Draft · not in force · pending review by counsel
DRAFT — not legal advice. Requires review by counsel before publication. Placeholders in
[[DOUBLE_BRACKETS]]must be filled first; see docs/legal/README.md.
Privacy Policy
Effective: [[EFFECTIVE_DATE]]
This policy explains what personal data [[LEGAL_ENTITY]] ("qaitai", "we") collects when you use tryqaitai.com and qaitai Cloud (app.tryqaitai.com), and what we do with it.
Two roles. For your account, billing and our website, we are the controller. For the content of the apps you test (what our agent sees and records), you are the controller and we are your processor, under our Data Processing Addendum.
Self-hosted. If you run qaitai on your own infrastructure, this policy does not cover that instance: your data stays with you, and we receive nothing unless you contact us. (Opt-in telemetry, if we add it, will be documented here and off by default.)
What we collect
| Data | Where it comes from | Why |
|---|---|---|
| Account: name, email, avatar, GitHub or Google identity | You, GitHub, Google | Sign-in, workspaces, invitations |
| Workspace data: projects, journey prompts, verified domains, settings, audit log | You | Running the service; security |
| GitHub data: repositories, pull requests, deployments you grant the qaitai GitHub App access to | GitHub | Finding preview URLs, posting PR checks, understanding your app |
| Test secrets (e.g. a test user's password) and your own model or browser API keys (BYOK) | You | Logging in to your app during tests; calling the provider you chose |
| Run data: steps, page URLs, accessibility snapshots, screenshots, replays, findings, usage | Our agent, while testing your app | Showing results, reproducing bugs, billing |
| Billing: billing contact, address, payment method (held by Stripe) | You, Stripe | Charging for paid plans |
| Technical: IP address, browser, error reports, product usage events | Your browser | Security, debugging, improving the product |
We don't sell personal data, and we don't use your app content or run data to train AI models.
How your app's data flows
When you start a run, qaitai opens a real browser (on Steel, or on a runner you host) and an AI model decides what to do next.
- Sent to the model provider: your journey prompt, the page URL, accessibility snapshots and screenshots of the page, and the results of each action. Whatever your app shows on screen can therefore reach the model provider. Use test data, not real customer data, where you can.
- Never sent to the model: test secret values. The model only sees their names; a tool types the value into the page. Values are redacted from snapshots and recorded reasoning. A screenshot is a picture of the page, so if your app displays a secret on screen, it can appear in one.
- Stored by us: run steps, findings and snapshots in our database; screenshots and replays in object storage.
- Encrypted at rest: test secrets and BYOK keys, each with its own key (AES-256-GCM, envelope encryption). We store only a 4-character hint in the clear.
- BYOK: if you use your own model or browser key, that provider processes the data under your agreement with them.
- Self-hosted runners: runs that execute on your own runner keep the browser and model traffic in your network. We receive progress events, findings and (on qaitai Cloud) screenshots and replays.
The providers we use are listed on the Subprocessors page.
How long we keep it
| Data | Retention |
|---|---|
| Account and workspace data | While your account exists; deleted within 30 days of account deletion |
| Screenshots and replays | Free 7 days · Pro 30 days · Team 90 days · Enterprise per contract |
| Run steps and findings | While the workspace exists, unless you delete them [[CONFIRM_RUN_RETENTION]] |
| Test secrets and BYOK keys | Until you delete them or the workspace |
| Billing records | As long as tax law requires (typically 7 years) |
| Error reports and analytics | [[OBSERVABILITY_RETENTION]] (at most 12 months) |
| Backups | Rolled off within [[BACKUP_RETENTION]] |
Legal bases (EEA/UK)
Contract (running the service you signed up for), legitimate interests (security, fraud prevention, product analytics, improving the product), legal obligation (tax and accounting records) and consent where required (for example non-essential cookies).
Cookies
We use cookies needed to keep you signed in. On qaitai Cloud we use PostHog for product analytics; where the law requires consent we ask first. [[COOKIE_DETAILS]]
International transfers
We and our providers operate mainly in the United States. Transfers of EEA, UK and Swiss personal data rely on the EU Standard Contractual Clauses, the UK Addendum, or the EU-US Data Privacy Framework where the recipient is certified.
Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, and object to or restrict some processing. Email privacy@tryqaitai.com. We answer within 30 days. If we process data on behalf of a customer (for example content of an app you tested), we will pass your request to that customer. You can also complain to your local data protection authority.
[[EU_UK_REPRESENTATIVE]]
Security
Row-level security isolates every workspace's data in the database, secrets are encrypted, cloud runs
may only target domains you have verified, and runners connect outbound only. If a breach affects your
personal data, we will notify affected customers without undue delay and within 72 hours of confirming
it. Report vulnerabilities as described in SECURITY.md in our repository.
Children
qaitai is not for children under 16, and we don't knowingly collect their data.
Changes
We'll post updates here and email account owners about material changes at least 30 days before they take effect.
Contact
[[LEGAL_ENTITY]], [[REGISTERED_ADDRESS]] · privacy@tryqaitai.com