Legal

Terms of Service

Version
2.0
Effective
26 July 2026
Applies to
accessproof.dev, the AccessProof macOS app, and every audit we perform

This document is complete in substance but still carries placeholders in square brackets for the registered entity, address and governing law. It has not yet been reviewed by a qualified lawyer in the relevant jurisdiction, and it is not legal advice.

In short: You buy a credit, submit a build, and get back a readiness assessment with recorded evidence. Your build is confidential, is never used to train a model, and is deleted when the audit completes. A 48-hour delivery target is a target, not a guarantee — if we miss it we owe you a credit, not damages. Nothing we produce is a certification or legal advice, and our liability is capped at what you paid for the audit in question.

1. Who these terms are between

These Terms of Service (the Terms) are a contract between [LEGAL_ENTITY], [REGISTERED_ADDRESS], [COUNTRY] (we, us), trading as AccessProof, and the person or organisation that buys a credit or submits a build (you). They govern the AccessProof website at accessproof.dev, the AccessProof macOS application, and every audit we perform.

Your licence to run the macOS application itself is set out separately in the App licence, which Apple requires as a distinct document. Where the two disagree about the software, the App licence governs the software; these Terms govern the service.

2. Definitions

These words carry a specific meaning throughout the set of documents.

  • Build — the application binary you submit for audit (an .ipa or a TestFlight build), together with any demo credentials you supply with it.
  • Credit — a one-time purchase entitling you to one Audit. Held on our server against your Device Token.
  • Device Token — the random identifier the macOS app generates on first launch and stores in the macOS Keychain. It carries your credit balance. It is not an account, contains no personal information, and is not linked to your Apple ID.
  • Audit — one automated and human-reviewed examination of one Build, on one platform, against the Rule Catalog.
  • Run — a single execution of an agent task against your Build inside an isolated simulator.
  • Finding — a single issue we assert, with a severity, a rule reference and its supporting Evidence.
  • Evidence — the screenshot, cropped element, measured value or failure frame that proves a Finding.
  • Rule Catalog — the versioned set of rules an Audit is run against. The version used is recorded in your Report.
  • Report — the document we deliver, containing the Findings and the Evidence embedded inside it.
  • Readiness Assessment — what a Report is: a technical statement about the Build we tested, at the time we tested it, against the Rule Catalog version named in it. See section 4.

3. What the service does

We install your Build on an isolated simulator, drive it through a set of real user tasks, measure what a user with an access need would encounter, and hand back a Report in which every Finding is supported by Evidence. The method has three layers: deterministic measurement (contrast ratios, target sizes, Dynamic Type behaviour), recorded agent runs, and human review of critical Findings.

Runtime Findings pass a reproducibility filter before they are reported: each is attempted three times, the median measurement is the one published, and a Finding that does not reproduce in at least two of three attempts is dropped rather than reported. This is deliberate. A Report that lists a Finding you cannot reproduce costs you an afternoon and costs us your trust.

Findings are mapped to WCAG 2.2 AA success criteria and to EN 301 549 clauses where a mapping exists. That mapping is our editorial judgement about which criterion a Finding relates to. It is not an assertion by any standards body, conformity assessment body or regulator.

4. What the service is not

A Report is a technical readiness assessment. It is not, and must not be represented by you as:

  • a certification, accreditation or conformity assessment of any kind;
  • a guarantee, warranty or assurance that your application complies with the European Accessibility Act, EN 301 549, the Americans with Disabilities Act, Section 508, WCAG, or any other law or standard;
  • legal advice, or a substitute for advice from a qualified lawyer in your jurisdiction;
  • an accessibility statement, a conformance claim, or a VPAT prepared on your behalf;
  • a substitute for testing with disabled users, or for review by an accessibility specialist familiar with your product.

We are not a conformity assessment body and we do not hold ourselves out as one. Every Report and every page of this site carries the line Technical readiness assessment — not legal advice.

An Audit examines what the Rule Catalog covers. It does not cover every WCAG success criterion — many criteria require human judgement about content and context that no automated run can supply — and a Report that lists no Findings in an area is not a statement that no issue exists there. The Report names the Rule Catalog version so that you, or anyone reviewing your work, can see exactly what was and was not examined.

5. Who may use the service

The service is intended for businesses, developers and agencies acting in a professional capacity. You must be able to form a binding contract, and if you accept these Terms on behalf of an organisation you confirm you are authorised to bind it.

Where you are a consumer under the mandatory law of your country of residence, nothing in these Terms removes rights that law gives you. Where a clause here conflicts with such a right, the right prevails and the rest of the Terms continue to apply.

6. There are no accounts

AccessProof deliberately has no sign-up, no password and no user profile. Your Credit balance is held on our server against your Device Token, which the app generates locally and keeps in your Keychain. The consequences are worth stating plainly, because they cut both ways:

  • We cannot build a profile of you, because there is nothing to build it on.
  • We cannot look up "your account" if you email us. To reach your Credits we need the App Store transaction identifier from your Apple receipt.
  • If you delete the app, erase the Keychain item or move to a different Mac, the Device Token is gone and the balance it carried is not automatically transferred. Contact info@accessproof.dev with your Apple receipt before you do any of these, and we will move the balance.

7. Credits

A Credit is bought through the Mac App Store at $149.99 (Apple is the merchant of record and sets the local price and tax for your storefront). One Credit buys one Audit: one application, one platform. Re-auditing the same application after you have made fixes is a separate Audit and a separate Credit.

Your balance is authoritative on our server, not in the app. The app displays a number; the server decides it. This is what makes the balance survive an app reinstall, and it is also why the app cannot spend a Credit on its own.

  • A Credit is consumed at the moment a Report is delivered to you — not when you upload, not when the Run starts.
  • If a Build cannot be installed, opened or driven, the Credit is not consumed. We issue a free retry, open for 72 hours.
  • If we cause a material delay against the delivery target in section 8, we add a bonus Credit. You do not have to ask.
  • Credits do not expire, cannot be transferred or resold, and have no cash value.

Credits are not a refund instrument. Refunds are Apple's decision and are covered in the Refunds & purchases policy, which forms part of these Terms.

8. Delivery target, and what it obliges us to do

We publish a delivery target of 48 hours. Being precise about what that means is the difference between a promise and marketing:

  • The clock starts when we accept a Build for audit — not when you begin the upload — and stops when the Report is delivered.
  • Time spent waiting on you (working demo credentials, a build that installs, an answer to a question that blocks the Run) does not count against it.
  • It is a target, not a guarantee, and it is not a deadline of the kind that makes time of the essence.

Your remedy if we miss it. If we exceed the target for reasons within our control, we add a bonus Credit to your balance. If we exceed it by more than seven days for reasons within our control and you no longer want the Audit, you may withdraw the Build before delivery, and the Credit is returned to your balance unconsumed. Those are the remedies; the delivery target does not give rise to a claim for damages, service credits beyond the above, or loss of profits.

9. What you must provide, and what you promise

By submitting a Build you represent and warrant that:

  • you own the application or are authorised by its owner to have it tested;
  • you have the right to give us any demo credentials you supply, and those credentials belong to a disposable test account containing no real customer data;
  • the Build contains no personal data of third parties, no live production data, no payment instruments and no unlawful content;
  • you will not supply credentials to a production environment or to any system where an automated Run could cause loss to you or anyone else.

Our agent drives your application the way a user would. It taps things. If you give us a live environment, it will act in that live environment. Use a test build with test data.

10. Your build is confidential

Your Build, its contents, and everything we observe while running it are your confidential information. We process them for the sole purpose of producing your Report. We do not share, disclose, publish, redistribute, sell or licence your Build or its contents to any third party, and we do not use your Build or its contents to train, fine-tune or evaluate any machine learning model. The agent that drives your application runs on a commercial API under terms that prohibit training on submitted content — never on a consumer subscription.

The Build is deleted when the Audit completes (audit_completed), and the exact UTC deletion time is stamped into your Report. A failed Run holds the Build for the 72-hour retry window and it is then deleted the same way. Demo credentials live only for the length of the Run, are encrypted at rest with a per-audit key, and are never written to logs or telemetry. Screen recordings are destroyed with the Build; the screenshots and the single frame from the moment a task failed are embedded in the Report, which is the only copy in existence — we keep none, which also means we cannot re-issue your Evidence if you lose the Report.

The operational detail behind each of these statements is on the Security page; who processes what, and where, is in Sub-processors.

11. Intellectual property

Yours stays yours. Your Build, your application, your brand and everything in them remain your property. Nothing here transfers any right in them to us beyond the limited licence in section 12.

Ours stays ours. The Rule Catalog, the audit method, the report format and templates, the AccessProof name, mark and site content are our property. Buying an Audit does not licence any of them.

Your Report. On delivery you receive a perpetual, worldwide, irrevocable, royalty-free licence to use, copy and distribute your Report for any purpose connected with your business — including giving it to your client, your auditor, your insurer, a regulator or a court. You may not resell the Report as a standalone product, present it as your own work product, or remove the readiness-assessment disclaimer from it.

12. The licence you give us, and how to switch it off

You grant us a limited, non-exclusive licence to store, install, execute, record and analyse your Build strictly to perform your Audit, for as long as the retention rules in section 10 allow, and for no other purpose.

Benchmarks. We use Findings in aggregate, anonymous and de-identified form to produce category benchmarks and research — for example, "the median tap target in banking apps we audited was 38pt". No individual customer, application, Build or Finding is ever published in identifiable form, and the de-identified data cannot be reversed to identify your application.

If you would rather your Findings were excluded from benchmarking altogether, email info@accessproof.dev with your transaction identifier before or after the Audit. There is no charge and no consequence for opting out.

13. Acceptable use

You may not:

  • submit an application you do not own and are not authorised to have tested;
  • use the service to test, probe or attack a system you do not control;
  • attempt to identify another customer, their application or their Findings;
  • represent a Report as a certification, a compliance guarantee or legal advice, or alter a Report so that it reads as one;
  • reverse engineer, scrape or systematically extract the Rule Catalog in order to reproduce it;
  • resell Audits as your own service without a written agreement with us;
  • interfere with the service, circumvent the Credit system, or access it by any means other than the app.

We may suspend or refuse an Audit that we reasonably believe breaches this section. Where we do, an unconsumed Credit stays in your balance.

14. Accuracy, and the limits of it

We hold ourselves to a strict no-false-positive rule and enforce it through the reproducibility filter in section 3. We still cannot promise that every Finding is correct, that every issue in your application was found, or that a Finding will reproduce on hardware, an OS version or a device configuration different from the one recorded in your Report.

Simulator behaviour is not identical to device behaviour. Assistive technology behaviour — VoiceOver in particular — can differ between a simulator and a physical device. An Audit reflects the Build we tested, at the time we tested it, against the Rule Catalog version named in the Report, and nothing beyond that.

If you believe a Finding is wrong, tell us. Reply to the report email or write to info@accessproof.dev with the Finding identifier. If we agree it is wrong we will correct the Report and, where the error is material, add a Credit.

15. Third parties

Purchases are processed by Apple, under Apple's terms, and Apple is the merchant of record. Parts of the service run on infrastructure operated by the providers listed in Sub-processors. We remain responsible to you for the service; we are not responsible for the availability of Apple's services or of a third-party site we link to.

16. Disclaimer of warranties

Except as expressly stated in these Terms, and to the maximum extent permitted by law, the service and every Report are provided "as is" and "as available", without warranty of any kind, whether express, implied or statutory, including any implied warranty of merchantability, fitness for a particular purpose, non-infringement, or that the service will be uninterrupted or error-free.

Nothing in this section limits a warranty that cannot lawfully be excluded, including consumer guarantees under the mandatory law of your country of residence.

17. Limitation of liability

To the maximum extent permitted by law, and except for the matters in the paragraph immediately below:

  • our total aggregate liability arising out of or in connection with an Audit is limited to the amount you paid for that Audit;
  • our total aggregate liability arising out of or in connection with the service as a whole, in any twelve-month period, is limited to the amounts you paid us in that period;
  • we are not liable for indirect, incidental, special, punitive or consequential loss; loss of profit, revenue, business, goodwill or anticipated savings; loss or corruption of data; or for any fine, penalty, damages award or legal cost imposed on you by a regulator, court or counterparty, whether or not connected to the accessibility of your application.

What we never exclude. Nothing in these Terms limits or excludes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, for wilful misconduct, or for any other liability that cannot lawfully be limited or excluded.

Read together with section 4, this is the allocation of risk you are agreeing to: an Audit is evidence you can act on, and the decision about whether your application meets a legal obligation — and the consequences of that decision — remain yours and your advisers'.

18. Indemnity

You will indemnify us against claims, losses and reasonable legal costs arising from a Build you submitted that you were not authorised to have tested, from third-party personal data or unlawful content contained in a Build, or from your use of a Report in breach of section 13.

19. Suspension and termination

You may stop using the service at any time; deleting the app is enough. We may suspend or terminate access where you breach these Terms, where required by law, or where continuing would expose us or another customer to material risk. Sections 10, 11, 14, 16, 17, 18 and 21 survive termination. Unconsumed Credits survive termination by us for convenience and do not survive termination for your material breach.

20. Events outside our control

We are not liable for a failure or delay caused by an event beyond our reasonable control, including a failure of Apple's services, of a sub-processor, of network infrastructure, or an OS or tooling change that prevents Runs from completing. Where such an event prevents delivery, your Credit stays unconsumed.

21. Changes to these Terms

We may update these Terms. The version number and effective date at the top of this page change with them, and the previous version is available on request from info@accessproof.dev. A material change is announced in the app before it takes effect. The Terms that govern an Audit are the ones in force when the Credit for it was spent — a later change does not apply retroactively to work already commissioned.

22. Governing law and disputes

These Terms are governed by the law of [GOVERNING_LAW], and the courts of [COMPETENT_COURTS] have jurisdiction. If you are a consumer, this does not deprive you of the protection of the mandatory law of your country of residence, and you may bring proceedings there.

Before starting proceedings, please write to info@accessproof.dev and give us thirty days to resolve the matter. Most disputes about a Report are disputes about a Finding, and section 14 fixes those faster than a court will.

23. General

  • Entire agreement. These Terms, together with the App licence, the Privacy Policy, the Refunds & purchases policy and the Sub-processors list, are the whole agreement between us about the service.
  • Severability. If a provision is unenforceable, the rest continues in force.
  • No waiver. Not enforcing a provision once does not waive it.
  • Assignment. You may not assign these Terms without our consent. We may assign them to a successor of our business, on notice.
  • Notices. Legal notices to us go to info@accessproof.dev and to the registered address above. Notices to you go to the address you used to contact us, or through the app.
  • Language. These Terms are drafted in English. A translation is provided for convenience only; the English version governs.

Contact

[LEGAL_ENTITY], [REGISTERED_ADDRESS], [COUNTRY]. Registration [COMPANY_REGISTRATION_NUMBER] · Tax ID [TAX_ID].

One address handles everything — legal notices, privacy and data subject requests, support, security disclosure and accessibility feedback: info@accessproof.dev. Put the subject in the first line and it reaches the right person.