Privacy policy

Last updated 11 August 2026. Written in plain English on purpose — if a lawyer needs to read this too, the plain version is what it means.

GotAlt is built by one person, not a company with a legal or privacy team. This policy explains what actually happens to your data when you use the site — no boilerplate you'd need a lawyer to translate.

What we collect

What we collect depends on whether you're running a one-off free tool or signed in to a monitored account.

Using the free tools

  • The URL you submit. We need it to fetch the page and images you're asking us to check.
  • Your email address, for the AI-powered tools only. The deep AI audit, the alt text checker, and the alt text generator all ask for one first — this is lead capture, not a login, and it doesn't create an account.
  • Your IP address, temporarily. We use it to enforce the daily free-tier limits (5 rule-based scans, 1 deep audit, 1 alt text check, 3 alt text generations per day) so the free tier stays free for everyone. It is not logged permanently — see "How long we keep things" below.

Signing in and paid monitoring

Signing in creates an account, and an account is more data than a one-off scan:

  • Your email address, to identify the account and send you a sign-in link.
  • Sign-in and session records. Each time you request a sign-in link we record the request (including your IP address, so we can rate-limit abuse of the mail system); each successful sign-in creates a session record with your IP address and browser user agent, so a session can be revoked if it looks wrong.
  • The sites and pages you ask us to monitor — their URLs — and the weekly check results: rule findings, vision-audit verdicts on flagged images, and a running issue history so you can see what's new versus what was already open.
  • Billing information, held by Stripe, not by us. We store your Stripe customer and subscription IDs so we know what you're entitled to. Card details are never sent to or stored on our servers — Stripe handles that directly.

There is no password to set — sign-in is a one-time emailed link — and we don't build an advertising profile of you. But an account is a real, persistent record, not nothing: it's what lets weekly monitoring, alerts, and issue history work at all.

What we don't do

No tracking, no selling, no cookie banner

  • No analytics cookies. We don't run Google Analytics or anything like it.
  • No advertising trackers, pixels, or retargeting scripts.
  • We never sell or rent your data to anyone, for any reason.
  • No cookie consent banner, because we don't set tracking cookies. A banner asking permission for tracking we don't do would just be another thing standing between you and the tool.

Who processes your data, and why

We use a small number of infrastructure providers to run the site. We don't build our own servers or our own AI models, so parts of what you submit pass through these processors:

  • Cloudflare — hosting, the Workers platform that runs our scanning and monitoring logic, D1 (our database, for accounts and monitoring data), and KV storage for rate-limit counters. Cloudflare is how the site is served and how a page you submit gets fetched. Read Cloudflare's privacy policy.
  • Anthropic — the vision and language models behind the deep audit and the alt text checker. When you ask us to verify an image or generate alt text, the image and relevant page content are sent to Anthropic's models to produce the result. Read Anthropic's privacy policy.
  • Stripe — payment processing and billing for Professional and Agency accounts. If you subscribe, your payment details go directly to Stripe; we never see or store your card number. Read Stripe's privacy policy.
  • Resend — sends the transactional email the site relies on: sign-in links and, if you turn them on, regression alerts. Your email address and the content of that one email pass through Resend to deliver it. Read Resend's privacy policy.

We don't use any other third-party processor. No customer-support chat widget, no email marketing platform, no analytics vendor.

How long we keep things

  • Free-tool results are not stored on our servers. A one-off scan, deep audit, alt text check, or generation is run on request and sent back to your browser; we don't write the result to our database. If you close the tab, it's gone unless you saved it yourself. (This is different from monitoring, below — a monitored page's results are kept, because tracking change over time is the point of paying for it.)
  • Rate-limit counters (the IP-based ones used to enforce free-tier daily limits, and the email-unlock tokens for the AI tools) expire automatically after 25 hours.
  • Monitoring data — the sites and pages you've added, and their check history — is kept for as long as your account exists, so your issue history stays meaningful. Deleting your account deletes it.
  • Sign-in links expire after 15 minutes and work once; the record of having sent one is kept for up to 30 days, only to rate-limit abuse of the sign-in system, then removed. Sessions are kept until they expire, are revoked (for example by signing out), or the account is deleted.
  • Emails you send us are kept until you ask us to delete them.

Your rights

Whether or not you're covered by the GDPR, the CCPA, or another privacy law, you can ask us to:

  • Access — see what personal data we hold about you. If you've only used the free tools, that's likely an email address and nothing else. If you have an account, it also includes the sites and pages you monitor and their check history.
  • Delete — have that data removed, including closing your account if you have one.
  • Export (data portability) — get a copy of it in a usable format.
  • Object — tell us to stop processing it for a particular purpose.

To exercise any of these, email hello@gotalt.com with the email address on the account or lead you're asking about.

International transfers

Cloudflare, Anthropic, Stripe, and Resend all operate infrastructure in multiple countries, which means data you submit may be processed outside your own country, including in the United States. Each publishes its own safeguards for international transfers in the privacy policies linked above.

Children

GotAlt is a tool for people who build or manage websites. It isn't directed at children, and we don't knowingly collect data from anyone under 13 (or the relevant minimum age in your jurisdiction).

Changes to this policy

If this policy changes, we'll update the date at the top of this page. We won't quietly narrow your rights or start doing something this page says we don't do without updating it first.

This isn't legal advice, and this page shouldn't be read as a substitute for advice from a qualified lawyer about your own obligations.

Questions about your data?

Email us directly and a person will answer — there's no support queue or ticketing system standing in the way.

hello@gotalt.com