Sybqa

Legal · Draft pending owner review

Privacy Policy

This page explains what Sybqa collects when you use it, why, who helps us process it, and how long we keep it.

Who we are

Sybqa is operated by [TODO: company legal name], [TODO: registered address]. In this policy, “we” means that company. Privacy questions: [TODO: privacy contact email].

What we collect

Analytics and your choice

When website analytics is switched on, Sybqa asks before it measures anything. Until you choose Accept analytics, your browser does not load the analytics code and sends nothing to our analytics provider. If your browser sends Do Not Track, we treat it as Decline and do not ask.

[TODO: confirm the legal basis for analytics and for feedback in each jurisdiction where Sybqa is offered.]

Feedback you send

Choosing Send feedback opens a form. Sending it is your action, so it works whether or not you accepted analytics. Sybqa stores the message, the rating and the page path, and forwards them to PostHog as a survey response. Do not put passwords, card numbers or other secrets in the message. If you type your email address, we may use it to reply. We do not attach your account or email on our own. [TODO: feedback retention period.]

Free first run

When the free first run is switched on, you can run one check on a public site without an account. Sybqa keeps the address you entered, your goal and the results so you can watch and open the report. The run link is a private address that only you hold; anyone with it can open the report. Sybqa stores a hash of the link, not the link itself, and a hashed form of your network address to enforce the one-run limit and block abuse. Free runs do not use AI. [TODO: retention period for free-run reports and abuse records.]

Test keys you supply

For test sign-up and payment runs, you can give Sybqa a Clerk development key and a Stripe test key. Sybqa accepts test-mode keys only. It keeps them in memory for that run and does not write them to plans, reports, logs or saved run state. The generated test password is filled in locally and is not sent to AI models or shown in reports.

How we use it

We do not sell your data. Sybqa does not train AI models on your run evidence. [TODO: confirm legal basis wording required for your jurisdiction.]

AI providers

Deterministic checks run without AI. When a run uses hosted AI, some run data goes to outside model providers:

Each provider follows its own data policy. Do not point hosted AI runs at pages that show sensitive personal, health or financial data.

Service providers

Providers that process data for Sybqa
ProviderPurposeData
Fly.ioHosting and storageAll service data, including run evidence
ClerkSign-inAccount details
StripePaymentsBilling and payment details
OpenRouter and its model providersHosted AI, when usedScreenshots, page text, QA goal
TypeSafe JevAI decisions, when usedURLs, QA goal, page text
ResendRun notification emailRecipient address, run ID, outcome, report link
PostHogProduct analyticsAllowlisted server events and, if you accept, page views and clicks; feedback messages

[TODO: confirm this list matches the production configuration and add data processing agreement links.]

How long we keep it

Your choices and rights

You can ask to see, correct, export or delete your personal data, or close your account, by emailing [TODO: privacy contact email]. We will reply within [TODO: response time]. Depending on where you live, you may also have the right to complain to a data protection authority.

Where your data is stored: [TODO: hosting region and international transfer safeguards].

Security

Provider secrets stay on the server and are never sent to your browser. Run reports require sign-in. No system is perfectly secure. To report a security issue, email [TODO: security contact email].

Changes

We will post changes on this page and update the date above. For important changes, we will also tell account holders by email.