Legal

Privacy Policy

The short version: Mend stores what you ask it to store, and this page says exactly what that is.

Effective date: 6 August 2026

Mend is an accessibility auditor with two halves. A Chrome extension audits the page you are looking at. A hosted dashboard stores audits, re-runs them on a schedule, and turns them into reports. The two are separate, and they handle your data differently — so this policy treats them separately.

The extension

When you run an audit, and only then, the extension reads the content and structure of the page in the active tab so it can analyze that page. It accesses a page only when you invoke it and has no standing access to any website. The analysis runs inside your browser.

Your preferences are stored locally, and the most recent audit for each tab is cached for the browsing session. That data stays on your device and goes when you clear the extension's data or uninstall it. The extension contains no analytics and no telemetry.

The extension sends nothing until you connect it. Connecting means two deliberate steps: creating an account and pasting an account key into the extension's settings. Until you do both, and then choose to save a specific run, no audit leaves your device.

What the dashboard stores

An account holds your name and email address, and the audits associated with it. For each saved audit we store the page's URL and title, when it ran, and for every issue found: the rule, its impact, a CSS selector for the failing element and a short HTML snippet of it.

Those snippets can contain real page content — whatever text or attributes happened to be on the element that failed. If you audit a page showing customer data, that data can end up in the snippet. It is worth knowing before you point Mend at an internal system.

How long audits are kept depends on your plan, and the limits are listed on the pricing page. You can download everything stored for your account as JSON, delete all synced audits, or delete the account entirely, at any time, from your account page. Deletion is immediate and permanent.

Scheduled monitoring

A monitor re-audits a page on a schedule. This does not happen on your device: Mend opens the page in a browser on its own servers, at a time we choose, and stores the result as an ordinary audit. Requests to your site come from our infrastructure, not from you, and will appear in your logs as such. A monitor keeps running until you pause or delete it on the Monitors page — including after you delete that page's stored audits, which removes the history but not the schedule.

Sign-in flows and stored credentials

A monitor can sign in before it audits, by replaying a short list of steps you define. If those steps involve a password or a token, you store it in a per-account vault, and this is the most sensitive thing Mend holds. How it is handled:

  • Stored values are encrypted with AES-256-GCM under a key held in the server environment, never in the database beside them.
  • The vault is write-only. Mend can use a stored credential when it signs in; it cannot display one back to you, and neither can we. There is no screen, export or API that returns one. Credentials are excluded from the JSON export for the same reason.
  • A credential is used for exactly one thing: typing it into the page your flow points at, in a browser on our servers, at scan time.
  • Before a scan is stored, its output is checked for the values that were typed into the page. If any survived into the audit, the run is discarded rather than saved.
  • If a flow ends up back on a sign-in page — an expired session, a changed form — the run is discarded too, rather than recording an audit of your login screen.

A monitor has exactly the access of the account whose credentials you gave it, so give it an account that can see what you want audited and no more. You can delete a stored credential at any time, and deleting it stops the flows that used it. The full description is in monitoring a page behind a login.

Recording a sign-in

Rather than writing the steps by hand, you can record them: Mend opens the page in a browser on its servers and streams it to you as video while you drive it. That session is temporary. It exists only while the recorder is open, is capped in length, and ends when you finish, close it or leave it idle. Nothing that happens inside it is stored except the steps you keep, and any value you type into a password field becomes a vault entry rather than a step containing the text.

Third parties

Mend does not sell your data, and sends nothing to an advertising network on any plan. The dashboard relies on a small number of processors, and only in the ways described here.

Payments

If you subscribe to Pro, payment is processed by Stripe. Checkout is hosted by Stripe, so your card number never reaches Mend's servers — we never see or store it. What we keep is your Stripe customer and subscription IDs, the plan you're on, its status, and when the current period ends, so the dashboard knows what your account is entitled to.

What Stripe receives: your email address, any name and payment details you enter into their checkout, and subscription metadata identifying which Mend account the payment belongs to. Stripe handles that data under its own privacy policy as our payment processor.

Sign-in and email

If you choose to sign in with Google or GitHub, that provider tells us your email address and name to create the account — you can use an email and password instead. Transactional email — address verification, password resets, and alerts about a monitored page that stopped working — is delivered through Resend. There is no marketing email.

You can point a monitor’s alerts at an address other than your own — a team alias, say. We store that address, and email it once to ask permission. Nothing else is ever sent there unless someone holding it confirms, and removing it from your Monitors page deletes it.

Messages you send us

The contact form on the support page emails your message, the name and address you put in it, and — if you were signed in — which account you sent it from, to our support inbox. It is not stored in the Mend database. It lives in that mailbox as any email would, and we keep it as long as it is useful for support.

Hosting

The dashboard, its database and the browsers that run scheduled scans all run on Railway, which hosts the data described above on our behalf.

Website analytics

This website does not run any analytics. No analytics cookie is set, nothing counts your visits, and no third-party analytics service receives anything about the pages you look at. If that changes, this section will say so before it does.

This applies to the website only. The extension does not load PostHog and contains no analytics of any kind.

Deleting your account

Deleting your account removes everything Mend stores for you — audits, API keys, monitors, stored credentials, and the account itself — and, if you subscribed, cancels your Stripe subscription and removes the customer record held for you. Stripe retains its own payment and invoice records where it is legally required to.

Changes

If this policy changes, the updated version will be posted here with a new effective date.

Contact

Questions about privacy? Use the form on the support page and it reaches us directly.