Privacy Policy

TET Accessibility API. Last updated 25 July 2026.

This policy explains what the TET Accessibility API (the "Service") collects when you use the WordPress plugin TET Accessibility for WooCommerce (the "Plugin"). The Service is operated by TET, based in Japan.

The short version

The Plugin works without an account. Scanning your site, reading the issue list, dismissing findings and exporting the CSV all happen on your own server, and nothing is sent to us. Data only reaches us in three situations, all of which you trigger yourself: requesting a key, pressing "Suggest a fix", and opening the settings screen while a key is saved.

What we receive, and when

1. When you request a free key

DataWhyKept for
Email addressTo send you the key and contact you about the accountUntil you ask us to delete it
Site URLTo support you and to detect abuse of the free tierUntil you ask us to delete it
A one-way hash of your IP addressTo rate-limit free key issuance. We do not store the address itself and cannot recover it from the hash30 days

2. When you press "Suggest a fix"

DataWhyKept for
The rule that fired and its WCAG referenceTo generate the suggestionNot stored after the response
The description of the findingTo generate the suggestionNot stored after the response
The HTML snippet already shown to you in your adminTo generate the suggestion. Truncated to 1,200 characters before it is sent onwardNot stored after the response
The page type (shop, product, cart, checkout or account)To generate the suggestion12 months, as a usage record
Your site localeTo answer in your languageNot stored after the response
Your site addressTo apply the site limit on your plan. Normalised, so http/https and a www prefix are not counted as separate sitesUntil you or we release the activation, or 60 days without use
Your API keyAuthentication and quota accountingStored only as a hash; see below
Token counts and a timestampBilling and capacity planning12 months

We keep a usage record of which rule a suggestion was requested for and when. We do not retain the markup or the finding text after your response has been returned.

3. While an API key is saved

The Plugin's settings screen asks the Service how many suggestions remain on your plan. Only your API key is sent, and the answer is cached for one hour. Removing the key from the Plugin stops this.

4. When a payment is made

If you buy a paid plan, our payment provider tells us your email address and which plan you bought, so we can move your key onto it. We never see your card details; the payment provider handles those and is the merchant of record.

What we never receive

The Plugin does not send, and the Service is not built to accept: customer records, orders, payment information, user accounts, passwords, post or page content, or full copies of any page. The scan itself runs on your own server and its results stay in your own database.

API keys

We store a SHA-256 hash of your key, never the key itself. If you lose it we cannot recover it, only issue a replacement.

Who else processes your data

ProcessorRoleLocation
Anthropic PBCGenerates the suggestion text from the finding and markup you submitUnited States
Our hosting providerRuns the Service and its databaseSee our website for the current provider
Our email providerDelivers API keys and account emailSee our website for the current provider

Anthropic processes submitted content to return a response. Per Anthropic's commercial terms, inputs and outputs from API customers are not used to train their models. We do not sell your data, and we do not use it for advertising.

International transfers

We are based in Japan and our AI processor is in the United States, so data you submit is transferred outside the EEA and the UK. Where those transfers concern personal data, we rely on the European Commission's adequacy decision for Japan and on Standard Contractual Clauses with our processors.

Legal basis (UK and EU users)

Your rights

You may ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or export it. Email support@tetphilosopher.com and we will respond within 30 days. Deleting your account removes your email address, site URL, key hash and usage records.

If you are in the EEA or the UK and you are unhappy with our response, you may complain to your national data protection authority. In Japan, the Personal Information Protection Commission handles such complaints.

Cookies

The Service is an API and sets no cookies. This documentation site uses no analytics and no tracking.

Children

The Service is a developer tool and is not directed at anyone under 16. We do not knowingly collect data from children.

Security

All traffic is encrypted in transit with TLS. API keys are stored only as hashes. Access to production data is limited to the operator of the Service. No system is perfectly secure; if a breach affects your data we will notify you and, where required, the relevant regulator.

Changes

If we change this policy materially we will update the date above and notify account holders by email before the change takes effect.

Contact

TET
Email: support@tetphilosopher.com