Privacy Notice
a11 Accessibility ("a11," "we," "us") provides an AI accessibility platform ("a11") for video captioning, audio description, and document remediation. This Privacy Notice explains what data we collect, why, where it lives, who processes it, and the choices and rights available to institutions and individuals.
a11 is based in the United States (Provo, UT).
1. Our Role
For most data, a11 acts as a processor / service provider on behalf of the customer institution, which is the controller/owner of the content it uploads. For higher-education institutions in the United States, a11 acts as a school official with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA), processing education records solely to provide the contracted accessibility services and under the institution's direction. See Section 8.
2. Data We Collect and Why
| Data | Why we collect it | Legal basis |
|---|---|---|
| Source media (institution-uploaded videos, audio, documents; or media pulled from the institution's own systems such as Kaltura) | To generate captions, audio descriptions, and remediated documents | Performance of our contract with the institution; institutional direction |
| Derived accessibility data (transcripts, captions, descriptions, remediated document elements, OCR output) | To deliver the accessibility outputs the institution requested | Performance of our contract with the institution |
| Account information (name, email, role/team) | To create accounts, authenticate users, and provide support | Performance of our contract; legitimate interests in securing the service |
| Operational data (usage analytics, error logs) | To operate, secure, debug, and improve the service | Legitimate interests |
We do not sell personal data. We do not use institutional content for advertising.
3. How We Use Data
We use data only to provide and support the a11 service: processing media into accessibility outputs, maintaining accounts, providing support, securing the platform, and improving product reliability. We do not use institutional content, or the outputs derived from it, to train our own models.
4. AI Providers and Subprocessors
To generate accessibility outputs, we send relevant source media and derived data to third-party AI providers for one-time inference only. These providers do not train their models on data we submit through their APIs:
- (Speech-to-text via Whisper runs self-hosted on Modal — no third-party transcription provider receives your audio.)
- OpenAI — GPT-4o-mini and text-to-speech; used via the OpenAI API, which does not train on API-submitted data.
- Google Vertex AI / Gemini — video/visual description and OCR enrichment; Vertex AI does not train on submitted data. [confirm Vertex backend]
- MathPix — math and table OCR; SOC 2 and does not train on submitted data.
We also rely on infrastructure and operational subprocessors: AWS (storage/compute), Supabase (database, auth), Vercel (frontend hosting), Railway (API hosting), Modal (GPU compute), Resend (transactional email), Kaltura (pulls the institution's own source video), Sentry (error monitoring), PostHog (product analytics), Namecheap (DNS), and Stripe (payments — planned/future).
A current, itemized list with data categories, locations, and each provider's compliance certifications is maintained in our Subprocessor List.
5. Where Data Is Stored
All primary storage is in the United States:
- Source media: AWS S3 (
us-west-2), encrypted at rest with AES-256. - Accounts and derived data: Supabase Postgres (US), encrypted at rest with AES-256.
Some subprocessors may process data in other regions per their own infrastructure; we select providers that offer appropriate safeguards.
6. Data Retention and Deletion
- Source media is automatically deleted after a retention window measured from contract end: 30 days by default, 90 days for Team, and a configurable window for Enterprise. A scheduled job hard-deletes these objects from S3.
- Derived accessibility data and account data are retained for the life of the account and deleted on account termination or on verified request.
- Backups (Supabase automated backups) are encrypted, used only for disaster recovery, and age out on a rolling schedule.
Full details are in our Data Retention & Deletion Policy.
7. How We Protect Data
- Encryption in transit (TLS) and at rest (AES-256).
- Row-Level Security (RLS) and per-team isolation so each institution accesses only its own data.
- Access limited to authorized personnel with a business need.
- Error monitoring and analytics configured to avoid storing source-media content.
8. FERPA Statement
Where a11 processes student content for a higher-education institution, that content may constitute education records under FERPA. a11:
- Acts as a school official performing a service the institution would otherwise perform itself, under the institution's direct control as to the use and maintenance of education records;
- Uses education records only to provide the contracted accessibility services;
- Does not re-disclose education records except as directed by the institution or as required by law, and does not use them to train models;
- Deletes education records per the institution's contract and this notice.
Individuals with questions about their education records should contact their institution, which is the record owner. a11 supports institutions in responding to such requests.
9. Your Rights
Depending on your relationship with the institution and applicable law, you may have rights to access, correct, or delete personal data. Because a11 processes most data on behalf of institutions, we direct individual requests to the relevant institution and assist it in fulfilling them. Account holders can update basic account information in-product or by contacting us.
10. Children's and Student Data
a11 is provided to institutions, not marketed directly to children. Student data is handled under the institution's direction and applicable law (including FERPA).
11. Changes to This Notice
We may update this notice. Material changes will be reflected by an updated Effective date and, where appropriate, communicated to institutional customers.
12. Contact
a11 Accessibility — Owen Wayment, CEO Email: service@a11accessibility.com Provo, UT, USA
a11 Accessibility · Provo, UT, USA · service@a11accessibility.com