Accessibility Compliance Checker for Docs, Slides, and Sheets Privacy Policy

Accessibility Compliance Checker for Docs, Slides, and Sheets - Google Docs™, Slides™, and Sheets™ Addon
Emoji icon 1f4d1.svg

Privacy Policy

This Privacy Policy describes how "Accessibility Compliance Checker for Docs, Slides & Sheets" ("the App"), provided by Fractal Apps LLC ("the Company"), collects, uses, and discloses information when you use the App and related services (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

1. Scope

This Privacy Policy applies to information processed through the Service, including within Google Docs™, Google Slides™, and Google Sheets™, and any related websites or support channels operated by the Company.

2. Google API Services User Data Policy (Limited Use)

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

The App accesses Google user data via Google APIs. The App's use of that data is limited to providing or improving user-facing features. We do not use Google user data for advertising, do not sell, rent, or trade it to any third party, and do not use it - whether raw, aggregated, anonymized, or derived - to create, train, or improve foundational or generalized artificial intelligence or machine learning models. Specifically, we do not use Google user data for any of the following purposes: targeted or personalized advertising, selling to data brokers or information resellers, determining credit-worthiness or for lending purposes, creating databases, or training AI models.

3. What leaves Google, and when

This section is the most important one in this policy. The App behaves differently depending on which feature you use, and we would rather state that plainly than bury it.

A. Running a check: nothing leaves Google

When you press "Run check", the entire scan runs inside Google Apps Script, on Google's infrastructure. Your document is read, analyzed, and the findings are produced without any part of its contents being transmitted to the Company or to any third party. The only request made to our server at that point records that a check occurred, and contains your email address, which editor you were in, and counts of how many findings were produced by rule. It does not contain any text, images, or other content from your document.

B. AI-written suggestions: only the fragment needed

Seven kinds of suggestion are written by a language model, and each sends only the specific fragment required to produce it:

  • Image descriptions - the image itself, its dimensions, and up to a short passage of surrounding text.
  • Link text rewrites - the existing link text, its destination URL, and the sentence containing it.
  • Document titles - an excerpt from the beginning of the document.
  • Distinguishing duplicate headings - the heading text and a portion of the section beneath each.
  • Slide titles - the text already present on that slide.
  • Sheet names - the column headers and first rows of that sheet.
  • Equations written out in words - the equation's characters and the surrounding paragraph.

Your full document is never sent for any of these. You choose when they run: no suggestion is requested until you apply a fix that requires one.

C. Exporting a tagged PDF: your document contents are sent to our server

If, and only if, you press "Export as PDF", the App builds a representation of your document - its text, structure, formatting, and any images it contains, encoded within that representation - and sends it to the Company's server, where the PDF is generated and checked against the PDF/UA standard. The finished PDF is returned to you and saved to your Google Drive.

This is necessary because Google's own PDF export does not produce a tagged, accessible file, and generating one requires processing the document outside Apps Script. The document representation is held in memory only for as long as the export takes, is not written to disk, and is not retained after the PDF has been returned. If you never use the export feature, your document contents are never sent to the Company.

4. Artificial intelligence and machine learning

The suggestions described in Section 3B are produced by a third-party AI service. We use exactly one such provider:

  • Google LLC - the Gemini API, accessed under a paid Google AI developer account. The App sends only the fragments described in Section 3B.

The models used are pre-trained and inference-only. We do not fine-tune them, create derivative models from them, or otherwise use your content or any data derived from it to create, train, or improve any foundational or generalized AI or ML model, and we do not authorize any third party to do so with data we transfer to them. Google's terms for paid use of the Gemini API provide that submitted prompts and generated responses are not used to train Google's models.

The App does not integrate with any other AI or ML service provider, and does not send Google user data to any AI or ML service other than the one named above.

5. Google user data we access

The App requests the following Google OAuth scopes and accesses the corresponding Google user data:

  • The open document (via documents.currentonly, presentations.currentonly, and spreadsheets.currentonly) - used to read the structure and contents of the file you are working in, and to apply the fixes you approve. These scopes grant access only to the file you currently have open. Google will not provide the App with any other document, presentation, or spreadsheet in your account, and the App has no ability to list, search, or open them.
  • Files this App creates (via drive.file) - used solely to save the PDF you ask the App to generate. This scope does not permit the App to read any file already in your Drive.
  • Email address (via openid and userinfo.email) - used to identify your account for managing your free usage allowance and subscription status.
  • Sidebar interface (via script.container.ui) - used to display the add-on sidebar within the Google editor where you interact with the App.
  • External network requests (via script.external_request) - used to communicate with the Company's server for usage tracking, subscription management, AI-written suggestions, and PDF export, as described in Section 3.

6. Other information we collect

A. Account and usage records

We store the following against your email address: your subscription status and price, your Stripe customer identifier, your free usage allowance and how much of it you have used, counts of checks run, fixes applied and findings produced, which editor you last used, the domain portion of your email address, and the accumulated cost of AI processing on your account. These records exist to operate your allowance and subscription, and to let us understand which checks are actually used.

B. Cached image descriptions

When the App writes a description for an image, we store that description alongside a SHA-256 hash of the image, so that describing the same image again does not require a second AI request. The stored record contains the hash, the description text, a confidence value, and the model used. The image itself is not stored, and a hash cannot be reversed to reconstruct it. These records are scoped to your individual account and are not shared with any other user.

C. Decorative image decisions

When you mark an image as decorative, that decision is recorded in your document's own Apps Script properties, keyed by a hash of the image. This record is stored by Google against the document, not by the Company, and is not transmitted to us.

D. Usage and diagnostic data

We may collect usage and diagnostic data such as feature usage counts, timestamps, and error logs to operate, maintain, and improve the Service. Error logs may include your email address, the name of the App feature that failed, and the associated error message, so that we can diagnose and resolve issues. Certain operational events - a new installation, a subscription starting or ending, a payment failure, or an authorization error - generate an internal notification to the Company containing your email address, sent through Discord.

E. Payment information

If you subscribe, payment is processed by Stripe. We do not store your credit card number or full payment details. Stripe may collect information as described in Stripe's Privacy Policy.

F. Cookies (website only)

If we operate a marketing or documentation website for the Service, that website may use cookies or similar technologies to operate and remember preferences. You can refuse cookies in your browser settings; however, some features may not work.

G. Accounts are individual

Your account record, allowance, and cached descriptions are associated with your individual email address. They are not shared with colleagues at the same organization or email domain, and using the App does not give any other person access to your records or to descriptions written for your images.

7. How we use information

We use the information we access or collect solely to:

  • Provide and operate the Service (checking documents, applying fixes, generating PDFs)
  • Produce the AI-written suggestions you request
  • Identify your account and manage your usage allowance and subscription
  • Process payments via Stripe
  • Provide support and respond to inquiries
  • Monitor performance, reliability, cost, and security
  • Fix bugs and decide which checks to build next
  • Comply with legal obligations

We do not sell, rent, or trade your Google user data to any third party. We do not use your data for advertising or any purpose unrelated to providing or improving the Service.

8. Data retention and deletion

We retain account and usage records only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.

Document content sent for PDF export is processed transiently: it is held in memory for the duration of the export, is not written to disk, and is not retained once the PDF has been returned to you. Fragments sent for AI-written suggestions are likewise not retained by the Company after the suggestion is returned; retention by Google of data submitted to the Gemini API is governed by Google's Gemini API terms.

Cached image descriptions (Section 6B) are retained until you request deletion, so that repeated work is not repeatedly billed.

To request deletion of your data, email support@fractalapps.dev. We will process deletion requests within 30 days. Deletion removes your account record, your usage history, and your cached image descriptions.

9. Disclosure of information

We do not sell, rent, or trade your information to third parties. We may disclose information only in the following circumstances:

  • To service providers who process data on our behalf and are contractually obligated to protect it (see Section 10)
  • Where necessary to comply with applicable law, regulation, legal process, or governmental request
  • To protect the rights, property, or safety of the Company, our users, or the public
  • To prevent fraud, abuse, or security issues

10. Third-party service providers

We use the following third-party service providers to operate the Service. These providers access information only to perform tasks on our behalf and are obligated not to use it for other purposes:

  • Google LLC - the Gemini API, used to produce the AI-written suggestions described in Section 3B, in accordance with Google's Gemini API terms.
  • Railway - cloud hosting for the Company's server, which stores your account record, usage counts, and cached image descriptions, and where PDF export is performed.
  • Stripe - payment processing for subscriptions, in accordance with Stripe's Privacy Policy.
  • Resend - email delivery, used to send service-related emails to your address.
  • Discord - internal operational notifications to the Company, which include your email address for the events described in Section 6D.
  • Cloudflare R2 - encrypted backups of the Company's database.

11. Security

We use reasonable administrative, technical, and organizational measures designed to protect your information, including encryption of data in transit (HTTPS/TLS) and signed identity tokens issued by Google for authenticating requests to our server. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. International data transfers

Your information may be processed in countries other than your own depending on where the Company and its service providers operate. Where required, we take steps designed to ensure appropriate safeguards are in place for cross-border transfers.

13. Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain processing of your personal data. To exercise any of these rights, contact us at support@fractalapps.dev. We will respond to your request within 30 days.

14. Educational institutions and children's privacy

The Service is designed for staff use - the people who author documents - and is not intended for use by children under the age of 13 (or a higher age threshold where required by local law). We do not knowingly collect personal information from children, and the App collects no information about the readers of a document, only about the account of the person operating the App.

Where an educational institution installs the App for its staff, the institution is responsible for determining whether that use is consistent with its own obligations, including under FERPA and any applicable state student privacy laws. If you believe a child has provided personal data, please contact us and we will take steps to delete it.

15. Links to other websites

The Service may contain links to third-party sites not operated by us. We are not responsible for the content or privacy practices of those sites. We recommend reviewing their policies before providing information.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page and update the "Last updated" date. Changes are effective when posted. Your continued use of the Service after changes become effective constitutes acceptance.

17. Contact

If you have questions about this Privacy Policy, contact us:

Google Docs™, Google Slides™, Google Sheets™, and Google Drive™ are trademarks of Google LLC. This App is not created by, endorsed by, or affiliated with Google LLC.

Last updated on August 10, 2026