Privacy Policy
Effective: 2026-07-25
This Privacy Policy explains how we collect, use, store, and share information about you when you use the AIPoweredTesting desktop application, the website at ai-powered-testing.com, and related services (the "Service"). It applies to visitors from the European Economic Area (GDPR), residents of California (CCPA), and the general public.
1. Introduction
AIPoweredTesting is currently in closed beta. This policy describes the limited personal data we process to operate the Service. Where our data practices differ by region (GDPR or CCPA), we note the difference explicitly. By using the Service you acknowledge that you have read and understood this policy. If you do not agree, please do not use the Service.
2. Data controller
The data controller responsible for your personal data under GDPR, and the "business" under CCPA, is:
Aleksandr KoshcheevPersona Física en Régimen Simplificado de Confianza
RFC: KOAL761127LN4
Av. Adolfo López Mateos Sur 5060, Piso 4, Despacho D, Interior A, Col. Miguel de la Madrid, C.P. 45239, Zapopan, Jalisco, México
Email: support@ai-powered-testing.com
3. What we collect
3.1 From the public early-access form
- Email — required.
- Name — required.
- Role, team size, use case, company website — optional.
- IP address and User-Agent string captured automatically on submit.
- Cloudflare Turnstile challenge token (anti-spam).
3.2 From Google Sign-in
- Email address.
- Display name.
- Google account unique identifier (
subclaim).
3.3 From the macOS application (product telemetry)
Non-exhaustive list of events we log to improve the Service:
session_started,session_completed— start/end of an app session.feature_used— which high-level features were opened.test_run_started,test_run_completed— durations, device type, pass/fail counts.app_version_opened— version, OS version, device locale.
3.4 From crash reports (Sentry)
- Stack trace, exception class and message.
- App version, macOS version, device locale.
- We do not intentionally collect personal data in crash reports.
3.5 At beta-code activation
- IP address and User-Agent (for audit — detects code sharing and geographic anomalies).
3.6 Test content and run artifacts (synced by the desktop app)
- Test content you author — test scripts, scenarios, presets, suites, and application catalog entries are stored on our backend so they can sync across your devices and be shared with your team.
- Run artifacts — screenshots, execution logs, device logs (logcat), and HTML reports produced by a test run are uploaded to our storage so you and your team can review sessions from any machine.
- Run history — per-session records: which test ran, on which device or emulator, pass/fail outcome, and timestamps.
- Run artifacts may incidentally capture personal data if the application under test displays it (for example, on a screenshot). You control what your tests display; retention limits for this data are described in section 6.
4. What we do NOT collect
- Credit card or bank account details — no payment processor is active in the closed beta.
- The binaries of the applications you test (
.apk/.ipa) — builds are never uploaded to or stored on our servers; the Service references your own download URL or a locally attached build. - Biometric data.
- Precise geolocation (GPS) — we derive country only from your IP for rate-limit and abuse detection.
- Browser tracking cookies — the Service uses functional cookies only (session token, CSRF protection, language preference).
5. Legal basis (GDPR)
- Public-form submissions — your consent (Article 6(1)(a)), given by submitting the form.
- Account and beta access — performance of a contract (Article 6(1)(b)).
- Product telemetry — legitimate interest in product improvement (Article 6(1)(f)).
- Crash reports — legitimate interest in debugging and reliability (Article 6(1)(f)).
- Future marketing emails — your consent (not currently in use).
6. Retention
- Early-access submissions not converted to accounts — 90 days, then deleted.
- Account and profile data — for the duration of your access to the Service; personal data is removed within 30 days after account deletion.
- Test content you author (test scripts, scenarios, presets, suites, application catalog) — for the life of your account; removed together with account data after account deletion.
- Run artifacts and run history (screenshots, logs, reports, session records) — guaranteed available for 90 days after the run, then automatically deleted (deletion completes at approximately 104 days). See the Data Retention Policy for details.
- Audit logs — 12 months (compliance window).
- Product telemetry events — 24 months, then aggregated or deleted.
- Crash reports — 12 months.
- Backups — 30 days rolling (disaster recovery).
7. Third parties (sub-processors)
We use the following sub-processors. All transfers from the EEA rely on EU Standard Contractual Clauses (SCCs) included in each provider's DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| OAuth Sign-in (email, name, sub) | USA | |
| Resend | Transactional email (welcome / beta-code delivery) | USA |
| Cloudflare | Turnstile anti-spam and CDN (IP, User-Agent, challenge token) | USA |
| AWS | Hosting, database, and run-artifact storage — screenshots, logs, reports (us-east-2) | USA |
| Sentry | Crash reporting (stack traces, app / OS version) | USA |
Stripe is listed as a planned phase-2 sub-processor for subscription billing. It is not currently receiving any user data and will not begin processing data until (a) Stripe merchant onboarding (KYC) is completed and (b) paid plans open. At that time, we will update this policy and notify existing users.
8. Your rights (GDPR)
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights in respect of your personal data:
- Right of access (Article 15) — obtain a copy of the data we hold about you.
- Right to rectification (Article 16) — ask us to correct inaccurate data.
- Right to erasure (Article 17) — ask us to delete data when there is no longer a valid reason to process it.
- Right to data portability (Article 20) — receive your data in a structured, machine-readable format.
- Right to restriction of processing (Article 18).
- Right to object (Article 21) — including to processing based on legitimate interest.
- Right to withdraw consent at any time, without affecting processing based on consent before its withdrawal.
You also have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your residence.
9. Your rights (CCPA)
If you are a California resident, you have the right to know what personal information we collect about you and why, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. We will not discriminate against you for exercising any of these rights.
10. How to exercise your rights
To exercise any of the rights above, email support@ai-powered-testing.com from the address associated with your account or early-access submission. We respond within 30 calendar days. We may ask you to verify your identity before acting on a request in order to protect your data from unauthorized disclosure.
11. Children
The Service is not directed to individuals under the age of 18 and we do not knowingly collect personal data from them. If you believe that we have collected data from a child under 18, please contact us at support@ai-powered-testing.com and we will delete it promptly.
12. Changes to this Policy
We may update this policy from time to time. The current version is always available at ai-powered-testing.com/legal/privacy. Material changes will be communicated by email to the address associated with your access and/or by a banner on the Service at least 30 days before they take effect.
13. Contact
For privacy-related questions or to exercise any of the rights above, contact us at support@ai-powered-testing.com or by postal mail at the address listed under "Data controller".