What we store, and why.
Last updated 2026-09-26. Written in plain language, so that it can be read.
What we store
Your email address and a salted hash of your password. Your team's name and settings. The site URLs you add and, if you enter one, the test account for a site (email and password), set by team admins and never shown again. Run results: verdicts, reasons, the runner's logs with the test account's values blanked out, and screenshots of the sites you test, uploaded by the runner that tested them. An audit log of changes made in your team, with the address they were made from, kept for two years and visible to team admins.
Where the tests run
With your own runner, the browser runs on your machine: we receive what it uploads and nothing else. With hosted runners (Cloud), one of our runners receives the site's test account for the duration of the run, opens the site with it in a browser on our machine, uploads the results, and keeps neither the account nor the pages once the run has ended. The test account leaves the run's record when the run ends. Self-hosted installs send nothing to us at all.
Who else sees data
The mail relay you or we configure delivers invitations, password resets and alerts (site names, test names, reasons). A webhook you configure receives the same alert as JSON. Stripe receives your email and plan when you pay. The local model that drafts tests from a sentence receives that sentence. A share link you create shows the run's verdicts and screenshots to anyone holding it, until you revoke it. Nothing is sold or shared for advertising.
How long
Runs for the history period of your plan (a year at most on unlimited plans, 90 days after a trial ends; a shared run is kept for a year). Account data while the account exists; the audit log keeps the e-mail address on the actions it records for 730 days, also after the account is deleted. When the data volume runs low, the oldest evidence past a week goes first, teams that never paid before paying ones. Deleting a run removes its results and screenshots at once; removing a site keeps its past results until they expire; deleting a team removes everything it held. Backups an operator keeps follow the operator's own schedule.
Where
Hetzner Online GmbH, Falkenstein (DE). Hosted runners are not offered yet: every run executes on a runner you connect, and only its results reach us. Your own runners test from wherever you run them. Self-hosted installs keep everything inside your own infrastructure.
Your rights
Delete your account or a team you own on the account page. For an export, or anything else, write to privacy@qa.pro; we answer within 30 days.
Cookies
A session cookie to keep you logged in and a five-second flash cookie in the demo. No analytics cookies, no third-party trackers.