Legal
Legal documents
Seven documents. Written to be read by the person who has to sign off on buying this, not to be endured. Version 2.0, effective 26 July 2026.
These documents are complete in substance but still carry placeholders in square brackets for the registered entity, address and governing law, and have not yet been reviewed by a qualified lawyer in the relevant jurisdiction. They are not legal advice.
Where to start
If you are evaluating AccessProof for a client's app, the two that matter are the Privacy Policy — because it says what happens to a build containing real user data — and Sub-processors, because it names everyone who could technically see it. If you are about to spend a credit, read Terms section 4, which sets out what a report is not.
-
Terms of Service
The contract for the audit itself: what a credit buys, when the delivery clock starts, what a report is and is not, and how liability is allocated.
Anyone buying a credit
-
Privacy Policy
Every category of data we touch, the legal basis for it, and the exact moment it is deleted. Includes the Article 28 processor terms that apply when your build contains your users’ data.
Procurement, DPOs, anyone uploading real data
-
End User Licence Agreement
The licence for the Mac app itself, including the Apple-required Licensed Application terms and the rule that your credit balance lives on our server, not on your device.
Anyone installing the app
-
Refunds & Purchase Policy
When a credit is consumed, when a retry is free, what happens if we are late, and the uncomfortable fact that Apple — not we — decides refunds.
Anyone who has paid us
-
Sub-processors
Every party that can technically see customer data, what each one sees, and the boundary that matters most: your build binary never leaves our audit machine.
Security review
-
Cookies & Tracking
There are none, there is no analytics, and there is no consent banner. The page tells you how to verify all three in your own browser in fifteen seconds.
Anyone who does not believe us
-
Accessibility Statement
Our own conformance target, method, date — and a named list of what is still not right, because an accessibility company hiding its own gaps has lost the argument.
Everyone, and us
The rules we wrote these under
Every number in these documents — the 48-hour target, the 72-hour retry window, the deletion trigger, the price — is read from the same configuration files the software reads. Nobody typed them into a legal page by hand, so a claim here cannot drift away from the behaviour in the product without someone changing the product first.
Where a marketing sentence on this site and a clause in these documents say different things, the clause governs — and the difference is a drafting bug we would like to hear about, at info@accessproof.dev.
Related, but not legal documents: the security page covers the technical detail behind the retention promises, and methodology explains how a finding is produced and verified.