Legal

Privacy Policy

This policy explains what AISwarmQA collects, why, and what control you have over it. It is written to match what the product actually does today — not aspirational language — and is a draft pending professional legal review before commercial launch.

Who operates AISwarmQA

AISwarmQA is currently operated by an individual, not (yet) a registered company. The operator’s registered legal identity, business address, and governing jurisdiction are being finalized and will be published on the Imprintpage once confirmed — this does not change what data is collected or how it is protected in the meantime. For any privacy request, use the contact details below.

What we collect

Account & workspace data

When you create an account: your email address, an optional display name, and (if you sign in with Google) the identifier Supabase Auth assigns to that sign-in. We do not receive or store your password — authentication is handled by Supabase Auth. Workspace data includes the workspace name, plan, members and their roles, and an audit trail of significant actions (who did what, when) for security and accountability.

Audit & target data

The URL you submit for an audit, the pages our crawler discovers on that same origin, and the findings, screenshots, and structured observations our audit engine records while testing it. This data describes your target site’sbehavior, not your end users — we do not knowingly collect personal data belonging to visitors of the sites you audit.

Evidence

Screenshots and supporting metadata (affected URL, HTTP status, console/network error text) captured while reproducing a finding, stored in private cloud storage. See Security § Evidence privacy for access controls.

Billing data

If you subscribe to a paid plan, Stripe processes your payment details directly. We never see or store your card number — only the Stripe-issued customer, subscription, and price identifiers needed to keep your plan in sync.

GitHub export data

If you connect GitHub, we store the GitHub App installation reference and the repositories you authorize for export, and the resulting GitHub Issue URLs. We do not store a GitHub personal access token; export actions use a short-lived, server-side GitHub App installation token.

Email delivery records

A record of transactional emails sent to you (recipient address, template, delivery status) so we can confirm delivery and debug failures.

What we do not store

We do not persist your IP address. It is read transiently to enforce sign-in rate limits and is not written to our database.

Why we process it

Account, workspace, audit, evidence, and billing data are processed to provide the service you signed up for: running audits, storing your results, and billing your plan. Rate-limiting and audit-trail data are processed on the basis of our legitimate interest in keeping the service secure and abuse-free. Where a stricter regime applies to you (for example the GDPR), we intend to rely on contract performance and legitimate interest as the applicable legal bases; this section will be finalized alongside the jurisdiction noted above.

AI processing

AI-assisted audits send a sanitized snapshot of the page you asked us to test to Anthropic for planning and exploration — never cookies, localStorage, authorization headers, submitted form values, passwords, or your account data. See Security § What the AI providers see for exactly what is redacted before anything leaves our infrastructure.

Sub-processors

We share data with the following infrastructure providers, only as needed to run the service:

  • Supabase — authentication, primary database, and evidence storage. Receives account, workspace, audit, and evidence data.
  • Anthropic — AI planning and exploration. Receives a redacted page snapshot, per the AI processing section above.
  • Railway — hosts the application and worker services. Has infrastructure-level access to data in transit and at rest on its platform.
  • Stripe — billing and payment processing. Receives your payment details directly; we receive only Stripe identifiers back.
  • Resend — sends transactional email (account, billing, and security notifications). Receives your email address and the message content.
  • GitHub — only if you connect it. Receives the finding content you explicitly choose to export as an Issue.

Business-plan customers who need a signed Data Processing Addendum covering the sub-processors above can request one from ryba.aleksandr44@gmail.com; a standard template will be published here once the operator’s legal identity is finalized.

Retention

Evidence is retained according to your workspace’s plan and then deleted — including from underlying storage, not just hidden from view: 7 days on the Free plan, 90 days on Pro, and 365 days on Business (Business retention is configurable by agreement). Deletion runs on a recurring schedule once the retention window closes. Account and workspace records are kept for as long as your account or workspace exists, plus what is required for billing and legal record-keeping after that.

Your rights

The following controls exist in the product today:

  • Export your account data — available now, from your account settings.
  • Export your workspace data — available now, for workspace owners/admins: members, projects, audits, and connected repositories.
  • Revoke shared evidence — available now, per evidence item.
  • Delete a workspace— available now. Deletion is requested explicitly, is blocked while audits are running, and takes effect after a short scheduled delay rather than instantly, so it can be reversed if requested in error.
  • Delete a single user accountwithout deleting the whole workspace — not yet a self-service control. Contact us and we will handle the request manually.

Cookies

We use one essential, first-party cookie to keep you signed in (an httpOnly session cookie set by our authentication layer). We do not use advertising or third-party tracking/analytics cookies.

International transfers

Our sub-processors listed above operate infrastructure that may process data outside your own country. We rely on each provider’s own data-protection commitments and, where required, standard contractual safeguards; this section will be expanded with specifics once our own jurisdiction (above) is finalized.

Changes to this policy

As this is a draft ahead of full legal review, expect this page to change. Material changes will update the date at the top of this page.

Contact

For any privacy request — data export, deletion, or a question about this policy — email ryba.aleksandr44@gmail.com.