Skip to content
qaitai
Menu
Get started

Draft · not in force · pending review by counsel

DRAFT — not legal advice. Requires review by counsel before publication. Placeholders in [[DOUBLE_BRACKETS]] must be filled first; see docs/legal/README.md.

Privacy Policy

Effective: [[EFFECTIVE_DATE]]

This policy explains what personal data [[LEGAL_ENTITY]] ("qaitai", "we") collects when you use tryqaitai.com and qaitai Cloud (app.tryqaitai.com), and what we do with it.

Two roles. For your account, billing and our website, we are the controller. For the content of the apps you test (what our agent sees and records), you are the controller and we are your processor, under our Data Processing Addendum.

Self-hosted. If you run qaitai on your own infrastructure, this policy does not cover that instance: your data stays with you, and we receive nothing unless you contact us. (Opt-in telemetry, if we add it, will be documented here and off by default.)

What we collect

DataWhere it comes fromWhy
Account: name, email, avatar, GitHub or Google identityYou, GitHub, GoogleSign-in, workspaces, invitations
Workspace data: projects, journey prompts, verified domains, settings, audit logYouRunning the service; security
GitHub data: repositories, pull requests, deployments you grant the qaitai GitHub App access toGitHubFinding preview URLs, posting PR checks, understanding your app
Test secrets (e.g. a test user's password) and your own model or browser API keys (BYOK)YouLogging in to your app during tests; calling the provider you chose
Run data: steps, page URLs, accessibility snapshots, screenshots, replays, findings, usageOur agent, while testing your appShowing results, reproducing bugs, billing
Billing: billing contact, address, payment method (held by Stripe)You, StripeCharging for paid plans
Technical: IP address, browser, error reports, product usage eventsYour browserSecurity, debugging, improving the product

We don't sell personal data, and we don't use your app content or run data to train AI models.

How your app's data flows

When you start a run, qaitai opens a real browser (on Steel, or on a runner you host) and an AI model decides what to do next.

  • Sent to the model provider: your journey prompt, the page URL, accessibility snapshots and screenshots of the page, and the results of each action. Whatever your app shows on screen can therefore reach the model provider. Use test data, not real customer data, where you can.
  • Never sent to the model: test secret values. The model only sees their names; a tool types the value into the page. Values are redacted from snapshots and recorded reasoning. A screenshot is a picture of the page, so if your app displays a secret on screen, it can appear in one.
  • Stored by us: run steps, findings and snapshots in our database; screenshots and replays in object storage.
  • Encrypted at rest: test secrets and BYOK keys, each with its own key (AES-256-GCM, envelope encryption). We store only a 4-character hint in the clear.
  • BYOK: if you use your own model or browser key, that provider processes the data under your agreement with them.
  • Self-hosted runners: runs that execute on your own runner keep the browser and model traffic in your network. We receive progress events, findings and (on qaitai Cloud) screenshots and replays.

The providers we use are listed on the Subprocessors page.

How long we keep it

DataRetention
Account and workspace dataWhile your account exists; deleted within 30 days of account deletion
Screenshots and replaysFree 7 days · Pro 30 days · Team 90 days · Enterprise per contract
Run steps and findingsWhile the workspace exists, unless you delete them [[CONFIRM_RUN_RETENTION]]
Test secrets and BYOK keysUntil you delete them or the workspace
Billing recordsAs long as tax law requires (typically 7 years)
Error reports and analytics[[OBSERVABILITY_RETENTION]] (at most 12 months)
BackupsRolled off within [[BACKUP_RETENTION]]

Legal bases (EEA/UK)

Contract (running the service you signed up for), legitimate interests (security, fraud prevention, product analytics, improving the product), legal obligation (tax and accounting records) and consent where required (for example non-essential cookies).

Cookies

We use cookies needed to keep you signed in. On qaitai Cloud we use PostHog for product analytics; where the law requires consent we ask first. [[COOKIE_DETAILS]]

International transfers

We and our providers operate mainly in the United States. Transfers of EEA, UK and Swiss personal data rely on the EU Standard Contractual Clauses, the UK Addendum, or the EU-US Data Privacy Framework where the recipient is certified.

Your rights

Depending on where you live, you can ask to access, correct, delete or export your personal data, and object to or restrict some processing. Email privacy@tryqaitai.com. We answer within 30 days. If we process data on behalf of a customer (for example content of an app you tested), we will pass your request to that customer. You can also complain to your local data protection authority.

[[EU_UK_REPRESENTATIVE]]

Security

Row-level security isolates every workspace's data in the database, secrets are encrypted, cloud runs may only target domains you have verified, and runners connect outbound only. If a breach affects your personal data, we will notify affected customers without undue delay and within 72 hours of confirming it. Report vulnerabilities as described in SECURITY.md in our repository.

Children

qaitai is not for children under 16, and we don't knowingly collect their data.

Changes

We'll post updates here and email account owners about material changes at least 30 days before they take effect.

Contact

[[LEGAL_ENTITY]], [[REGISTERED_ADDRESS]] · privacy@tryqaitai.com