Skip to main content

Privacy Policy

Last Updated: 16 June 2026

1. Introduction

Welcome to www.qaeverest.ai (hereinafter referred to as "QAEverest", "we", "our", and "us"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our platform, applications, public APIs, and related services (collectively, the "Services"). Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the Services.

2. Information We Collect

Personal Information

While using our Services, we may ask you to provide certain personally identifiable information that can be used to contact or identify you ("Personal Data"). This may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, State, Province, ZIP/Postal code, City
  • Profile information
  • Billing and company details, such as company name, billing address, and tax/GST identifiers

Account & Authentication Data

If you sign in using a third-party identity provider (such as Google or GitHub) or via enterprise Single Sign-On (SSO/SAML), we receive profile information from that provider, such as your name, email address, and, where applicable, your role. Enterprise accounts may be provisioned automatically based on assertions from your organisation's identity provider.

Technical & Usage Information

We also collect information automatically, including but not limited to:

  • Usage data (e.g., pages visited, features used, time spent)
  • Device information (e.g., browser type, operating system)
  • Cookies and tracking technologies
  • IP address and approximate geographic location (e.g., country)

Content You Provide

To deliver the Services, we collect and store the content you submit, including user stories and requirements, generated and uploaded test cases and suites, uploaded files and images, and execution reports.

Customer Application Data

When you use our automation, visual, and self-maintaining features, the Services may load, crawl, screenshot, and record the applications and pages you direct them to. This may include screenshots, DOM/HTML data, crawl snapshots, visual-regression baselines, and execution recordings or replays of your applications. You are responsible for ensuring you have the right to submit such applications for processing.

Integration Credentials

When you connect a third-party integration (such as Jira, Confluence, Azure DevOps, GitHub, GitLab, Bitbucket, Jenkins, ClickUp, or Slack), we store the credentials, tokens, or API keys you provide so we can access that service on your behalf.

API Keys, Audit & Usage Logs

If you use our public API or MCP server, we collect and store API key identifiers and associated usage metrics. For organisation and enterprise accounts, we also maintain audit logs and usage records of actions performed within the Services.

3. Use of Information

We use the collected information for various purposes, including:

  • To provide, maintain, and operate the Services
  • To process transactions and manage subscriptions and credits
  • To execute the automation, testing, and AI features you request
  • To notify you about changes, updates, and notifications
  • To provide customer support
  • To gather analysis and insights so that we can improve the Services
  • To monitor usage and maintain security and audit logs
  • To detect, prevent, and address technical issues, fraud, and abuse

4. AI Processing & Model Training

The Services use artificial intelligence to process your content and generate output. To do so, content such as user stories, requirements, test cases, DOM/HTML data, and screenshots of your applications may be transmitted to and processed by our AI providers.

5. Third-Party Service Providers & Sub-Processors

We engage third-party companies to facilitate, provide, and improve the Services. These third parties have access to your Personal Data only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose. Our key categories of sub-processors include:

AI Providers

We use one or more AI/LLM providers (which, depending on configuration, may include Anthropic Claude, including vision models, Amazon Web Services (Bedrock), and other AI providers) to deliver AI features. Your content, including screenshots and DOM data of your applications, may be processed by these providers to provide the requested Services.

Payment Gateway

We use a third-party payment gateway (such as Razorpay) to process payments. Your payment and billing information is collected and processed by the payment provider in accordance with its privacy policy and security measures.

Cloud Storage & Infrastructure

We store data using third-party cloud storage and database services (such as Google Cloud Storage and managed database providers). Stored data may include the categories described in Section 2.

Authentication & Email

We use third-party authentication providers (such as Google and GitHub OAuth, and enterprise SAML identity providers) for sign-in, and email/SMTP providers to send transactional and notification emails.

Connected Integrations

When you connect integrations, data may flow between the Services and those third-party tools using the credentials you provide. Your use of any third-party service is governed by that service's own privacy policy.

6. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to operate and secure the Services, remember your preferences, keep you signed in, and analyse usage. You can control or disable cookies through your browser settings; however, some features of the Services may not function properly without them.

7. Organisations & Multi-Tenancy

If you use the Services as part of an organisation, your organisation's administrators may be able to access, manage, and monitor your account, activity, projects, and audit logs, and may manage your access and roles. Data created within an organisation may be accessible to authorised members of that organisation according to their assigned roles.

8. International Data Transfers

Your information may be processed and stored in countries other than your own, including by our sub-processors. Where data is transferred across borders, we take steps to ensure appropriate safeguards are in place.

9. Legal Bases for Processing

Where applicable law (such as the GDPR) requires, we process your Personal Data on legal bases including the performance of a contract, your consent, our legitimate interests, and compliance with legal obligations.

10. Security and Data Retention

We value your trust and strive to use commercially acceptable means of protecting your information, including encryption and access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

We retain your data, including test data, reports, screenshots, recordings, integration credentials, and audit logs, for as long as your account is active or as needed to provide the Services, and thereafter as required by law. When data is no longer needed, we will securely delete or anonymise it.

11. Data Breach Notification

In the event of a data breach affecting your Personal Data, we will notify affected users and relevant authorities where required by applicable law.

12. Disclosure of Data

We may disclose personal information that we collect, or that you provide:

  • Disclosure for Law Enforcement. Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.
  • Business Transaction. If we or our subsidiaries are involved in a merger, acquisition, or asset sale, your Personal Data may be transferred.

13. Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal data:

  • The right to access – to request copies of your personal data.
  • The right to rectification – to request correction of inaccurate or incomplete data.
  • The right to erasure – to request deletion of your personal data.
  • The right to restrict or object to processing.
  • The right to data portability.
  • The right to withdraw consent at any time.
  • The right to lodge a complaint with a data protection supervisory authority.

If you are a California resident, you may also have rights under the CCPA/CPRA, including the right to know, delete, and opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information.

14. User Choices and Access

You have the right to access, update, or delete your personal information. You can:

  • Review and update your profile information through your account settings.
  • Request the deletion of your account and all associated data by contacting us at support@qaeverest.com.
  • Opt out of receiving marketing emails by following the unsubscribe link in the emails.

15. Children's Privacy

The Services are intended for business and professional use and are not directed to children. We do not knowingly collect personal information from children under the age of 16. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us so that we can delete such information.

16. Changes to this Policy

We reserve the right to update this Privacy Policy at any time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date above. You are advised to review this Privacy Policy periodically for any changes.

17. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: support@qaeverest.com