Privacy Policy
Effective: 2026-07-25
This Privacy Policy explains how we collect, use, store, and share information about you when you use the AIPoweredTesting desktop application, the website at ai-powered-testing.com, and related services (the "Service"). It applies to users in México (LFPDPPP), visitors from the European Economic Area (GDPR), residents of California (CCPA), and the general public.
1. Introduction
AIPoweredTesting is currently in closed beta. This policy describes the limited personal data we process to operate the Service. Where our data practices differ by region (GDPR or CCPA), we note the difference explicitly. By using the Service you acknowledge that you have read and understood this policy. If you do not agree, please do not use the Service.
2. Data controller
The data controller under GDPR, the "responsable" under México's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), and the "business" under CCPA, is:
Aleksandr KoshcheevPersona Física en Régimen Simplificado de Confianza
RFC: KOAL761127LN4
Av. Adolfo López Mateos Sur 5060, Piso 4, Despacho D, Interior A, Col. Miguel de la Madrid, C.P. 45239, Zapopan, Jalisco, México
Email: support@ai-powered-testing.com
3. What we collect
3.1 From the public early-access form
- Email — required.
- Name — required.
- Role, team size, use case, company website — optional.
- IP address and User-Agent string captured automatically when you submit the form.
- Cloudflare Turnstile challenge token (anti-spam).
3.2 From Google Sign-In
- Email address.
- Display name.
- Unique Google account identifier (the
subclaim).
3.3 From the macOS application (product telemetry)
A non-exhaustive list of events we log to improve the Service:
session_started,session_completed— start/end of an app session.feature_used— which high-level features were opened.test_run_started,test_run_completed— durations, device type, pass/fail counts.app_version_opened— version, OS version, device locale.
3.4 From crash reports (Sentry)
- Stack trace, exception class, and message.
- App version, macOS version, device locale.
- We do not intentionally collect personal data in crash reports.
3.5 At beta-code activation
- IP address and User-Agent (for auditing — helps us detect code sharing and geographic anomalies).
3.6 Test content and run artifacts (synced by the desktop app)
- Test content you author — test scripts, scenarios, presets, suites, and application catalog entries are stored on our backend so they can sync across your devices and be shared with your team.
- Run artifacts — screenshots, execution logs, device logs (logcat), and HTML reports produced by a test run are uploaded to our storage so you and your team can review sessions from any machine.
- Run history — per-session records: which test ran, on which device or emulator, pass/fail outcome, and timestamps.
- Run artifacts may incidentally capture personal data if the application under test displays it (for example, in a screenshot). You control what your tests display; retention limits for this data are described in section 6.
4. What we don't collect
- Credit card or bank account details — no payment processor is active in the closed beta.
- The binaries of the applications you test (
.apk/.ipa) — builds are never uploaded to or stored on our servers; the Service references your own download URL or a locally attached build. - Biometric data.
- Precise geolocation (GPS) — we derive only your country from your IP address, for rate limiting and abuse detection.
- Browser tracking cookies — the Service uses functional cookies only (session token, CSRF protection, language preference).
5. Legal basis (GDPR)
- Public-form submissions — your consent (Article 6(1)(a)), given by submitting the form.
- Account and beta access — performance of a contract (Article 6(1)(b)).
- Product telemetry — legitimate interest in product improvement (Article 6(1)(f)).
- Crash reports — legitimate interest in debugging and reliability (Article 6(1)(f)).
- Future marketing emails — your consent (not currently in use).
- Automated decision-making — none: we do not make decisions based solely on automated processing that produce legal or similarly significant effects for you (Article 22).
6. Retention
- Early-access submissions not converted to accounts — 90 days, then deleted.
- Account and profile data — for the duration of your access to the Service; personal data is removed within 30 days of account deletion.
- Test content you author (test scripts, scenarios, presets, suites, application catalog) — for the life of your account; removed together with account data after account deletion.
- Run artifacts and run history (screenshots, logs, reports, session records) — guaranteed to remain available for 90 days after the run, then automatically deleted (deletion completes at approximately 104 days). See the Data Retention Policy for details.
- Audit logs — 12 months (compliance window).
- Product telemetry events — 24 months, then aggregated or deleted.
- Crash reports — 12 months.
- Backups — rolling 30 days (disaster recovery).
7. Third parties (sub-processors)
We use the following sub-processors. All transfers from the EEA rely on EU Standard Contractual Clauses (SCCs) included in each provider's data processing agreement (DPA).
| Sub-processor | Purpose | Location |
|---|---|---|
| OAuth Sign-In (email, name, sub) | USA | |
| Resend | Transactional email (welcome / beta-code delivery) | USA |
| Cloudflare | Turnstile anti-spam and CDN (IP, User-Agent, challenge token) | USA |
| AWS | Hosting, database, and run-artifact storage — screenshots, logs, reports (us-east-2) | USA |
| Sentry | Crash reporting (stack traces, app and OS versions) | USA |
Stripe is listed as a planned phase 2 sub-processor for subscription billing. It is not currently receiving any user data and will not begin processing data until (a) Stripe merchant onboarding (KYC) is completed and (b) paid plans open. At that time, we will update this policy and notify existing users.
8. Your rights (GDPR)
If you are located in the EEA, the United Kingdom, or Switzerland, you have the following rights with respect to your personal data:
- Right of access (Article 15) — obtain a copy of the data we hold about you.
- Right to rectification (Article 16) — ask us to correct inaccurate data.
- Right to erasure (Article 17) — ask us to delete data when there is no longer a valid reason to process it.
- Right to data portability (Article 20) — receive your data in a structured, machine-readable format.
- Right to restriction of processing (Article 18).
- Right to object (Article 21) — including to processing based on legitimate interest.
- Right to withdraw consent at any time, without affecting processing based on consent before its withdrawal.
You also have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your residence, with the UK Information Commissioner's Office (ICO), or with the Swiss Federal Data Protection and Information Commissioner (FDPIC), as applicable.
9. Your rights (CCPA)
If you are a California resident, you have the right to know what personal information we collect about you and why, the right to correct inaccurate information, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we have not done so in the preceding 12 months. We will not discriminate against you for exercising any of these rights.
10. Your rights (México — LFPDPPP)
If you are located in México, the Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares — LFPDPPP) grants you the ARCO rights:
- Access — obtain the personal data we hold about you and the details of how we process it.
- Rectification — ask us to correct inaccurate or incomplete data.
- Cancellation — ask us to delete your personal data.
- Opposition — object to the processing of your data for specific purposes.
You may also revoke consent you have previously given, with effect for the future. This Privacy Policy serves as our privacy notice (aviso de privacidad) under the LFPDPPP. To exercise any ARCO right, follow the steps in "How to exercise your rights" below. If you believe your rights have been violated, you may file a complaint with the Secretaría Anticorrupción y Buen Gobierno, the federal supervisory authority for personal data protection in México.
11. How to exercise your rights
To exercise any of the rights above, email support@ai-powered-testing.com from the address associated with your account or early-access submission. We respond within 30 calendar days; for complex requests we may extend this period where the law allows, and we will tell you if so. We may ask you to verify your identity before acting on a request in order to protect your data from unauthorized disclosure.
12. Children
The Service is not directed to individuals under the age of 18 and we do not knowingly collect personal data from them. If you believe that we have collected data from a child under 18, please contact us at support@ai-powered-testing.com and we will delete it promptly.
13. Changes to this Policy
We may update this policy from time to time. The current version is always available at ai-powered-testing.com/legal/privacy. Material changes will be communicated by email to the email address associated with your account and/or by a banner on the Service at least 30 days before they take effect.
14. Contact
For privacy-related questions or to exercise any of the rights above, contact us at support@ai-powered-testing.com or by postal mail at the address listed under "Data controller."