Extension Privacy Policy
Exactly what the Zylyn Accessibility Scanner extension collects, why it collects it, and what it never touches.
This policy covers the browser extension. For the Zylyn platform as a whole, see our main Privacy Policy.
Single Purpose
The Zylyn Accessibility Scanner extension has one purpose: to run an accessibility test on a web page you choose, and send the results of that test to your Zylyn account.
It exists because our servers cannot reach pages that sit behind a login. Running the test inside your own browser, in a tab you are already signed in to, lets you test dashboards, member areas, and checkout flows without ever sharing your password with us.
Nothing happens until you ask.The extension does not run in the background, does not watch your browsing, and does not send anything anywhere unless you click “Scan this page”.
What We Collect
When — and only when — you run a scan, the following is collected and saved to your Zylyn account:
Page Address and Title
The URL and page title of the tab you choose to scan, plus the browser window's viewport size (results can differ by screen width).
Accessibility Scan Results
The findings produced by the accessibility engine, including short, truncated HTML snippets of the specific elements that failed a check.
Account and Request Data
Your Zylyn account and user id (so the report is saved to the right account), plus the IP address and browser user-agent of the upload request.
Stored In Your Browser
One setting only: which account you last chose in the extension's account picker. No scan data or credentials are stored locally.
Accessibility findings necessarily include a small amount of the page itself. For each element that fails a check, we store a fragment of its HTML — truncated to roughly 150 characters, and limited to a few examples per issue — so that you can identify and fix the element.
What We Do Not Collect
The extension does not collect, transmit, or store any of the following:
- Your browsing history, or any page you do not explicitly choose to scan
- Cookies, passwords, authentication tokens, or session data from the sites you scan
- Text you type into forms (page markup is captured as written, not as filled in)
- Screenshots or images of the pages you scan
- Keystrokes, mouse movement, or any behavioural tracking
- Analytics or telemetry from within the extension itself
Your credentials never leave your browser. The extension reads the rendered page, not your session. It never asks for, captures, or transmits the passwords or login cookies of the sites you scan.
Permissions and Why We Need Them
Every permission the extension requests, what it is used for, and what it deliberately does not allow:
| Permission | Why we request it | What it does not allow |
|---|---|---|
| activeTab | Read the page you are on, only when you click the Zylyn icon or use the right-click entry. | Does not grant standing access to any site, and grants nothing until you invoke the extension. |
| scripting | Run the accessibility engine inside the page you asked to scan. | Used only for that scan; the engine is bundled in the extension. |
| storage | Remember which account you selected in the account picker. | Holds no scan data, no personal data, and no credentials. |
| contextMenus | Add the right-click “Scan this page with Zylyn” entry. | Grants no access to data of any kind; it only opens the extension. |
| Host access (zylyn.co) | Upload scan results to your Zylyn account. | The extension requests access to the Zylyn API only — not to the sites you scan. |
The accessibility engine is bundled inside the extension at a pinned version. The extension does not download or execute remote code.
Pages Behind a Login
Testing authenticated pages is the reason this extension exists, so we want to be precise about what that means for your data.
- Snippets may contain content only you can see. If a failing element sits inside a private dashboard, the stored fragment of that element comes from that page.
- We automatically mask obvious personal data in stored snippets — email addresses and long digit sequences such as account or card numbers are redacted before storage. This is an automated safeguard, not a guarantee: it cannot recognise every possible form of personal data.
- Extension scans are never made public. Unlike public-page scans, they are never given a shareable public link, never used to generate a screenshot, and never sent to our customer-relationship system.
- Only frames from the same site are included. Content embedded from other domains is counted but not scanned, and your report will tell you when coverage was partial.
Please scan responsibly. Only scan systems you are authorised to access, and prefer a dedicated test account where one is available. Scan reports are visible to other members of your Zylyn account — and, if your account is managed by an agency, to that agency.
How We Use This Data
| Purpose | Data used | Legal basis |
|---|---|---|
| Produce and store your accessibility report | Page URL, title, viewport, scan results | Contract performance |
| Attach the report to the right page and account | Account id, user id, page record | Contract performance |
| Charge the scan to your credit balance | Account id, scan event | Contract performance |
| Protect the service from abuse and misuse | IP address, user-agent, request metadata | Legitimate interest |
We do not use extension data for advertising, profiling, or any purpose unrelated to producing your accessibility reports.
Storage, Retention, and Deletion
Scan results are transmitted over an encrypted connection and stored in the Zylyn platform database, hosted by our infrastructure provider, which acts as a sub-processor on our behalf under a data processing agreement. No other third party receives extension scan data.
Reports are retained for the life of your account so that your accessibility history and trends remain available. You can request deletion of specific reports or of all your data at any time by contacting us, and we will action it manually. Closing your account removes your reports from the platform.
The single setting stored inside your browser is removed when you uninstall the extension.
Chrome Web Store Limited Use Disclosure
Zylyn’s use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- We use the data only to provide and improve the single, user-facing purpose described in Section 01.
- We do not sell this data, and we do not transfer it to third parties except as necessary to operate the service (our infrastructure sub-processor), to comply with applicable law, or to protect against fraud, abuse, or technical issues.
- We do not use or transfer this data for advertising, personalised advertising, or to determine creditworthiness or for lending purposes.
- We do not allow humans to read this data, except with your explicit consent (for example when you ask us for support), where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Security
- All uploads travel over HTTPS.
- Uploads are authenticated with your existing Zylyn session, and are accepted only from the official Zylyn extension.
- Reports are scoped to your account; members of other accounts cannot access them.
- Personal-data patterns in stored page snippets are automatically masked, as described in Section 05.
No system is perfectly secure. If you believe you have found a vulnerability in the extension or the platform, please contact us at the address below and we will respond promptly.
Your Rights
You have the right to access, correct, export, or delete the data described in this policy, to object to or restrict its processing, and to withdraw consent where processing is based on consent. These rights, and how to exercise them, are described in full in our main Privacy Policy. You can also remove the extension at any time from your browser’s extensions page; removing it stops all collection immediately.
Changes to This Policy
If we change what the extension collects or how that data is used, we will update this page, revise the “Last Updated” date, and — where the change is material — notify registered users by email. Any new permission that grants access to additional data will require your explicit approval in the browser before it takes effect.
Contact Us
Questions about this policy, or a request regarding your data? Get in touch:
Zylyn — Privacy Contact
Making the digital world accessible to everyone.

