Browser Extension

Extension Privacy Policy

Exactly what the Zylyn Accessibility Scanner extension collects, why it collects it, and what it never touches.

Last Updated: July 30, 2026Effective: July 30, 2026

This policy covers the browser extension. For the Zylyn platform as a whole, see our main Privacy Policy.

Section 01

Single Purpose

The Zylyn Accessibility Scanner extension has one purpose: to run an accessibility test on a web page you choose, and send the results of that test to your Zylyn account.

It exists because our servers cannot reach pages that sit behind a login. Running the test inside your own browser, in a tab you are already signed in to, lets you test dashboards, member areas, and checkout flows without ever sharing your password with us.

Nothing happens until you ask.The extension does not run in the background, does not watch your browsing, and does not send anything anywhere unless you click “Scan this page”.

Section 02

What We Collect

When — and only when — you run a scan, the following is collected and saved to your Zylyn account:

Page Address and Title

The URL and page title of the tab you choose to scan, plus the browser window's viewport size (results can differ by screen width).

Accessibility Scan Results

The findings produced by the accessibility engine, including short, truncated HTML snippets of the specific elements that failed a check.

Account and Request Data

Your Zylyn account and user id (so the report is saved to the right account), plus the IP address and browser user-agent of the upload request.

Stored In Your Browser

One setting only: which account you last chose in the extension's account picker. No scan data or credentials are stored locally.

Accessibility findings necessarily include a small amount of the page itself. For each element that fails a check, we store a fragment of its HTML — truncated to roughly 150 characters, and limited to a few examples per issue — so that you can identify and fix the element.

Section 03

What We Do Not Collect

The extension does not collect, transmit, or store any of the following:

  • Your browsing history, or any page you do not explicitly choose to scan
  • Cookies, passwords, authentication tokens, or session data from the sites you scan
  • Text you type into forms (page markup is captured as written, not as filled in)
  • Screenshots or images of the pages you scan
  • Keystrokes, mouse movement, or any behavioural tracking
  • Analytics or telemetry from within the extension itself

Your credentials never leave your browser. The extension reads the rendered page, not your session. It never asks for, captures, or transmits the passwords or login cookies of the sites you scan.

Section 04

Permissions and Why We Need Them

Every permission the extension requests, what it is used for, and what it deliberately does not allow:

PermissionWhy we request itWhat it does not allow
activeTabRead the page you are on, only when you click the Zylyn icon or use the right-click entry.Does not grant standing access to any site, and grants nothing until you invoke the extension.
scriptingRun the accessibility engine inside the page you asked to scan.Used only for that scan; the engine is bundled in the extension.
storageRemember which account you selected in the account picker.Holds no scan data, no personal data, and no credentials.
contextMenusAdd the right-click “Scan this page with Zylyn” entry.Grants no access to data of any kind; it only opens the extension.
Host access (zylyn.co)Upload scan results to your Zylyn account.The extension requests access to the Zylyn API only — not to the sites you scan.

The accessibility engine is bundled inside the extension at a pinned version. The extension does not download or execute remote code.

Section 05

Pages Behind a Login

Testing authenticated pages is the reason this extension exists, so we want to be precise about what that means for your data.

  • Snippets may contain content only you can see. If a failing element sits inside a private dashboard, the stored fragment of that element comes from that page.
  • We automatically mask obvious personal data in stored snippets — email addresses and long digit sequences such as account or card numbers are redacted before storage. This is an automated safeguard, not a guarantee: it cannot recognise every possible form of personal data.
  • Extension scans are never made public. Unlike public-page scans, they are never given a shareable public link, never used to generate a screenshot, and never sent to our customer-relationship system.
  • Only frames from the same site are included. Content embedded from other domains is counted but not scanned, and your report will tell you when coverage was partial.

Please scan responsibly. Only scan systems you are authorised to access, and prefer a dedicated test account where one is available. Scan reports are visible to other members of your Zylyn account — and, if your account is managed by an agency, to that agency.

Section 06

How We Use This Data

PurposeData usedLegal basis
Produce and store your accessibility reportPage URL, title, viewport, scan resultsContract performance
Attach the report to the right page and accountAccount id, user id, page recordContract performance
Charge the scan to your credit balanceAccount id, scan eventContract performance
Protect the service from abuse and misuseIP address, user-agent, request metadataLegitimate interest

We do not use extension data for advertising, profiling, or any purpose unrelated to producing your accessibility reports.

Section 07

Storage, Retention, and Deletion

Scan results are transmitted over an encrypted connection and stored in the Zylyn platform database, hosted by our infrastructure provider, which acts as a sub-processor on our behalf under a data processing agreement. No other third party receives extension scan data.

Reports are retained for the life of your account so that your accessibility history and trends remain available. You can request deletion of specific reports or of all your data at any time by contacting us, and we will action it manually. Closing your account removes your reports from the platform.

The single setting stored inside your browser is removed when you uninstall the extension.

Section 08

Chrome Web Store Limited Use Disclosure

Zylyn’s use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  • We use the data only to provide and improve the single, user-facing purpose described in Section 01.
  • We do not sell this data, and we do not transfer it to third parties except as necessary to operate the service (our infrastructure sub-processor), to comply with applicable law, or to protect against fraud, abuse, or technical issues.
  • We do not use or transfer this data for advertising, personalised advertising, or to determine creditworthiness or for lending purposes.
  • We do not allow humans to read this data, except with your explicit consent (for example when you ask us for support), where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Section 09

Security

  • All uploads travel over HTTPS.
  • Uploads are authenticated with your existing Zylyn session, and are accepted only from the official Zylyn extension.
  • Reports are scoped to your account; members of other accounts cannot access them.
  • Personal-data patterns in stored page snippets are automatically masked, as described in Section 05.

No system is perfectly secure. If you believe you have found a vulnerability in the extension or the platform, please contact us at the address below and we will respond promptly.

Section 10

Your Rights

You have the right to access, correct, export, or delete the data described in this policy, to object to or restrict its processing, and to withdraw consent where processing is based on consent. These rights, and how to exercise them, are described in full in our main Privacy Policy. You can also remove the extension at any time from your browser’s extensions page; removing it stops all collection immediately.

Section 11

Changes to This Policy

If we change what the extension collects or how that data is used, we will update this page, revise the “Last Updated” date, and — where the change is material — notify registered users by email. Any new permission that grants access to additional data will require your explicit approval in the browser before it takes effect.

Section 12

Contact Us

Questions about this policy, or a request regarding your data? Get in touch:

Zylyn — Privacy Contact

Making the digital world accessible to everyone.

Websitezylyn.co
UpdatedJuly 30, 2026