Legal · Draft pending owner review
Privacy Policy
This page explains what Sybqa collects when you use it, why, who helps us process it, and how long we keep it.
Who we are
Sybqa is operated by [TODO: company legal name], [TODO: registered address]. In this policy, “we” means that company. Privacy questions: [TODO: privacy contact email].
What we collect
- Account details. Your name, email address and sign-in identifiers. Sign-in is handled by Clerk.
- Billing details. Your plan, subscription status, invoices and credit balance. Stripe collects and stores your card details; we do not see or store full card numbers.
- What you ask Sybqa to test. The target URL, your QA goal, an optional Figma link and the test plan you approve.
- Run evidence. Screenshots, optional video recordings, browser traces, network and console records, findings and reports from each run. These can contain anything the tested pages showed, including personal data if the pages displayed it.
- Usage and cost records. Credits used, model names, token counts and reported provider costs for each run.
- Server-side product events. A small set of events (plan created, run started, run finished, checkout started and completed, billing updated, free run requested, started and finished) with a hashed account or run ID. These events do not include prompts, target URLs, screenshots, email addresses or error text.
- Website analytics, only if you accept. Page views and clicks in your browser, described in “Analytics and your choice” below.
- Feedback you send. The message you write, an optional rating from 1 to 5, and the page you were on.
- Free first run. If the free first run is switched on, the public address you enter and your goal, described in “Free first run” below.
Analytics and your choice
When website analytics is switched on, Sybqa asks before it measures anything. Until you choose Accept analytics, your browser does not load the analytics code and sends nothing to our analytics provider. If your browser sends Do Not Track, we treat it as Decline and do not ask.
- What it records after you accept. Which Sybqa pages you open, which buttons and links you click, your browser and screen type, and an ID kept in your browser storage and a cookie so repeat visits connect to each other. We do not record your screen, keystrokes or form text.
- What it leaves out. The addresses of the sites you test, your QA goals, run links, report contents, API tokens and email addresses are not sent. Page addresses are sent without their query and fragment.
- How it is sent. The analytics code is served from Sybqa’s own domain, and events travel through Sybqa’s own server to PostHog. Your browser does not contact PostHog directly. [TODO: confirm whether visitor IP addresses are forwarded to PostHog in production.]
- Changing your mind. Choose Privacy choices in the page footer. Declining removes the analytics ID from your browser and stops measurement.
[TODO: confirm the legal basis for analytics and for feedback in each jurisdiction where Sybqa is offered.]
Feedback you send
Choosing Send feedback opens a form. Sending it is your action, so it works whether or not you accepted analytics. Sybqa stores the message, the rating and the page path, and forwards them to PostHog as a survey response. Do not put passwords, card numbers or other secrets in the message. If you type your email address, we may use it to reply. We do not attach your account or email on our own. [TODO: feedback retention period.]
Free first run
When the free first run is switched on, you can run one check on a public site without an account. Sybqa keeps the address you entered, your goal and the results so you can watch and open the report. The run link is a private address that only you hold; anyone with it can open the report. Sybqa stores a hash of the link, not the link itself, and a hashed form of your network address to enforce the one-run limit and block abuse. Free runs do not use AI. [TODO: retention period for free-run reports and abuse records.]
Test keys you supply
For test sign-up and payment runs, you can give Sybqa a Clerk development key and a Stripe test key. Sybqa accepts test-mode keys only. It keeps them in memory for that run and does not write them to plans, reports, logs or saved run state. The generated test password is filled in locally and is not sent to AI models or shown in reports.
How we use it
- To run the checks you request and show you the results.
- To sign you in, bill you and track your credits.
- To send run notifications you set up.
- To keep the service secure, fix problems and understand which features are used.
- To plan better checks for your own account. Sybqa keeps a short history of journey names and pass or fail counts for each site you test and uses it when planning your next run. You can pause or dismiss this history in the console. It is not shared with other accounts.
We do not sell your data. Sybqa does not train AI models on your run evidence. [TODO: confirm legal basis wording required for your jurisdiction.]
AI providers
Deterministic checks run without AI. When a run uses hosted AI, some run data goes to outside model providers:
- OpenRouter routes requests to the model providers it selects. They can receive screenshots, visible page text, page controls and your QA goal.
- TypeSafe Jev receives candidate URLs, your QA goal, and visible text and control descriptions to choose routes and approve test actions.
- Local Ollama models run on the operator’s own machine and send nothing to an outside AI provider. Hosted Sybqa does not offer this option today.
Each provider follows its own data policy. Do not point hosted AI runs at pages that show sensitive personal, health or financial data.
Service providers
| Provider | Purpose | Data |
|---|---|---|
| Fly.io | Hosting and storage | All service data, including run evidence |
| Clerk | Sign-in | Account details |
| Stripe | Payments | Billing and payment details |
| OpenRouter and its model providers | Hosted AI, when used | Screenshots, page text, QA goal |
| TypeSafe Jev | AI decisions, when used | URLs, QA goal, page text |
| Resend | Run notification email | Recipient address, run ID, outcome, report link |
| PostHog | Product analytics | Allowlisted server events and, if you accept, page views and clicks; feedback messages |
[TODO: confirm this list matches the production configuration and add data processing agreement links.]
How long we keep it
- Run evidence is kept until you or the operator delete it. Automatic deletion is not set up yet. [TODO: retention period.]
- Test keys are dropped when the run ends.
- Billing records are kept as long as tax and accounting law requires. [TODO: period.]
- Account details are kept while your account is open. [TODO: period after closure.]
Your choices and rights
You can ask to see, correct, export or delete your personal data, or close your account, by emailing [TODO: privacy contact email]. We will reply within [TODO: response time]. Depending on where you live, you may also have the right to complain to a data protection authority.
Where your data is stored: [TODO: hosting region and international transfer safeguards].
Security
Provider secrets stay on the server and are never sent to your browser. Run reports require sign-in. No system is perfectly secure. To report a security issue, email [TODO: security contact email].
Changes
We will post changes on this page and update the date above. For important changes, we will also tell account holders by email.