you add, are saved to your dashboard.

Support and feedback data. The contact form on our website collects your name, email address, and message, and is emailed to our support inbox via Resend. In-app bug reports and feature requests collect your account email, a title, a description, an optional screenshot you choose to attach, and your extension version.

Technical and usage data. Our hosting provider, Netlify, logs standard web-server data including your IP address, browser user agent, and the pages you request. We also keep a short-lived record of the IP addresses used to attempt sign-in (for rate-limiting brute-force attacks) and to submit the contact form (for spam prevention); these records are purged automatically and are not linked to your profile beyond that purpose.

Analytics data. We use PostHog and Google Analytics (via Google's gtag.js) on the website to understand how the Service is used. On redflagstatus.com, these only load after you accept analytics cookies in our consent banner — see "Cookies and tracking technologies" below. The Chrome extension sends product-usage events to our server (which relays them to PostHog) whenever you are signed in. Extension events include the event name (for example "scan completed"), your account ID, your plan, the scan type, page and violation counts, and failure reasons — never page URLs, page content, or scan findings. The extension sends no analytics events when you are signed out. See our Cookie Policy for the specific cookies and identifiers involved. We do not use analytics data for advertising, and we do not sell it.

Sources of personal information

We collect personal information: (a) directly from you, when you create an account, contact us, or submit feedback; (b) automatically, through your use of the extension and website (scan results, usage events, IP address, cookies); and (c) from third parties who provide services on our behalf, principally Stripe (billing status) and Supabase (authentication events).

How scans work

The Chrome extension runs axe-core entirely inside your browser. No page content is transmitted to our servers during a scan. If you are signed in, violation results are automatically saved to your dashboard after each scan so you can track issues over time. You can delete your scan data at any time. If you are signed out, scanning still works locally but nothing is saved.

How we use personal information

We use personal information to: provide and maintain the Service (authenticate you, run and store scans, enforce plan limits); process payments and manage subscriptions; respond to support requests and feedback; detect, prevent, and investigate fraud, abuse, and security incidents (for example, repeated free-plan sign-ups used to bypass domain limits, or automated sign-in attempts); measure and improve product usage; and communicate essential service notices (password resets, security alerts, billing issues). We do not use your data to serve you third-party advertising, and we do not send marketing email.

Where GDPR/UK GDPR applies, our legal bases are: performance of a contract (account, scans, billing), legitimate interests (fraud/abuse prevention, product analytics, service communications), consent (non-essential cookies, where applicable — see our Cookie Policy), and legal obligation (tax and accounting records for payments).

Cookies and tracking technologies

The website and dashboard use a small number of cookies and similar technologies (such as localStorage) to keep you signed in, cache your plan, and measure product usage. The full list of cookies, their providers, purposes, and durations — and how to control them — is in our Cookie Policy.

Who we share data with

We do not sell or rent your personal information. We share it only with service providers ("sub-processors") who need it to run the Service, under contractual confidentiality and data-processing obligations:

  • Supabase — database, authentication, and file storage, with application data stored in the Sydney, Australia region.
  • Stripe — payment processing and subscription billing.
  • Netlify — web hosting and serverless functions.
  • Google Gemini (Google LLC) — AI processing for the optional Label Review feature, limited to the element fields listed above.
  • PostHog — product analytics, limited to the usage events described above, routed through our reverse proxy t.redflagstatus.com.
  • Google Analytics (Google LLC) — website traffic analytics via gtag.js.
  • Cloudflare — bot and abuse protection via Turnstile on our login/sign-up pages.
  • Resend — delivery of the contact form and in-app feedback emails to our support inbox.

We may also disclose personal information if required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of RedFlag, our users, or others — for example, in response to a valid legal request, or if RedFlag is involved in a merger, acquisition, or asset sale (in which case we will notify you before your data becomes subject to a different privacy policy).

International data transfers

Application data (accounts, domains, violations) is stored with Supabase in Sydney, Australia. Some of our sub-processors — including Stripe, Google (Gemini and Analytics), PostHog, Cloudflare, Netlify, and Resend — operate infrastructure outside Australia, including in the United States and the European Economic Area. Where personal information is transferred internationally, we rely on the sub-processor's own compliance mechanisms (such as Standard Contractual Clauses) and choose providers with appropriate data-protection commitments.

Bot protection

Our login and sign-up pages use Cloudflare Turnstile to protect against automated abuse. Turnstile runs a privacy-preserving challenge in your browser and does not display an image puzzle. Cloudflare may process your IP address and browser signals, and may set a short-lived challenge cookie, to verify the challenge. This data is governed by Cloudflare's privacy policy.

Browser and device storage

The Chrome extension uses chrome.storage.local to store your authentication session (tokens), your active domain/tab context, and in-progress crawl state. This data stays on your device and is cleared when you sign out or uninstall the extension. The extension itself does not use cookies.

The web dashboard sets a session cookie issued by Supabase Auth to keep you signed in, and a small signed cookie that caches your plan and onboarding status. Your light/dark theme preference is stored in your browser's localStorage, not a cookie. See our Cookie Policy for details.

Data retention

We keep your account data for as long as your account is active. If you delete your account, your domains, violations, scan history, notes, and screenshots are permanently deleted within 30 days.

Fraud-prevention exception. To prevent the Free plan's lifetime full-site-scan limit from being reset by re-signing up with the same email, we retain a minimal record — your email address and the domain(s) you ran a full-site scan against — after account deletion. We also retain a limited archive of past violations (rule ID, severity, status, domain/page URL, and timestamps, plus your email) for internal record-keeping and dispute resolution; this archive does not include CSS selectors, HTML snippets, or screenshots. You may ask us to review or delete this residual data by emailing us, subject to our legitimate interest in preventing abuse of the Service.

Payment records are retained by Stripe for the period required for tax and accounting compliance. Server logs are retained by Netlify per their standard retention practices. Login-attempt and contact-form rate-limit records are short-lived (on the order of hours) and used only to block abuse.

Scan history access by plan. Free plan users can view violation data from the last 3 days in their dashboard; older data is stored but not displayed until you upgrade. Pro plan users have access to their full, lifetime scan history with no time restriction. Data is never deleted based on plan — only what's displayed in the dashboard is limited.

Security

We apply row-level security in our database so that, by default, only you can read or write your own account data, domains, violations, and scan history. Traffic between your browser/extension and our servers is encrypted with HTTPS/TLS. Passwords are hashed by Supabase Auth and never stored or logged in plain text. Access to systems capable of bypassing these protections (service-role credentials) is restricted to server-side code and is never exposed to the browser or extension. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

Automated processing

The optional AI Label Review feature uses Google Gemini to suggest whether specific elements (for example, an icon button or a hidden dialog) likely have an accessibility problem. This is a decision-support suggestion, not a solely automated decision that produces legal or similarly significant effects on you — every flagged result is a suggestion you can accept, edit, or dismiss in your dashboard, and it never affects your account status, billing, or access to the Service.

Children's privacy

RedFlag is a business tool and is not directed at, marketed to, or knowingly used to collect personal information from children. You must be at least 18 years old, or the age of majority in your jurisdiction, to create an account. If you believe a child has provided us with personal information, contact us and we will delete it.

Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. There is no common industry standard for how to respond to DNT, and RedFlag does not currently respond differently to browsers with DNT enabled. You can still control analytics and cookies using the mechanisms described in our Cookie Policy.

Your privacy rights

Wherever you are located, you can ask us to access, correct, export, or delete your personal information, or ask us questions about how we process it, by emailing support@qern.com.au. You can also delete your account and most associated data directly from your dashboard settings (see "Data retention" above for the limited fraud-prevention records we keep after deletion).

If you are in the European Economic Area or United Kingdom (GDPR / UK GDPR)

You have the right to access, rectify, erase, or restrict processing of your personal data, to receive a portable copy of it, and to object to processing based on our legitimate interests. Where we rely on consent (for example, certain cookies), you can withdraw it at any time without affecting the lawfulness of processing before withdrawal. You have the right to lodge a complaint with your local data protection supervisory authority. We have not appointed a dedicated EU/UK representative; please contact us directly at the email above.

If you are a California resident (CCPA/CPRA)

California residents have the right to know what personal information we collect, use, and disclose; to request deletion or correction of that information; to opt out of the "sale" or "sharing" of personal information; and to not be discriminated against for exercising these rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes beyond providing the Service. To exercise your rights, email us at the address above; we will verify your request using your account email before acting on it.

If you are in Australia

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), to the extent it applies to us. You can request access to or correction of your personal information, or lodge a complaint about how we've handled it, by emailing us first; if you're not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Changes to this policy

If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or an in-app notice. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.

Contact

Questions about this policy or your personal information? Email us at support@qern.com.au.

HomeCookie PolicyTerms of Service

RedFlag legal

We use analytics cookies (Google Analytics, PostHog) to understand how RedFlag is used. Essential cookies are always on.Learn more in our Cookie Policy.