A
AccessiFlow Privacy Policy
Effective 24 September 2026 · Applies to the AccessiFlow browser extension
In one paragraph: AccessiFlow changes how a web page looks, sounds and behaves on your own device to make it accessible. Most of what it does — dark mode, the screen reader, keyboard navigation, live captions — never leaves your browser. The only thing that goes to a server is page text or an image, and only when you turn on an AI feature (button repair, form explanations, simplified text) — sent to power that one feature, never sold, and never used to identify you.
01What AccessiFlow is for
AccessiFlow is an accessibility extension. Its single purpose is to make the website you're currently viewing easier to see, hear, navigate and understand for people with disabilities, following WCAG 2.2. Every permission it requests and every byte of data it touches exists to serve that purpose — nothing else.
02What stays on your device
These features run entirely locally. Nothing about your browsing is sent anywhere to provide them:
- Smart Dark Mode, Reading Lens, Seizure-safe mode — computed from the page's own styles in memory.
- Built-in screen reader, keyboard-only mode, voice control — read and act on the page's structure locally; voice recognition and command parsing happen in your browser.
- Live captions — audio from the current tab is transcribed on-device using a local speech-recognition model. Audio is never uploaded.
- Hold-click menu and on-screen keyboard — what you type and choose is acted on in your browser, and the "What do you want to do?" box is matched on your device. Suggested words are drawn from the page you are on and what you type on it, kept only while that page is open, and never taken from a password box. A screenshot is taken only when you ask for one and goes to your clipboard; the clipboard is read only when you press Paste. Neither is ever uploaded.
- Your settings (contrast mode, font size, language, feature toggles) — saved in your browser's local extension storage, not on any server we operate.
03What is sent off your device — and only with your consent
A small set of AI-assisted features need a server-hosted language model. These are off by default; enabling them in AccessiFlow's settings is what gives consent, and each request is also subject to an hourly usage budget.
| Feature | What's sent | Why |
| Broken button / control repair | The control's surrounding text and role | To generate a spoken label so screen readers can announce it |
| Form briefs | The form's visible text and field structure | To generate a plain-language summary before you fill it in |
| Page simplifier / TL;DR | The page's visible text | To produce a simplified rewrite or summary |
| Image descriptions (alt text) | The specific image being described | To generate alt text for an unlabeled image |
| Explain hard words | The single word you double-click, and nothing else | Looked up in the free public dictionary at dictionaryapi.dev, only when that setting is on |
These requests go to AccessiFlow's own proxy server, which forwards them to a hosted language model provider to generate the result, then returns it to your browser. Successful results are cached briefly on our proxy so the same page content isn't re-processed twice, then expire.
We do not send your name, email, account credentials, financial information, health information, or your browsing history to any server. We do not use this data for advertising, analytics, or to build a profile of you.
04What we don't collect
| Personally identifiable information (name, email, address) | Not collected |
| Health, financial or payment information | Not collected |
| Passwords or authentication credentials | Not collected |
| Browsing / web history | Not collected |
| Location | Not collected |
| Keystrokes, clicks or mouse movement | Read locally to operate features; never transmitted or stored |
| Page text or images, when an AI feature is on | Sent to generate that feature's result |
05Third parties involved
When an AI feature is used, page content passes through:
- AccessiFlow's own proxy server (hosted on Cloudflare Workers) — routes the request and applies caching and rate limits.
- A third-party model hosting provider — runs the language model that generates the label, summary or description.
- dictionaryapi.dev — a free public dictionary, which receives the single word you double-click when Explain hard words is on.
Neither party uses this content to train models on our behalf or retains it beyond what's needed to serve the request.
06Your controls
- AI-assisted features are off until you turn them on in AccessiFlow's settings.
- You can turn any feature off at any time, which stops further requests immediately.
- Uninstalling the extension removes all locally stored settings and cached data from your browser.
07Children's privacy
AccessiFlow is not directed at children and does not knowingly collect data from anyone, regardless of age — its handling of page content is identical for every user.
08Changes to this policy
If AccessiFlow's data practices change, this page will be updated and the "Effective" date above will change accordingly.