Privacy Policy

How AlwaysQA handles personal data, cookies, AI processing, US privacy rights, and data retention.

Last updated: July 8, 2026

This Privacy Policy explains how Maciej Chmura IdeaUnlock, operating the AlwaysQA service (“AlwaysQA”, “we”, “us”, “our”), collects, uses, stores, shares, and protects personal data when you visit our website, create an account, use our agent-first post-deploy QA service, communicate with us, or interact with our marketing content.

We are established in Poland and process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Polish data protection laws, applicable rules on electronic communications and cookies, and, where applicable, selected privacy requirements under United States laws, including California privacy laws.

This Privacy Policy is designed to cover the following areas:

  1. Privacy Policy
  2. Cookie Policy
  3. US / California Privacy Notice
  4. AI Processing
  5. Data Retention

This Privacy Policy does not replace any separate Data Processing Agreement (“DPA”) that may apply when we process Customer Content on behalf of business customers.


1. Privacy Policy

1.1 Who we are

The data controller for personal data covered by this Privacy Policy is:

Maciej Chmura IdeaUnlock ul. Tadeusza Kościuszki 1 32-020 Wieliczka Poland NIP / VAT ID: 8652425764 REGON: 18070444800000 Email: hello@alwaysqa.com

For privacy questions, data subject requests, security issues, DPA requests, or complaints, contact us at:

hello@alwaysqa.com

If we appoint a Data Protection Officer or a dedicated privacy contact in the future, we will update this Privacy Policy.


1.2 Scope of this Privacy Policy

This Privacy Policy applies to personal data we process when you:

  • visit our website;
  • create or manage an account;
  • use AlwaysQA;
  • use our dashboard, API, CLI, MCP integration, coding-agent integration, or other product interfaces;
  • subscribe to updates or marketing communications;
  • contact us for support, sales, or partnership purposes;
  • purchase a subscription, usage plan, credits, or other paid service.

This Privacy Policy also explains how we treat Customer Content processed through AlwaysQA.

When a customer uses AlwaysQA to test their own application, website, software, workflows, or environments, the customer usually decides what data is submitted to the service and why. In that context, the customer is generally the data controller, and we usually act as a data processor or sub-processor, subject to our DPA.


1.3 Definitions

“Personal Data” means any information relating to an identified or identifiable natural person.

“Customer” means an organization, business, developer, or individual who creates an account or uses AlwaysQA.

“User” means a person using our website, dashboard, API, MCP integration, CLI, agent integration, or any other interface of the service.

“Customer Content” means data submitted to, generated by, or processed through AlwaysQA by or on behalf of a Customer. This may include URLs, critical-flow instructions, check definitions, check versions, screenshots, videos, console logs, network logs, error logs, browser traces, deployment history, test results, issue reports, uploaded bug lists or CSVs, triage data, application metadata, and related information generated during post-deploy QA.

“Service Data” means technical, usage, diagnostic, security, and operational data generated by the use of AlwaysQA.

“Sub-processor” means a third-party service provider that processes personal data on our behalf.


1.4 What personal data we collect

Account data

When you create or manage an account, we may collect:

  • name;
  • email address;
  • company name;
  • role or job title;
  • password or authentication data;
  • workspace, team, or organization details;
  • account preferences;
  • authentication provider details if you use third-party login;
  • billing plan and subscription status;
  • IP address and login timestamps;
  • security and audit logs related to your account.

Billing and payment data

When you purchase a subscription, usage plan, credits, or paid service, we may process:

  • billing name;
  • company name;
  • billing address;
  • VAT/tax number;
  • payment status;
  • invoice details;
  • transaction identifiers;
  • subscription plan;
  • payment method metadata.

We do not intentionally store full payment card numbers. Payment card processing is handled by our payment provider, such as Stripe or another payment processor. The payment provider may process payment data under its own privacy policy and security standards.

Website and device data

When you visit our website or use the service, we may automatically collect:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referring URL;
  • pages visited;
  • date and time of access;
  • approximate location derived from IP address;
  • language settings;
  • cookie identifiers;
  • session data;
  • interactions with the website or dashboard;
  • error and performance data.

Product usage and diagnostic data

To operate, secure, and improve AlwaysQA, we may collect:

  • test execution metadata;
  • project and environment metadata;
  • API usage logs;
  • MCP, CLI, and agent integration usage data;
  • feature usage data;
  • performance metrics;
  • failure reports;
  • queue and worker execution data;
  • system logs;
  • security events;
  • rate limit and abuse prevention data.

Customer Content

Depending on how you configure AlwaysQA, Customer Content may include:

  • application URLs;
  • staging or production environment URLs;
  • user-provided testing instructions;
  • generated or uploaded check definitions;
  • uploaded bug lists or CSVs for regression validation;
  • Playwright or other test scripts;
  • screenshots and videos of test runs;
  • console logs;
  • network logs;
  • browser traces;
  • HTML snapshots;
  • error messages;
  • application state visible during testing;
  • issue descriptions;
  • customer-provided credentials or test accounts;
  • comments, prompts, and AI-generated QA analysis;
  • files or metadata submitted for issue triage.

Customer Content may contain personal data if the tested application displays or processes personal data. You are responsible for ensuring that you have the right to submit such data to AlwaysQA and that your use of the service complies with applicable privacy laws.

You should avoid submitting real personal data, sensitive personal data, production secrets, payment card data, health data, government identifiers, or confidential information unless it is strictly necessary and covered by an appropriate agreement with us.

Communications and support data

When you contact us, request a demo, submit a support ticket, join a waitlist, respond to a survey, or communicate with us by email, chat, or other channels, we may collect:

  • name;
  • email address;
  • company;
  • message content;
  • attachments;
  • support history;
  • diagnostic information you provide;
  • records of our communication with you.

Marketing data

If you subscribe to our newsletter, download materials, join a waitlist, request product updates, or interact with our marketing campaigns, we may collect:

  • name;
  • email address;
  • company;
  • role;
  • marketing preferences;
  • campaign source;
  • email engagement data;
  • consent records.

You can unsubscribe from marketing emails at any time by using the unsubscribe link or contacting us at hello@alwaysqa.com.


1.5 How we use personal data

We use personal data for the following purposes:

To provide the service

We process personal data to:

  • create and manage user accounts;
  • authenticate users;
  • provide access to AlwaysQA;
  • run post-deploy QA checks;
  • generate QA results and deployment history;
  • create screenshots, videos, logs, and reports;
  • manage projects, environments, and integrations;
  • provide MCP, API, CLI, agent, and dashboard functionality;
  • send service notifications;
  • maintain service availability.

To perform our contract with you

We process data necessary to:

  • provide paid and free services;
  • manage subscriptions;
  • process payments;
  • issue invoices;
  • provide support;
  • communicate about your account;
  • enforce our Terms of Service;
  • manage customer relationships.

To secure and protect the service

We process data to:

  • detect and prevent fraud, abuse, spam, and unauthorized access;
  • monitor suspicious activity;
  • secure accounts and infrastructure;
  • troubleshoot technical issues;
  • maintain logs for security and audit purposes;
  • protect our rights, users, systems, and business.

To improve and develop the service

We may use data to:

  • understand how users interact with AlwaysQA;
  • improve user experience;
  • debug failures;
  • improve test reliability;
  • develop new features;
  • improve documentation;
  • measure performance;
  • identify product issues.

Where possible, we use aggregated, anonymized, or de-identified data for analytics and product improvement.

To communicate with you

We may use contact data to:

  • respond to inquiries;
  • provide support;
  • send important service notices;
  • send security alerts;
  • notify you about changes to our terms or policies;
  • invite you to product feedback calls;
  • send administrative messages.

For marketing

Where permitted by law, we may use personal data to:

  • send newsletters;
  • send product updates;
  • invite you to webinars or demos;
  • provide educational content;
  • measure campaign performance;
  • personalize marketing content.

You can opt out of marketing communications at any time.

To comply with law

We may process and retain data where necessary to:

  • comply with tax, accounting, and business record obligations;
  • respond to lawful requests from public authorities;
  • establish, exercise, or defend legal claims;
  • comply with applicable EU, Polish, US, or other legal obligations.

If GDPR applies, we rely on the following legal bases:

PurposeLegal basis
Creating and managing your accountPerformance of a contract
Providing AlwaysQA servicesPerformance of a contract
Processing Customer Content on behalf of a customerCustomer’s instructions under a DPA; performance of contract
Billing, payments, invoices, accountingPerformance of a contract; legal obligation
Security, fraud prevention, abuse preventionLegitimate interests; legal obligation where applicable
Product analytics and service improvementLegitimate interests; consent where required
Support and customer communicationPerformance of a contract; legitimate interests
Marketing to existing customersLegitimate interests, where permitted; consent where required
Newsletter and optional marketingConsent
Non-essential cookies and tracking technologiesConsent
Legal claims and complianceLegal obligation; legitimate interests

Where we rely on legitimate interests, we balance our interests against your rights and freedoms.

Where we rely on consent, you may withdraw consent at any time. Withdrawal of consent does not affect processing that occurred before the withdrawal.


1.7 Customer Content and our role as processor

When you use AlwaysQA to test your own application, website, software, workflows, or environments, Customer Content is usually processed on your behalf. In that context:

  1. you decide what Customer Content is submitted;
  2. you decide the purpose of testing;
  3. you are responsible for the lawfulness of the data submitted;
  4. we process Customer Content only to provide, secure, maintain, and improve the service, or as otherwise instructed by you;
  5. we do not sell Customer Content;
  6. we do not use Customer Content for third-party advertising;
  7. we do not intentionally disclose Customer Content except as needed to provide the service, comply with law, or protect the service;
  8. we apply technical and organizational measures to protect Customer Content.

If Customer Content includes personal data, our DPA governs the processing of that data. Customers should sign or accept our DPA before submitting personal data through the service.


1.8 Customer responsibility for end-user data

If you use AlwaysQA to test an application that contains data relating to your own users, customers, employees, contractors, or other individuals, you are responsible for:

  • having a lawful basis to process that data;
  • informing those individuals where required;
  • configuring the service appropriately;
  • avoiding unnecessary personal data in test environments;
  • using test or synthetic data where possible;
  • avoiding special category data unless necessary and legally permitted;
  • managing credentials and test accounts securely;
  • responding to data subject requests related to Customer Content;
  • entering into a DPA with us where required.

We will provide reasonable assistance as described in our DPA.


1.9 Sensitive data and prohibited data

AlwaysQA is not designed to process highly sensitive data unless expressly agreed in writing.

You must not submit the following data unless we have agreed appropriate safeguards in a separate written agreement:

  • health data;
  • biometric data;
  • genetic data;
  • racial or ethnic origin data;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • sex life or sexual orientation data;
  • government identifiers;
  • children’s data;
  • payment card numbers;
  • bank login credentials;
  • private keys;
  • production secrets;
  • passwords not intended for test automation;
  • data subject to special regulatory regimes.

If you need to test workflows involving sensitive data, you should use anonymized, pseudonymized, masked, or synthetic data whenever possible.


1.10 How we share personal data

We do not sell personal data in the traditional sense.

We may share personal data with the following categories of recipients:

Service providers and sub-processors

We use trusted service providers to help us operate AlwaysQA, including providers for:

  • cloud hosting and infrastructure;
  • databases and storage;
  • email delivery;
  • payment processing;
  • analytics;
  • error monitoring;
  • logging and observability;
  • customer support;
  • authentication;
  • security;
  • AI model processing;
  • communication tools;
  • billing and accounting.

These providers may process personal data only as necessary to provide services to us and must protect the data under appropriate contractual obligations.

A current list of sub-processors should be made available in our DPA or on a dedicated sub-processors page.

Customer-controlled integrations

If you connect AlwaysQA with third-party tools, such as GitHub, GitLab, Slack, Linear, Jira, CI/CD tools, cloud platforms, MCP clients, coding agents, or other integrations, we may share data with those tools according to your configuration and instructions.

You are responsible for reviewing the privacy and security practices of third-party tools you choose to connect.

Legal and compliance recipients

We may disclose personal data if we believe it is necessary to:

  • comply with applicable law;
  • respond to lawful requests;
  • protect the rights, property, or safety of AlwaysQA, our users, or others;
  • investigate fraud, abuse, or security incidents;
  • enforce our Terms of Service;
  • establish, exercise, or defend legal claims.

Business transfers

If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, personal data may be transferred as part of that transaction. We will take reasonable steps to ensure that the recipient continues to protect the data.


1.11 International data transfers

We are based in Poland and may process personal data in the European Economic Area.

Some of our service providers may process personal data outside the EEA, including in the United States or other countries that may not provide the same level of data protection as the EEA.

Where required, we use appropriate safeguards for international transfers, such as:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses;
  • transfer impact assessments where appropriate;
  • contractual, technical, and organizational safeguards;
  • encryption and access controls where appropriate.

If you need more information about international transfer safeguards, contact us at hello@alwaysqa.com.


1.12 Security

We use reasonable technical and organizational measures designed to protect personal data and Customer Content against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

These measures may include:

  • encryption in transit;
  • encryption at rest where appropriate;
  • access controls;
  • authentication safeguards;
  • role-based permissions;
  • audit logs;
  • secure infrastructure configuration;
  • vulnerability management;
  • backup procedures;
  • monitoring and alerting;
  • least-privilege access;
  • confidentiality obligations for personnel and contractors.

No system is completely secure. You are responsible for securing your own account credentials, test environments, integrations, API keys, access tokens, and test credentials.

If you believe your account or data may have been compromised, contact us immediately at hello@alwaysqa.com.

Where required by applicable law, we will notify affected customers, users, and/or supervisory authorities about personal data breaches.


1.13 Your GDPR rights

If GDPR applies to you, you may have the following rights:

  1. Right of access — to obtain confirmation whether we process your personal data and receive a copy of that data.
  2. Right to rectification — to correct inaccurate or incomplete data.
  3. Right to erasure — to request deletion of your personal data in certain circumstances.
  4. Right to restriction of processing — to ask us to limit processing in certain circumstances.
  5. Right to data portability — to receive certain data in a structured, commonly used, machine-readable format.
  6. Right to object — to object to processing based on legitimate interests or direct marketing.
  7. Right to withdraw consent — where processing is based on consent.
  8. Right to lodge a complaint — with a supervisory authority.

To exercise your rights, contact us at hello@alwaysqa.com.

We may need to verify your identity before responding. We will respond within the time required by applicable law.

If you are in Poland or believe your rights under GDPR have been violated, you may lodge a complaint with the Polish supervisory authority:

President of the Personal Data Protection Office Urząd Ochrony Danych Osobowych ul. Stanisława Moniuszki 1A 00-014 Warszawa Poland Website: https://uodo.gov.pl


1.14 Children

Our website and service are intended for business and professional users. They are not intended for children.

We do not knowingly collect personal data from children under 16, or under a higher age where required by local law. If you believe that a child has provided us with personal data, contact us at hello@alwaysqa.com, and we will take appropriate steps to delete the data.


Our website and service may contain links to third-party websites, services, documentation, integrations, or tools.

We are not responsible for the privacy practices of third parties. You should review their privacy policies before using them.


2.1 What are cookies?

Cookies are small text files stored on your device when you visit a website. We may also use similar technologies, such as local storage, pixels, tags, and analytics identifiers.

This Cookie Policy explains how we use cookies and similar technologies on our website and within AlwaysQA.


2.2 Types of cookies we use

We may use the following categories of cookies:

Strictly necessary cookies

These cookies are required for the website and service to function. They may support:

  • login and authentication;
  • session management;
  • security;
  • fraud prevention;
  • load balancing;
  • account access;
  • cookie consent preferences.

These cookies cannot usually be disabled through our cookie banner because they are necessary for the service to work.

Functional cookies

These cookies help us remember your choices, such as:

  • language preferences;
  • region;
  • interface settings;
  • dashboard preferences.

Analytics cookies

These cookies help us understand how visitors and users interact with our website and service. We may use them to:

  • measure website traffic;
  • understand product usage;
  • detect performance issues;
  • improve user experience;
  • analyze conversion and onboarding flows.

In the EU/EEA/UK, we use analytics cookies only where legally permitted and, where required, only after consent.

Marketing cookies

These cookies may be used to:

  • measure marketing campaigns;
  • understand conversions from ads or content;
  • personalize marketing;
  • support retargeting or advertising campaigns.

In the EU/EEA/UK, we use marketing cookies only after consent where required by law.


Where required by law, especially in the EU/EEA/UK, we ask for your consent before placing non-essential cookies or similar technologies on your device.

Our cookie banner should allow you to:

  • accept all optional cookies;
  • reject all non-essential cookies;
  • customize cookie choices by category;
  • change or withdraw your consent later.

You can also manage cookies through your browser settings. Blocking certain cookies may affect how the website or service works.


You can change your cookie preferences through our cookie settings link, where available:

Cookie Settings

If the cookie settings link is not available in your browser or region, you can contact us at hello@alwaysqa.com.


We should maintain a current cookie list in our cookie banner or cookie settings interface.

The cookie list should identify, where applicable:

  • cookie name;
  • provider;
  • purpose;
  • category;
  • duration;
  • whether the cookie is first-party or third-party.

2.6 Do Not Track and Global Privacy Control

Some browsers offer “Do Not Track” signals. Because there is no uniform industry standard for responding to all such signals, we may not respond to every Do Not Track signal.

Where legally required, including under applicable California privacy laws, we will honor valid opt-out preference signals such as Global Privacy Control for activities that qualify as “sale” or “sharing” of personal information.


3. US / California Privacy Notice

3.1 Applicability

We are based in Poland, but some users may access our website or service from the United States.

Certain United States privacy laws may not apply to us unless we meet their applicability thresholds. Where such laws apply, we will honor applicable privacy rights.

This section provides additional information for users in the United States, including California residents.


3.2 Notice at collection

We may collect the categories of personal information described in this Privacy Policy for the purposes described above, including to:

  • provide and secure the service;
  • create and manage accounts;
  • process payments and invoices;
  • provide support;
  • improve the product;
  • send service communications;
  • send marketing communications where permitted;
  • comply with legal obligations.

We do not intentionally sell Customer Content.

We do not use Customer Content for third-party advertising.


3.3 Categories of personal information we may collect

In the last 12 months, we may have collected the following categories of personal information:

CategoryExamples
IdentifiersName, email address, IP address, account ID, billing details
Commercial informationSubscription plan, purchases, payment status, invoice records
Internet or network activityWebsite usage, log data, device data, cookie identifiers, service usage
Geolocation dataApproximate location derived from IP address
Professional informationCompany, role, job title
InferencesProduct interests, usage patterns, marketing preferences
Sensitive personal informationAccount login credentials, where processed for account access and security

We do not intentionally collect sensitive personal information for the purpose of inferring characteristics about you.


3.4 Sources of personal information

We may collect personal information from:

  • you directly;
  • your employer or organization;
  • your use of the website or service;
  • connected integrations;
  • payment providers;
  • analytics providers;
  • communication tools;
  • publicly available business sources;
  • marketing partners, where permitted.

3.5 Disclosure of personal information

We may disclose personal information to:

  • service providers;
  • sub-processors;
  • payment processors;
  • hosting providers;
  • analytics providers;
  • support tools;
  • communication providers;
  • professional advisers;
  • public authorities where required by law;
  • business transaction recipients.

3.6 Sale or sharing

We do not sell personal information for money.

We do not use Customer Content for cross-context behavioral advertising.

If our use of marketing or analytics technologies is considered “sharing” or “sale” under applicable California privacy laws, you may opt out by using our cookie settings, Global Privacy Control, or contacting us at hello@alwaysqa.com.


3.7 California privacy rights

California residents may have the right to:

  • know what personal information we collect, use, disclose, sell, or share;
  • access personal information;
  • delete personal information;
  • correct inaccurate personal information;
  • opt out of sale or sharing;
  • limit the use and disclosure of sensitive personal information;
  • not be discriminated against for exercising privacy rights.

To exercise these rights, contact us at hello@alwaysqa.com.

Authorized agents may submit requests on behalf of California residents where permitted by law. We may require proof of authorization and verification of identity.


3.8 Other US state privacy rights

Depending on your state of residence and whether a particular privacy law applies to us, you may have rights to:

  • access personal information;
  • correct inaccurate personal information;
  • delete personal information;
  • obtain a copy of personal information;
  • opt out of certain processing, including targeted advertising, sale, or profiling;
  • appeal a decision regarding your privacy request.

You may submit a request at hello@alwaysqa.com.

We may verify your identity before fulfilling your request.


4. AI Processing

4.1 How AlwaysQA uses AI

AlwaysQA may use AI systems to help generate, execute, analyze, summarize, or triage QA tests, issues, logs, screenshots, videos, browser traces, and related Customer Content.

AI features may be used to:

  • generate test cases from user instructions;
  • convert natural language instructions into executable tests;
  • analyze failed test runs;
  • summarize errors;
  • triage issue reports;
  • compare expected and actual behavior;
  • suggest potential causes of failures;
  • prepare reports for developers or teams;
  • support coding-agent, MCP, CLI, and API workflows.

4.2 AI providers and infrastructure

Depending on your configuration, AI processing may be performed by:

  • our own systems;
  • third-party AI model providers;
  • cloud infrastructure providers;
  • customer-selected providers or integrations.

Where we use third-party AI providers as sub-processors, we will take reasonable steps to ensure that appropriate contractual, confidentiality, security, and data protection safeguards are in place.


4.3 No AI training on Customer Content

We do not use Customer Content to train our general-purpose AI models.

We do not permit third-party AI model providers to use Customer Content to train their general-purpose AI models, unless the Customer has expressly enabled such use or agreed to it in writing.

We may use aggregated, anonymized, or de-identified technical information to improve the reliability, performance, security, and usability of AlwaysQA, provided that such information does not identify a Customer, User, or individual.


4.4 Customer responsibility when using AI features

Customers are responsible for ensuring that Customer Content submitted to AI-powered features is lawful and appropriate.

Customers should not submit sensitive personal data, secrets, credentials, private keys, payment card data, health data, regulated data, or confidential information to AI-powered features unless they have verified that the relevant configuration, provider, and agreement are appropriate for such data.

Where possible, Customers should use:

  • test data;
  • synthetic data;
  • anonymized data;
  • pseudonymized data;
  • masked production data;
  • dedicated test accounts.

4.5 AI outputs

AI-generated outputs may be inaccurate, incomplete, or require human review.

You are responsible for reviewing AI-generated check definitions, reports, summaries, issue triage, and recommendations before relying on them in production, legal, security, compliance, or business-critical contexts.

AlwaysQA is a QA assistance and automation tool. It does not guarantee that your application is error-free, secure, compliant, or free from defects.


4.6 MCP, agent, CLI, and API usage

AlwaysQA may be used through MCP, coding agents, API clients, command-line tools, or other developer workflows.

When you use these interfaces, we may process:

  • API keys or tokens;
  • authentication metadata;
  • prompts or commands sent to AlwaysQA;
  • test instructions;
  • generated responses;
  • execution logs;
  • connected project metadata;
  • user and workspace identifiers;
  • rate limit data;
  • security logs.

You are responsible for managing access to API keys, MCP clients, coding agents, connected tools, and automation workflows.


5. Data Retention

5.1 General retention rule

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

We may retain certain information longer where necessary to:

  • comply with legal obligations;
  • resolve disputes;
  • prevent fraud or abuse;
  • enforce agreements;
  • maintain security;
  • comply with tax, accounting, or business record obligations;
  • establish, exercise, or defend legal claims.

5.2 Default retention periods

Unless a different retention period is stated in your plan, product settings, DPA, order form, or written agreement with us, we aim to apply the following default retention periods:

Data categoryDefault retention period
Account dataFor the duration of the account and up to 24 months after account closure, unless longer retention is required for legal or security reasons
Billing and invoice dataAs required by Polish tax, accounting, and business record laws
Payment metadataFor as long as needed for billing, dispute resolution, fraud prevention, and legal compliance
Support communicationsUp to 36 months after the last interaction, unless longer retention is needed to resolve a dispute or legal issue
Marketing dataUntil you unsubscribe, withdraw consent, or object, unless we have another lawful basis
Website analytics dataUp to 26 months, unless configured differently or anonymized earlier
Security logsUp to 12 months, unless longer retention is needed for investigation, fraud prevention, or legal compliance
Product usage dataUp to 24 months, unless anonymized, aggregated, or needed for service improvement
Test run artifacts, including screenshots, videos, traces, and logsUp to 90 days by default, unless your plan, settings, or DPA provides a different period
Generated test reports and issue triage dataUp to 12 months by default, unless deleted earlier by the Customer or configured differently
Customer Content in deleted projectsDeleted or scheduled for deletion within a reasonable period after project deletion, subject to backups and legal retention requirements
BackupsRetained for a limited backup cycle, typically up to 90 days, and then deleted or overwritten according to our backup procedures

These periods may change as the service evolves. If we make material changes to retention periods, we will update this Privacy Policy or applicable product documentation.


5.3 Customer-controlled deletion

Where available, Customers may delete projects, test runs, artifacts, environments, integrations, or account data through the product interface.

Deletion from active systems may not immediately remove data from backups, logs, or archival systems. Backup copies are deleted or overwritten according to our normal backup cycle, unless longer retention is required for security, fraud prevention, legal compliance, or dispute resolution.


5.4 Account deletion

You may request deletion of your account by contacting us at hello@alwaysqa.com.

Before deleting an account, we may need to:

  • verify your identity;
  • confirm authority to delete a workspace or organization;
  • retain billing or invoice records required by law;
  • retain limited records necessary for fraud prevention, security, or legal claims.

If you are part of an organization account, account deletion may be subject to the organization owner’s instructions or applicable DPA.


5.5 Customer Content after termination

After termination or expiration of a paid customer relationship, we may retain Customer Content for a limited period to allow account recovery, export, billing verification, dispute resolution, or compliance with contractual obligations.

After that period, Customer Content will be deleted or anonymized according to our retention procedures, unless longer retention is required by law, security, dispute resolution, or a written agreement.


We may preserve data if we reasonably believe it is necessary to comply with law, respond to legal process, investigate abuse, protect users, protect the service, or establish, exercise, or defend legal claims.


6. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will take reasonable steps to notify you, such as by posting a notice on our website, updating the “Last updated” date, or sending an email where appropriate.

Your continued use of the website or service after the effective date of the updated Privacy Policy means that the updated Privacy Policy applies to your use of the service.


7. Contact us

For privacy questions, data subject requests, security issues, DPA requests, or complaints, contact:

Maciej Chmura IdeaUnlock ul. Tadeusza Kościuszki 1 32-020 Wieliczka Poland NIP / VAT ID: 8652425764 REGON: 18070444800000 Email: hello@alwaysqa.com