Privacy policy for WCAG Contrast Checker
WCAG Contrast Checker by Sapir
ContrastForge Privacy Policy
Last updated: August 22, 2026
Color Contrast Checker — WCAG 2.2 AA/AAA — ContrastForge
The short version
ContrastForge runs entirely in your browser. The pages you scan, the colours it measures, and the reports it produces all stay on your machine. We collect no browsing data, no analytics, and no telemetry of any kind.
What happens when you scan a page — the honest explanation
A contrast checker has to look at the page you are checking. Here is exactly what that means, and you can verify all of it in the extension's source code.
When you click the extension and run a scan, ContrastForge injects a measuring script into that one tab, at that moment. The script:
Walks the visible elements on the page and reads their computed colour values — text colour, background colour, opacity, font size and font weight
Composites those colours to work out what a person actually sees, and calculates contrast ratios from them
Draws a temporary outline around an element when you click one of the results, and removes it afterwards
Everything it computes lives in memory in that tab and in the extension's popup, and it makes no network requests at all. When you close the tab, it is gone. Nothing about the page is written anywhere unless you deliberately save a scan or export a report — and both of those are saved on your own computer.
The script is not installed on your pages in advance. There is no content script running in the background, and nothing happens on any page until you click the extension.
What the extension reads, and what it doesn't
To calculate a contrast ratio the extension needs each element's colours and its font size and weight. In the course of walking the page it also records a short element identifier — a CSS selector such as .btn-checkout, and a short snippet of the element's text — so the results list and the exported report can tell you which element failed. Without that, a report would be a list of ratios with no way to find them.
That is the extent of it. ContrastForge does not read form data, does not read anything you type, does not touch password fields, does not collect links or images, and does not build any record of the pages you visit. Everything it does read stays on your device.
What the extension stores
Your saved colour palettes, your scan history, your settings and your license status are stored locally in your browser using chrome.storage.local. Scan history includes the page URL, the date, and the findings from that scan — so you can compare a page against an earlier check. It is stored on your machine only and is never transmitted to us or anyone else. You can clear it at any time from the extension's settings, and uninstalling the extension removes it.
Reports you export are written to your computer by your browser's normal download process, exactly like any other file you download. We never receive a copy.
Permissions
ContrastForge asks for less access than any of our other extensions, and less than the contrast checkers it competes with. It asks for three things at install, and one more only if you use multi-page audits:
Active tab — access to the single tab you are looking at, granted at the moment you click the extension and not before. The extension has no standing access to any website and cannot see the other sites you visit. It does not request access to all sites at install time.
Access to the pages you list (optional) — not requested at install, and never for single-page scans. Asked for only when you run a multi-page audit, and revocable at any time. See the section below.
Scripting — permission to inject the measuring script into that active tab when you run a scan, and to draw the temporary highlight outline. Nothing is injected until you click.
Storage — saves your palettes, scan history, settings and license status locally.
Multi-page audits and the optional permission
Scanning one page needs nothing more than the tab you are looking at. Auditing a list of pages is different: the extension has to open each one and read it, and the active-tab permission does not cover a tab you did not click on.
So that access is an optional permission. It is not requested when you install the extension, and it is not requested when you scan a single page. Firefox asks you for it only at the moment you press "Scan all pages" on a multi-page audit, and you can decline — single-page scanning and everything else keeps working exactly as before. You can revoke it at any time in your browser's add-on settings.
When you do grant it, each URL in your list is opened in a background tab, measured the same way a single page is, and the tab is closed again. The findings stay on your machine like every other scan. Nothing about those pages is uploaded.
The only network request we ever make
If you choose to activate Pro, the extension sends your license key — once, when you click "Activate" in Settings — to Lemon Squeezy (our payment provider, lemonsqueezy.com) to verify it. This is the only outbound network request the extension makes, and it happens only at your explicit action. Your email address, if returned by Lemon Squeezy during validation, is stored locally to display your license status. Nothing about the pages you scan is ever included. The request goes to exactly one address, https://api.lemonsqueezy.com/v1/licenses/validate, and contains exactly one thing: the licence key you pasted. No page data, no identifiers, nothing about what you were doing. You can confirm this by searching the extension's source for fetch( — there is a single occurrence, in common.js.
What we never do
No collection of the pages you scan, their content, or their addresses
No browsing history collection
No standing access to websites — the extension only ever sees the tab you point it at
No reading of form data, typed input, or password fields
No analytics or usage tracking
No advertising or third-party trackers
No remotely hosted code — every line ships in the extension package and is reviewed by the add-on store you installed it from
No sale or sharing of any data, ever
A note on what ContrastForge is for
ContrastForge measures colour contrast against the WCAG 2.2 contrast criteria. It is not a full accessibility audit and it cannot tell you whether a site is legally compliant with any accessibility law. It is a measuring tool, and the professional judgement stays with the person using it.
Changes to this policy
If this policy changes, the date at the top of this page changes with it. If we ever made a change that affected what data leaves your machine — we do not intend to — we would say so plainly here and in the extension itself.
Contact
Questions: sapirsoftware@gmail.com
Sapir Software
The current version of this policy is always at https://sapirsoftware.github.io/contrastforge-privacy.html