Legal

Privacy policy

Last updated 26 July 2026

This describes exactly what QA Spider collects, why, where it is stored and who else can touch it. We have tried to write it in plain English rather than legal padding — if anything here is unclear, ask us and we will fix the wording.

1. Who we are

QA Spider ("we") provides automated software-testing services for web applications. This policy covers the QA Spider website and the QA Spider dashboard. For any privacy question, or to exercise a right described below, email hello@qaspider.com.

2. What we collect

We collect only what the service needs to function. Specifically:

  • Account data — your name, email address and a hashed password (we never store your password in readable form). If you sign in with Google or GitHub, we receive your name, email and avatar from that provider instead.
  • Workspace data — your organisation name, team members and their roles, and invitations you send.
  • Project configuration — the URLs of the applications you ask us to test, the environments you define, and any test-account credentials you choose to store so our tests can sign in.
  • Integration credentials — the API tokens or webhook URLs you provide to connect a bug tracker or a chat tool.
  • Test results — run outcomes, timings, per-step results, error output and screenshots captured from the pages we tested, plus any bug reports generated from them.
  • Usage and billing data — your plan, token balance and a ledger of consumption events (which run or generation used what).
  • Contact submissions — the name, email and message you send through our contact form.
  • Server logs — standard technical logs, including IP address and user agent, kept for security and debugging.

3. What we do not do

  • We do not sell your personal data, and we never have.
  • We do not use advertising trackers or third-party analytics cookies on our marketing site.
  • We do not use your application data or test results to train machine-learning models.
  • We do not access your source code. We test your application from the outside, as a user would.

4. Why we process it

To provide the service you signed up for (running tests, reporting results, filing bugs to your tracker, sending alerts) — this is performance of a contract. To secure accounts, prevent abuse and debug failures — our legitimate interest. To send you the transactional emails the service depends on, such as sign-in codes and run notifications — performance of a contract. Where we ever rely on consent, such as optional marketing email, you can withdraw it at any time.

5. Test-account credentials — please read

If you store credentials so our tests can sign in to your application, use a dedicated test account with the minimum permissions needed, on a non-production environment wherever possible. Never store a real customer or administrator account.

Integration tokens for bug trackers and chat tools are encrypted at rest with AES-256-GCM. Test-account credentials are currently stored in our database without that additional layer of encryption; hardening this is on our roadmap. Until then, treat any credential you give us as one you would be comfortable rotating, and rotate it if you stop using QA Spider.

6. Where your data lives, and who else touches it

The application and its database are hosted on Render, in the EU (Frankfurt) region, on an encrypted persistent disk. We use a small set of subprocessors, each for one clearly-bounded purpose:

  • Render — application hosting and database storage (EU).
  • Anthropic — the AI model that drafts test cases, QA documents and bug reports. It receives the prompt and the product context needed for that artifact.
  • Resend — delivery of transactional email (sign-in codes, notifications, contact replies).
  • GitHub Actions — executes your test runs and reports the result back to us.
  • Firecrawl — fetches and maps the public pages of a site you ask us to analyse.
  • Browserbase — provides the hosted browser used for optional live test recording. Only used if that feature is enabled for your workspace.
  • Google and GitHub — identity providers, only if you choose to sign in with them.

7. How long we keep it

Account and workspace data are kept while your account exists. Test results, screenshots and generated bug reports are kept so your history and metrics remain meaningful; you can delete individual runs, bugs and projects at any time, and deletion is immediate. Contact-form messages are kept while we need them to answer you. Server logs are retained for a short operational period. When you close your account we delete your workspace data, retaining only what we must for legal or accounting reasons.

8. Your rights

You can access, correct, export or delete your data. Much of this is self-service in the dashboard: you can export generated documents, delete bugs, runs and projects, and manage team members. For anything else — a full export, account deletion, an objection to processing, or a complaint — email hello@qaspider.com and we will respond within 30 days. If you are in the EEA or UK you also have the right to lodge a complaint with your local data-protection authority.

9. Security

Access to the production environment is restricted to the people who operate it. Traffic is served over HTTPS. Integration tokens are encrypted at rest. Outward-facing actions — filing a ticket in your tracker, posting to your chat, running against a production-looking environment — require explicit approval in the product rather than happening silently. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you without undue delay.

10. Cookies

We use cookies that are strictly necessary: a session cookie to keep you signed in, and a preference cookie remembering your light or dark theme. We do not use advertising or cross-site tracking cookies.

11. Children

QA Spider is a business tool and is not directed at anyone under 16. We do not knowingly collect their data.

12. Changes

If we change this policy materially we will update the date above and, for changes that affect how we handle your data, notify account owners by email before the change takes effect.

Questions about this policy, or a request about your data? Email hello@qaspider.com.