Plain-Language Summary
We never keep your documents or course content. Text you submit for processing — whether for accessibility fixes or quality-matters review — is sent to our servers, used to generate your result, and then discarded. We do not store it.
We never sell or share your data. Not with advertisers, not with data brokers, not ever.
We do log usage statistics — file types, fix and check counts, credits, timestamps — to run your license, provide dashboards, and support accreditation reports. File names are stored only as one-way hashes unless you opt in to full names.
You control your data. Request deletion at any time by emailing info@e2innovations.ai. We respond within five business days.
1. Scope and Definitions
This Privacy Policy is issued by E2 Innovations LLC ("we", "us", "our", "E2 Innovations") and applies to all our products and services, including:
- AccessFix / E2AF — Chrome extension and Desktop application for document accessibility
- PPQMFix / E2PPQM — Chrome extension and Desktop application for course quality and accreditation review
- TeachAssist, ScienceFix — AI-powered educational tools
- Virtual Labs — interactive science laboratory simulations
- E2AF Dashboard at
dashboard.e2innovations.ai — institutional admin dashboard
- E2 Innovations websites — including e2innovations.ai and product landing pages
This unified policy supersedes any earlier product-specific privacy policy, including the AccessFix Privacy Policy dated April 26, 2026, and earlier versions of this unified policy. The commitments made in those earlier policies are preserved and expanded upon here.
"Personal data" means information that identifies you, such as your name, email address, or institution affiliation. "Submitted content" means the text and images inside files, web pages, or courses you ask our software to process.
2. Data Stored Locally on Your Device
Our software stores the following data in your browser's local Chrome storage (chrome.storage.local) or, for Desktop applications, in a local data folder. This data stays on your device and is not transmitted to E2 Innovations except as described in this policy.
- Your license key — stored locally so you do not have to re-enter it each session. The license key is sent to E2 Innovations' license service on each request to confirm validity and to deduct credits (see Section 9).
- Per-installation signing secret — a random secret issued to your installation at license activation, stored locally and used to cryptographically sign your requests so that only activated installations can spend your credits. It contains no personal information.
- Scan, fix, and review history — a local log of recent activity, including page names, file names, issue counts, and your most recent review results, kept only on your device so they remain available when you reopen the app. Not transmitted externally.
- Extension and application settings — your preferences such as selected accreditor, auto-apply alt text, and display options.
- Cached license status — your most recently confirmed credit balance and expiry date, kept locally so the software can show this information to you between requests.
- Canvas access token (PPQMFix Desktop, optional) — if you choose "Remember on this computer" for the whole-course review feature, your Canvas access token is stored only on your device. It is sent solely to your institution's Canvas server, never to E2 Innovations. You may clear it at any time.
3. What We Collect on Our Servers
3.1 Information you provide directly
- License purchase information: name, email address, institution name, payment information (processed by Stripe; we do not store credit card numbers)
- Contact form submissions: name, email, organization, message text
- Virtual Labs registration: institution name, department, country (used to deliver lab access)
- Email correspondence: when you email us, we retain those emails for support and record-keeping
3.2 Information collected automatically when you use our software
- License key (an opaque string identifying your subscription)
- Installation identifier — for Desktop applications, a hash-based computer fingerprint; for Chrome extensions, a random installation ID — used to enforce per-installation license limits and to verify request signatures
- Action telemetry: action and file type processed (DOCX, PPTX, etc.), counts of issues found and fixed, action timestamps, credits charged, success/failure status, application version
- File names: stored only as a one-way SHA-256 hash by default. The original file name is NOT stored unless you explicitly enable "Log full file names" in your dashboard preferences
3.3 Information we do NOT collect
- Submitted content, beyond transient processing — the text inside files, pages, and courses you submit is transmitted to our servers only to perform the operation you requested, and is not stored on E2 Innovations infrastructure after your request completes (see Sections 5 and 6)
- AI-generated output — alt text, rewrites, review reports, and corrected documents are returned to you and discarded server-side
- Browsing history outside our products
- Location data
- Information about your students
4. How Our Products Process Content: Local vs. Server
Our products use two processing models. Which model applies depends on the product and feature; features that transmit content are identified below and in Section 5.
4.1 Local processing (content never leaves your device)
- AccessFix / E2AF standard accessibility scans and fixes — Word, PowerPoint, Excel, and text-based PDF accessibility analysis and metadata fixes run entirely within your browser or local application. Page and file content is read locally and is not transmitted during these operations.
- The AccessFix course-wide accessibility scan visits pages linked from your current LMS page (Canvas, D2L Brightspace, Moodle, Blackboard) and scans each one locally in your browser.
- Virtual Labs — simulations run in your browser; your lab work is not transmitted to us. We collect only the registration information described in Section 3.1.
- Extensions read page content only when you actively trigger a feature. They do not run silently in the background on pages you visit.
- Scan results are stored temporarily in local storage for report generation only.
4.2 Server processing (content transmitted, processed, discarded)
- PPQMFix — all review features. Because quality-review logic, standards data, and scoring run on our servers, every PPQMFix check — including the deterministic rule scan — transmits the captured page text, document text, or collected course content to E2 Innovations for analysis, as described in Section 5.2. Content is processed transiently and is not stored.
- AI-powered features in any product (Section 5) — including AccessFix AI alt-text and conversion features, and TeachAssist AI feedback.
- As our products evolve, additional features may adopt the server-processing model; any feature that transmits submitted content is covered by the commitments in Sections 5, 6, and 13, and material changes will be reflected in this policy per Section 20.
5. Server-Side and AI-Powered Features (Cloud Processing)
Server-side features send submitted content from your browser or computer to a service operated by E2 Innovations, which may forward it to our AI processing partner. Content is transmitted over an encrypted HTTPS connection; our service validates your license key, verifies your installation's request signature, deducts the applicable credits, performs the analysis, and returns the result to you. Submitted content is not stored on E2 Innovations infrastructure beyond the processing of your request.
5.1 AccessFix / E2AF cloud features
- Generating alternative text for images on web pages or in documents
- Converting scanned / image-only PDFs into accessible Word documents using optical character recognition
- Converting uploaded image files (.jpg, .png, .webp, .gif, .bmp) into accessible Word documents
- Converting legacy Office formats (.doc, .ppt, .xls) into modern accessible formats
- Converting text-based PDFs containing images into accessible Word documents with image descriptions
- Generating tagged PDF/UA-compliant PDFs from repaired DOCX files
5.2 PPQMFix course and document reviews
PPQMFix reviews course materials against the Quality Matters Rubric and accreditation criteria. When you run a PPQMFix feature, the following content is transmitted for analysis:
- Page scan: the visible text of the LMS page you choose to scan.
- Document check / corrected version: the text extracted from documents you upload (syllabi, course maps, policies, procedures).
- Full course review: the course content collected as described below.
Whole-course collection. At your request, PPQMFix can gather an entire course for review directly from your LMS:
- In Chrome, the extension reads course content (syllabus, module structure, pages, assignment, discussion, and quiz descriptions) from your institution's Canvas server using your existing logged-in browser session. It can only access courses your own account can access.
- In the Desktop application, you may provide a Canvas access token that you generate in your own Canvas account. The token is used solely to read the course you specify, is sent only to your institution's Canvas server, and is never transmitted to E2 Innovations. If you choose to remember it, it is stored only on your device.
Collected course content is transmitted to E2 Innovations solely to produce the review you requested. Review reports and corrected documents are returned to you; the submitted content is not stored after processing.
5.3 TeachAssist and other AI-assisted tools
Content you submit for AI-assisted feedback or generation is handled under the same model: transmitted for the requested operation, processed, returned, and discarded. Additional AI-assisted features introduced in future releases follow the same commitments.
What you should not submit
Because server-side processing involves sending content to cloud services, you should not use these features on documents containing protected personal information. This includes (but is not limited to) tax forms (W-2, 1099), Social Security numbers, medical records, FERPA-protected student records, financial statements, payroll documents, identification documents, and any other personally identifiable or legally protected data. Our software is designed for course materials, instructor-authored content, and other non-sensitive documents.
6. Data Retention by Our AI Processing Partner
Content sent through our AI processing partner's API is retained for up to 30 days for trust-and-safety review purposes, after which it is automatically deleted. Our AI processing partner does not use this content to train AI models, and we do not authorize any such use.
To request earlier deletion of specific content sent for AI processing, email info@e2innovations.ai with the approximate date and time of the submission, and we will coordinate the deletion request on your behalf.
Institutional customers conducting a vendor security review may request the identity and data-handling details of our current AI processing partner under a Non-Disclosure Agreement by contacting info@e2innovations.ai.
7. Usage Analytics and Institutional Dashboards
AccessFix / E2AF includes optional dashboards showing your usage history. We log a row in our analytics database each time you perform an action (fix a file, generate alt text, convert a PDF). PPQMFix and other products record the license and telemetry data described in Sections 3.2 and 9; product-specific dashboards, where offered, follow the same rules as this section.
7.1 What gets logged per action
| Field | Stored? | Why |
| License key | Yes | Identify whose dashboard the entry belongs to |
| Institution name | Yes (if your license has one) | Roll up data for institutional admin dashboards |
| Action type | Yes | e.g. "fix", "convert_pdf", "alt_text", "check-document" |
| File type | Yes | e.g. "docx", "pptx", "pdf" |
| File name (hashed) | Yes (always) | SHA-256 hash; lets dashboard count unique files without revealing names |
| File name (plain text) | Only if you opt in | Off by default. Toggle in your dashboard preferences. |
| Issues found and fixed counts | Yes | For dashboard statistics |
| Credits charged | Yes | For billing records |
| Timestamp | Yes | For activity charts |
| Platform and app version | Yes | To diagnose version-specific issues |
| Submitted content | NEVER | — |
| AI-generated output (alt text, reviews, rewrites) | NEVER | — |
7.2 Who can see this data
- You: your own activity, via the "📊 My Stats" tab in our app
- Your institutional admin (if any): aggregated data for all licenses tagged with your institution name. Admin licenses are issued by E2 Innovations only after explicit institutional agreement
- E2 Innovations engineers: for debugging and service improvement
- No one else. We do not sell, share, or otherwise disclose this data
7.3 Opting out of full-file-name logging
By default, file names are stored only as hashes. To enable or disable full file name storage, open the AccessFix / E2AF Chrome extension or Desktop app, navigate to the "📊 My Stats" tab, and toggle "Log full file names". This setting applies only to new activity going forward; previously hashed entries remain hashed.
8. Operational Logs at Our Hosting Providers
Our processing services run on managed cloud infrastructure that automatically records operational metadata for service health and debugging. Our services are implemented to record only operational metadata — request timestamp, response status code, and error information when a request fails — and do not write submitted content to logs as part of normal operation.
Operational logs at our hosting providers' tiers are retained for short provider-defined windows (typically 24 hours to a few days) and then automatically deleted by the provider.
9. License, Activation, and Account Data
When you purchase a license, we record the following information in our license database:
- The email address you provided at purchase (used to send your license key and for support correspondence).
- The license key issued to you, your remaining credit balance, expiry date, and whether the license is active.
- Activation records for your installations: for Desktop, hashes of activated computer fingerprints; for Chrome, random installation identifiers — together with each installation's signing secret, an activation label, and activation/last-seen timestamps. These enforce per-installation limits and let you view and deactivate your own installations from within the app.
We do not collect or store your mailing address, browsing history, or any other personal identifier through our software itself. Payment processing is handled separately by Stripe and is governed by Stripe's own privacy policy at stripe.com/privacy. We do not receive or store your payment card details.
10. Chrome Extension Permissions
Our Chrome extensions request only permissions strictly necessary for documented features. Depending on the product, these may include:
- activeTab — to read the content of the tab you are currently viewing, only when you click the extension icon or trigger a feature.
- storage — to save your license key, settings, and history locally on your device.
- scripting — to inject the scanner or helper into active pages when you trigger those features.
- tabs — to detect which tab is active and, where applicable, to walk through linked LMS course pages during a course-wide operation.
- alarms — used by AccessFix to keep long file-processing operations alive until they complete.
- host permissions: <all_urls> — required so the extension can operate on whatever LMS or website your institution runs. For PPQMFix, this also allows reading course content from your institution's Canvas domain during a whole-course review you initiate.
Our extensions do not request or use any Chrome permissions beyond those listed above, and each product requests only the subset it needs.
11. How We Use the Information
- To provide our services: validate your license, verify installation signatures, charge credits, deliver fixes, reviews, and AI results
- To enforce license terms: verify that activations remain within purchased limits
- To improve outcomes: aggregated, anonymized statistics help us identify common issues and refine our detection and review logic
- To support accreditation reporting: institutional admins can view dashboards and export usage reports for HLC, regional accreditors, and other compliance purposes
- To communicate with you: service announcements, renewal reminders, support replies, and (only with your consent) product updates
- To comply with law: respond to lawful requests, enforce our terms, protect against fraud or abuse
We do not use your information for advertising, marketing to third parties, or AI model training.
12. Who We Share Data With
We share data with a small number of essential service providers, each of whom is contractually required to handle your data securely:
- Supabase (database and serverless hosting) — hosts parts of our processing services and stores certain product records
- DigitalOcean (server and database hosting) — runs our license services, processing servers, and the institutional dashboard, and stores license and analytics records
- Our AI processing partner — processes submitted content for AI features (data not used for training; 30-day retention)
- Resend (email delivery) — sends magic-link login emails for the dashboard
- Cloudflare (DNS) — resolves our domain names
- Stripe (payment processing) — handles credit card transactions for license purchases
We do NOT share data with:
- Advertisers or marketing platforms
- Data brokers
- Analytics services like Google Analytics or Facebook Pixel
- Government agencies, except when legally compelled by a valid subpoena or court order
13. Retention and Deletion Periods
| Data Type | Retention Period |
| Submitted content processed by our servers | Transient — not stored after your request completes |
| AI processing partner content | 30 days (then auto-deleted) |
| Operational logs at hosting providers | Short provider windows (typically 24 hours to a few days) |
| Usage analytics (dashboard data) | 36 months (aligns with HLC accreditation cycle) |
| License records (active subscription) | Duration of subscription |
| License records (after cancellation) | 7 years (for accounting purposes) |
| Installation records (fingerprints / install IDs / signing secrets) | While the license is active; removed when you deactivate an installation or the license expires |
| Canvas access token (PPQMFix Desktop) | Stored only on your device; never on our servers. Clear it at any time |
| Contact form submissions | Indefinitely (deletable on request) |
| Email correspondence | Business records; deletable on request |
To request earlier deletion of your data, email info@e2innovations.ai with your license key. We will respond within five business days.
14. What We Do Not Do
- We do not sell, license, or share user data with third parties for marketing or any other purpose.
- We do not use analytics or tracking pixels within our extensions or applications.
- We do not track your browsing history or the pages you visit between scans.
- We do not use your submitted content to train AI models, and our AI processing partner does not either.
- We do not retain copies of content you process; the only data we keep about your account is what is described in Section 9.
- We do not collect data from users who have not entered a valid license key.
15. Your Rights and Data Deletion Requests
You have the right to:
- Request a copy of the license-account information we hold about you (your email, license key, credit balance, and installation records).
- Request deletion of your license-account information. Note that deletion will deactivate your license and you will no longer be able to use our software.
- Request that specific content you submitted for AI processing be removed from our processing partner's systems sooner than the standard 30-day window.
- Withdraw consent for server-side processing at any time by not using those features. AccessFix's local-only features will continue to work without any data leaving your browser.
- Receive your data in a machine-readable format (CSV export available from the dashboard).
- Object to specific processing activities.
To exercise any of these rights, email info@e2innovations.ai from the address associated with your license. We will respond within five business days.
16. Security
We take reasonable measures to protect your data, including:
- All data in transit is encrypted with TLS 1.2 or higher
- Every credit-spending request must be cryptographically signed by an activated installation (HMAC-SHA256 with a per-installation secret), so a leaked license key alone cannot be abused
- Databases use access controls and, where applicable, Row Level Security policies to prevent cross-tenant data access
- Servers are firewalled to allow only necessary traffic, with SSH key authentication only (no password logins)
- Automatic security patches via unattended-upgrades on all production servers
- API keys and shared secrets are stored in environment variables, never in source code, repositories, or client applications
- License keys are opaque tokens with no inferable structure; they cannot be guessed
However, no internet-connected system can be guaranteed perfectly secure. If we discover a data breach affecting you, we will notify you within 72 hours of confirming the breach.
17. FERPA, GDPR, CCPA and Other Laws
17.1 FERPA (US — student educational records)
Our software can be used by educators within institutions subject to the Family Educational Rights and Privacy Act (FERPA) and similar laws. Server-side features — including all PPQMFix reviews and AccessFix AI features — should not be used to process documents that contain personally identifiable student information (grades tied to names, disciplinary records, IEPs, transcripts, or similar), because such use would constitute disclosing those records to a cloud service. Course materials, syllabi, and instructor-authored content are appropriate.
Educators may use AccessFix's local-only features (Word, PowerPoint, Excel, and text-based PDF accessibility fixes) on any documents, since those operations occur entirely within the user's browser and do not transmit content externally.
If your institution requires a Data Processing Agreement or FERPA addendum, contact info@e2innovations.ai.
17.2 GDPR (European Union)
For users in the EU/EEA, we are the data controller for the limited personal data described in Section 3. The lawful basis for processing is:
- Contract: processing necessary to deliver the services you purchased (license validation, action logging for billing)
- Legitimate interests: aggregated analytics for service improvement
- Consent: full-file-name logging requires your explicit opt-in
You may lodge a complaint with your local data protection authority if you believe we have mishandled your data.
17.3 CCPA (California)
For California residents, you have the rights described in Section 15. We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising.
17.4 Other jurisdictions
We strive to comply with applicable data protection laws in every jurisdiction where our customers operate. If you have questions about local compliance, contact us.
18. Cookies and Tracking
- E2 Innovations websites: use no third-party tracking cookies. We do not use Google Analytics, Facebook Pixel, or other analytics services on our marketing pages.
- E2AF Dashboard (
dashboard.e2innovations.ai): uses one essential session cookie (e2af_session) that keeps you logged in for 24 hours. This cookie is HttpOnly, Secure, and SameSite=Lax — it is not used for tracking.
- Chrome extensions and Desktop apps: store license keys and preferences in browser/app local storage. This data does not leave your device except when sent to our services for license validation and the operations you request.
19. Children's Privacy
Our products are designed for use by educators and adults. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
When educators use our software to process course materials, any student information that incidentally appears in a document is treated as transient and is never stored.
20. Changes to This Policy
E2 Innovations LLC may update this Privacy Policy from time to time as our products evolve or as our processing arrangements change. When we do, we will:
- Update the Effective Date at the top of this page
- For material changes, notify active license holders by email to the address on their license
- Keep an archive of prior versions available on request
Continued use of our software after changes are posted constitutes your acceptance of the updated policy.
21. Governing Law
This Privacy Policy is governed by the laws of the State of Wyoming, United States. Any disputes arising from this policy or your use of our products shall be resolved in the courts of Laramie County, Wyoming.