Last updated: September 28, 2026
Color Contrast Checker — WCAG 2.2 AA/AAA — ContrastForge
ContrastForge runs entirely in your browser. The pages you scan, the colours it measures, and the reports it produces all stay on your machine. We collect no browsing data, no analytics, and no telemetry of any kind.
A contrast checker has to look at the page you are checking. Here is exactly what that means, and you can verify all of it in the extension's source code.
When you click the extension and run a scan, ContrastForge injects a measuring script into that one tab, at that moment. The script:
Everything it computes lives in memory in that tab and in the extension's popup, and it makes no network requests at all. When you close the tab, it is gone. Nothing about the page is written anywhere unless you deliberately save a scan or export a report — and both of those are saved on your own computer.
The script is not installed on your pages in advance. There is no content script running in the background, and nothing happens on any page until you click the extension.
To calculate a contrast ratio the extension needs each element's colours and its font size and weight. In the course of walking the page it also records a short element identifier — a CSS selector such as .btn-checkout, and a short snippet of the element's text — so the results list and the exported report can tell you which element failed. Without that, a report would be a list of ratios with no way to find them.
That is the extent of it. ContrastForge does not read form data, does not read anything you type, does not touch password fields, does not collect links or images, and does not build any record of the pages you visit. Everything it does read stays on your device.
Your saved colour palettes, your scan history, your settings and your license status are stored locally in your browser using chrome.storage.local. Scan history includes the page URL, the date, and the findings from that scan — so you can compare a page against an earlier check. It is stored on your machine only and is never transmitted to us or anyone else. You can clear it at any time from the extension's settings, and uninstalling the extension removes it.
Reports you export are written to your computer by your browser's normal download process, exactly like any other file you download. We never receive a copy.
ContrastForge asks for less access than any of our other extensions, and less than the contrast checkers it competes with. It asks for three things at install, and one more only if you use multi-page audits:
Scanning one page needs nothing more than the tab you are looking at. Auditing a list of pages is different: the extension has to open each one and read it, and the active-tab permission does not cover a tab you did not click on.
So that access is an optional permission. It is not requested when you install the extension, and it is not requested when you scan a single page. Your browser asks you for it only at the moment you press "Scan all pages" on a multi-page audit, and you can decline — single-page scanning and everything else keeps working exactly as before. You can revoke it at any time in your browser's extension settings.
When you do grant it, each URL in your list is opened in a background tab, measured the same way a single page is, and the tab is closed again. The findings stay on your machine like every other scan. Nothing about those pages is uploaded.
If you choose to activate Pro, the extension sends your license key — once, when you click "Activate" in Settings — to Lemon Squeezy (our payment provider, lemonsqueezy.com) to verify it. This is the only outbound network request the extension makes, and it happens only at your explicit action. Your email address, if returned by Lemon Squeezy during validation, is stored locally to display your license status. Nothing about the pages you scan is ever included. The request goes to exactly one address, https://api.lemonsqueezy.com/v1/licenses/validate, and contains exactly one thing: the licence key you pasted. No page data, no identifiers, nothing about what you were doing. You can confirm this by searching the extension's source for fetch( — there is a single occurrence, in common.js.
ContrastForge measures colour contrast against the WCAG 2.2 contrast criteria. It is not a full accessibility audit and it cannot tell you whether a site is legally compliant with any accessibility law. It is a measuring tool, and the professional judgement stays with the person using it.
If this policy changes, the date at the top of this page changes with it. If we ever made a change that affected what data leaves your machine — we do not intend to — we would say so plainly here and in the extension itself.
Questions: sapirsoftware@gmail.com