GATEKEEPERQA
Free usage & privacy
Know what you can run and what happens to your data.
Last updated September 29, 2026. The hosted scanner is free today; paid plans are not available. We are not promising unlimited access or a permanent free tier.
What is free today?
Guests receive 2 single-page scans per browser per UTC day. Free accounts receive 5 page scans per UTC day, with up to 5 same-site pages per run. A three-page run uses three page scans. Saved accounts keep their latest 10 reports for up to 30 days. Opening, comparing and downloading saved reports do not use scan credits.
Can my team rely on unlimited daily availability?
The online scanner has shared limits of 50 page attempts per day, 500 per calendar month and 8 per network per day. Scans queue when capacity is busy and new scans stop when a shared allowance is exhausted. This service has no availability guarantee; it should not be your only release check. Failed or incomplete pages restore personal allowance, while shared safety limits still count attempts.
When do allowances reset?
Daily allowances reset at 00:00 UTC; the shared monthly allowance resets on the first day of each calendar month, UTC. Signing in from another browser does not reset an account allowance.
What will paid plans cost?
Paid plans and team features are not available yet. Pricing, quotas and service commitments are still being decided. Contact support@gatekeeperqa.com to discuss your testing needs; the current free service does not promise a future price or tier.
Can I sign in with a work email?
Yes, with an email verification code. Gmail, Outlook and other email providers are supported. Outlook delivery is still being investigated because some codes arrive in Junk; check that folder if your code is missing. Reports are private to the account; company-wide shared workspaces are not available yet.
Does a passing report certify compliance?
No. The scan checks an initially loaded page state. Human testing, assistive technology testing and judgment remain necessary. The founder's DHS Trusted Tester certification is an individual qualification, not DHS approval of this product.
When capacity is full
The interactive sample and before-and-after example remain available without credits. The local CLI does not consume web scanner allowances. Signing in gives an account allowance but does not bypass shared limits.
What the hosted scanner processes
We load the public URLs you submit and generate evidence that can include page URLs, element selectors, HTML snippets, findings and report files. Saved reviews can also contain the names and notes you enter. Do not submit private data, credentials or sensitive content. The scanner does not support logging into a target website.
| Data | Storage and retention |
|---|---|
| Guest reports | Available for 15 minutes after completion; removed during scheduled cleanup. Queue URLs are removed when the job completes or fails. |
| Saved reports and review notes | Latest 10 reports per account, up to 30 days. You can delete a saved report from your account. Downloaded copies remain wherever you save them. |
| Email and sign-in | Supabase verifies email codes and maintains the authentication account. Scanner sign-in challenges last 10 minutes and application sessions last up to 7 days. Email is used for sign-in, not added to a marketing list. Contact Feedback for account deletion; report expiry does not delete your authentication account. |
| Essential cookies and abuse controls | A guest browser cookie lasts up to one day; a signed-in session lasts up to seven days. The service processes network addresses for rate limiting and stores daily keyed network hashes for shared allowances. These controls are separate from journey analytics. |
| Journey analytics | Daily aggregate counts for homepage views, scanner handoffs, accepted scan runs, complete/incomplete reports, verified sign-ins and new sign-ups. Kept for 30 days. No scanned URLs, emails, report content, referrers or visitor identifiers are stored in these counters. |
Account activity and administrator access
Account activity measurement is being introduced to help us understand service use and reliability. When enabled, we keep a pseudonymous account identifier, the date we first observed the verified account and whether it is an internal test account. This minimal account record is retained until account deletion.
We also keep the latest successful scan or saved-report activity time for up to 30 days, removed during scheduled cleanup. This includes opening, reviewing, exporting, renaming or deleting a saved report. These activity records contain no email addresses, scanned URLs or report contents. They are separate from the authentication and report records described above.
A separate MFA-protected administrator dashboard displays aggregate account counts, scanner health and capacity. Signed-in counts mean accounts with an unexpired session, not people currently online. Active counts reflect successful use, not continuous presence. Internal test accounts are separated where identified; account counts begin when tracking is enabled and do not represent all historical registrations.
Contact us using the privacy link below to request deletion of your account and its activity records. Recovery backups may retain deleted scanner data for up to 30 days.
Analytics choices and limitations
Homepage measurement uses no analytics cookies or local storage. It respects Do Not Track and Global Privacy Control. Server-side aggregate service counts do not identify people. Page views can include repeats; stages are not linked to a person, so counts are directional, not a tracked conversion funnel.
Cloudflare processes requests and hosts scanner data; Supabase manages authentication; our email provider delivers verification messages. Infrastructure providers necessarily process network information. Recovery backups may retain deleted scanner data for up to 30 days. This is not a promise of zero infrastructure logging.
Questions or deletion requests
Contact us about privacy or account deletion. Do not attach sensitive reports unless requested through an appropriate channel.