qatesting.ai

Privacy Policy

What we collect, why, who else touches it, where it lives, and how to get it deleted. Written to be read — you are about to trust us with a login to your own product.

Effective 3 August 2026

Who we are

QAtesting is a product of Freeflow, based in California, USA. This policy covers qatesting.ai and the QAtesting service. Questions, requests, or anything that looks wrong: support@qatesting.ai — a person reads it.

The short version

We store your account email, the domains you’ve verified, the results of your scans, and — only if you choose to save it — an encrypted copy of the login you give us for your own app. Scans and all their evidence are deleted 30 days after they run. Payments go through Stripe, so card numbers never reach us. There are no advertising or tracking cookies, and we do not sell or share your personal information.

What we collect

Your account. Your email address and when you signed up. You sign in with an email and password or with GitHub; if you use GitHub, we receive your email address from them.

Domains you claim. The domain name, the verification token and whether you proved ownership by meta tag or DNS record, and your per-domain scan settings.

The login for your app — only if you give us one. A credentialed scan needs a standard user login for your own site; an imported session works the same way. It is encrypted before it is stored and only ever decrypted inside the isolated crawl worker — never in your browser and never in the job queue. Every scan has a Remember choice: leave it unchecked and nothing is stored at all, and opting out also deletes a credential a previous scan saved rather than merely skipping the next one. You can also run a public-site scan and give us no login at all.

What the scan produces. The findings, the coverage sitemap, evidence screenshots, and a quality score. Screenshots are encrypted at rest in a private store, and personal data captured from your app — emails, card and account numbers, tokens — is redacted from text and masked in screenshots before any of it is stored.

Test email. Each scan is given a disposable receiving address of the form qa-…@inbox.qatesting.ai. If your app sends mail to it, we store the message’s details and an encrypted copy of its body, and both are deleted with the scan. The address contains a random token and never your scan or account id, so it reveals nothing in your app’s mail logs.

Billing. Your Stripe customer reference, your credit balance, your purchases and subscription status. Card numbers and payment details never reach our systems — Stripe handles them.

Analytics, error reporting, and cookies

Analytics. We use Vercel Web Analytics and Speed Insights to see which pages are used and how fast they load. Both are cookieless, collect no personal data, and do not track you across other sites.

Error reporting. We use Sentry to find crashes and bugs — in your browser and on our servers. It is configured for errors only: no performance tracing, no session replay, and no personal data attached to reports. On our servers we additionally strip request bodies before anything is sent, because those requests can carry the credentials you entrusted to us.

Cookies. Essential only. A session cookie keeps you signed in, and a short-lived cookie carries you through a GitHub sign-in and is then cleared. There are no advertising, profiling, or cross-site tracking cookies — which is why you have not been asked to accept any.

IP addresses. Our own application does not collect or store your IP address. Our hosting, authentication and email providers necessarily process it to deliver the service and to protect it from abuse.

Why we process it

To perform our contract with you — running the scans you ask for, showing you the reports, and billing you. Our legitimate interests — keeping the service working and secure, diagnosing failures, and understanding aggregate usage. Legal obligations — keeping the billing records tax and accounting rules require. Where the law requires consent, we ask for it first.

Who else processes it

We do not sell your personal information, and we do not share it for advertising. We use these service providers to run QAtesting, each handling only what its job needs:

Supabase — database, sign-in, and encrypted evidence storage · Vercel — hosting and analytics · Fly.io — the isolated worker that runs your crawl · Inngest — scheduling scan jobs · Stripe — payments · SendGrid — transactional email · Sentry — error reporting · Cloudflare — routing the disposable test-email address · GitHub — only if you choose to sign in with it.

No AI or large-language-model provider is involved in a hosted scan. QAtesting’s checks are deterministic; the optional AI passes are developer tooling and are not part of the service you buy.

We may also disclose information if the law requires it, or to protect our rights or someone’s safety.

Where it is processed

In the United States. Our database is hosted in AWS us-west-2 (Oregon) and the crawl worker runs in iad (Virginia). If you are outside the US, using QAtesting means your information is transferred to and processed there.

How long we keep it

Scans: 30 days, then permanently deleted. The scan, its findings, its coverage sitemap, its evidence screenshots and any test emails are hard-deleted 30 days after the scan runs — the screenshots included, not just the database rows. We email you a few days beforehand so you can export anything you want to keep as CSV, JSON or PDF, and you can delete any scan yourself sooner from its own page.

Kept longer, on purpose: your quality-score history and your triage labels. So that the score trend and your “not a bug” / “won’t fix” decisions survive across scans, we keep the score for each scan of a domain and the labels you gave findings, beyond the 30-day window. These are scores, labels and page paths — no screenshots and no content captured from your app. Deleting the domain removes them.

Until you close your account. Your email address, your domains and your billing history. Some billing records are kept for as long as tax and accounting rules require.

Your rights

Wherever you live, you can ask us to: give you a copy of your data, correct it, delete it, or stop or limit how we use it. Some of it you can do yourself right now — export any report as CSV or JSON, and delete any scan from its page.

To close your account and have its data deleted, email support@qatesting.ai — there is no self-serve button for this yet, so we do it by hand, and that includes the stored evidence. We aim to respond within 30 days.

If you are in the EU or UK, your rights of access, rectification, erasure, restriction, objection and portability apply, and you may complain to your local data protection authority. If you are in California, you have the right to know what we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information — we do neither, and we run no financial-incentive programs. We will never treat you differently for exercising any of these rights.

How we protect it

The login you give us and every evidence screenshot are encrypted at rest, and credentials are decrypted only inside the isolated worker that runs your crawl. Accounts are isolated from each other at the database level, not merely in application code. The crawl itself is read-only and is bounded to a domain you have proven you own — a cross-origin navigation is refused outright. One exception, and it matters because it is about where your login travels: if your app signs in through an external identity provider (SSO), the crawl follows that sign-in redirect so the login can complete, and only ever to a public host. Card details never touch our systems.

Being straight with you about the limits: no service is perfectly secure, and we hold no third-party security certification today.

Children

QAtesting is a tool for people building software, and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

Changes to this policy

If we change how we handle your information, we will update this page and the date at the top of it. The version you are reading is the current one.

Want the practical detail on how scans work? The FAQ covers what QAtesting does with your login and your data day to day.

Privacy Policy — QAtesting · QAtesting