Skip to content

Legal

Privacy Policy

Last updated: July 2026

1. What we collect

When you create a QAMind AI account, we collect your email address and a hashed password. If you sign in via a third-party provider (e.g. Google), we receive only your email and public profile name — no password is stored.

When you use the product, we store the data you create: test cases, test suites, run results, bug reports, and recordings. This data is stored on your behalf and is not read by QAMind staff except to diagnose a support request you have explicitly opened.

We collect standard server logs: IP address, browser user-agent, timestamp, and the URL requested. These are retained for 30 days for security and debugging purposes.

2. How we use your data

Your data is used to provide and improve QAMind AI. Specifically:

  • To authenticate your account and maintain your session.
  • To run the AI test generation features you invoke.
  • To send transactional emails (password reset, email verification).
  • To send the product update newsletter, if you have opted in.
  • To diagnose errors and improve reliability.

We do not sell your data. We do not use your test cases or bug reports to train AI models without your explicit written consent.

3. Cookies and tracking

QAMind AI uses a single session cookie to keep you logged in. We do not use third-party advertising trackers, pixel tags, or cross-site tracking cookies.

We use a privacy-respecting analytics tool (no personal identifiers, no fingerprinting) to understand aggregate usage patterns — for example, which features are used most. This data is anonymised and cannot be tied back to your account.

4. Data sharing

We share your data with the following categories of sub-processors only as necessary to operate the service:

  • Cloud infrastructure — hosting, database, and object storage.
  • Email delivery — transactional email (account, invites, verification) and, if you opt in, product newsletter email.
  • Email marketing platform (Loops) — if you create an account or subscribe to the newsletter, we share your email address (and optional name) with Loops so we can send welcome messages, signup notifications to our team, and newsletter campaigns you opted into. You can unsubscribe from marketing emails at any time via the link in those messages or by emailing us.
  • AI inference — by default, test generation and AI chat are processed by third-party AI providers (OpenAI and Anthropic) over encrypted connections; the content you submit for generation (requirement documents, recordings, test case text) is shared with those providers solely to produce the output. Workspaces running the self-hosted mode process this content on local models instead, and it is not transmitted to any external AI service.

We do not sell your data to brokers or advertising networks. Newsletter enrollment is opt-in only (signup checkbox or the marketing subscribe form).

5. Browser extension (QA Mind Recorder)

The QA Mind Recorder Chrome extension is covered by this policy. It records a browser session only when you explicitly start a recording from the extension popup, and only in the tab(s) you choose. Nothing is captured when a recording is not running. Using the extension requires a QAMind account and at least one project so recordings can sync to your workspace; the extension does not create accounts itself — signup and project creation happen on qamind.ai / app.qamind.ai.

While recording, the extension captures:

  • Interactions you perform — clicks, typing, navigation, and dropdown selections.
  • Element metadata used to build stable test locators — tag, id, name, accessibility label, visible text, and XPath/CSS selector.
  • The URL, path, and title of recorded pages. Query strings are stripped before storage.
  • Values you type into ordinary fields (for example an email address or search term), so generated test steps contain realistic test data. Free text is additionally masked for common personal identifiers.
  • Network request metadata (URL, method, status code, duration) and console errors, so failing API calls can be attached to a defect report.

Credentials are never captured. Values entered into password fields, one-time-code fields, and payment card fields are replaced with [REDACTED] inside the extension before anything is stored or transmitted. This applies to fields identified by type, by autocomplete attribute, and by naming hints — including password fields that a site reveals as plain text via a “show password” toggle. Your real password, OTP, card number, or API key never leaves your browser.

Recorded data is held in local browser storage on your machine and sent over HTTPS only to your own QAMind workspace. The extension communicates with no other destination — there are no third-party scripts, no analytics, no telemetry, no advertising identifiers, and no fingerprinting. It has no external dependencies.

The extension requests these browser permissions, and only for these purposes:

  • Storage — keep an in-progress recording on your device so it survives a browser restart.
  • Tabs — track which tab is being recorded and follow navigations within it.
  • Scripting — run the recorder inside the page you chose to record.
  • Context menus — provide the right-click “copy locator” action.
  • Web request (read-only) — observe request status and duration during a recording. Requests are never modified or blocked, and request bodies are never read.
  • Downloads (optional) — requested only at the moment you export a recording as a file; not granted at install.
  • Access to websites — the extension must work on whichever application you are testing, and that address cannot be known in advance. This access is used solely during a recording you started.

Recordings appear in your QAMind workspace and can be deleted there at any time. Removing the extension clears its local storage. If you record sessions of an application that contains other people’s data, you remain the controller of that content and we process it on your behalf.

6. Data retention

Your account data is retained for as long as your account is active. If you delete your account, all associated test cases, runs, bugs, and recordings are permanently deleted within 30 days. Server logs are deleted after 30 days on a rolling basis.

7. Your rights

You have the right to access, correct, export, or delete your personal data at any time. To exercise any of these rights, email us at info@qamind.ai. We will respond within 14 days.

If you are in the EU or UK, you have additional rights under GDPR / UK GDPR including the right to lodge a complaint with your local supervisory authority.

8. Security

Passwords are hashed using bcrypt. Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted at the storage layer. We conduct periodic security reviews and patch known vulnerabilities promptly.

Despite these measures, no system is fully immune to breach. If a breach affects your personal data, we will notify you within 72 hours of becoming aware of it.

9. Changes to this policy

We will update this policy as the product evolves. Material changes will be communicated via email to registered users at least 14 days before taking effect. The current version is always available at this URL.

10. Contact

Questions or requests: info@qamind.ai