Privacy Policy
Last updated: July 10, 2026
What we collect
Account data: your email address and hashed password (or GitHub identity if you sign in that way).
Run data you send: whatever your SDK integration records — task inputs, agent steps, tool calls, screenshots, outputs, costs. You control this entirely, including redaction before upload.
Product analytics: which features are used (signups, first traces, suite runs), via PostHog. No run content is ever included in analytics events.
How we use it
To run the service: storing traces, evaluating runs (run excerpts are sent to Anthropic’s Claude API for judging — Anthropic does not train on this API data), and rendering your dashboards. To improve the product: anonymized, aggregated failure patterns only, as described in the Terms — opt out any time.
Who else touches your data
Our processors: Supabase (database, auth, file storage), Vercel (hosting), Anthropic (evaluation judging), PostHog (analytics), Resend (email), Sentry (error reporting — configured to scrub run content and credentials). We never sell your data and never share it beyond these processors.
Retention and deletion
Screenshots: 90 days by default. Run data: until you delete it. Deleting a project removes its data permanently. Full account deletion: email hello@agentqa.dev and we complete it within 30 days, including backups on their rotation schedule.
Your rights
You can export your data (CSV per suite run, or ask us for a full export), correct it, delete it, or object to processing. If you’re in the EU/UK, these are your GDPR rights and we honor them for everyone regardless of location.
Security
Row-level tenant isolation enforced in the database, API keys stored as SHA-256 hashes, screenshots in private storage behind short-lived signed URLs, and share links that expose only aggregate results. Report security issues to hello@agentqa.dev.