← Back to QA Copilot

Privacy Policy

Last updated: July 17, 2026

1. Overview

This policy explains what data QA Copilot (qacopilot.com) collects, how it's used, and who it's shared with. It applies to anyone who creates an account or uses the Service.

2. Information We Collect

  • Account data: email address and authentication identifiers, handled by our auth provider, Supabase.
  • Content you submit: requirements text (PRDs, acceptance criteria, tickets) you paste in to generate test cases.
  • Generated output: the QA plans produced from your content, stored so you can revisit past projects.
  • Billing data: plan tier and subscription status. Payment card details are collected and processed directly by Stripe — we do not store card numbers.
  • Usage data: product analytics events (e.g. generation started/completed, feature usage) via PostHog, and error diagnostics via Sentry.

3. How We Use Information

We use this data to: operate and improve the Service; generate your QA plans by sending your submitted requirements text to our AI provider (OpenAI) for processing; enforce plan usage limits; process payments; respond to support requests; and monitor for errors and abuse.

4. Third-Party Processors

We share data with the following processors, each bound by their own privacy and security terms:

  • OpenAI — processes the requirements text you submit to generate test cases.
  • Supabase — hosts authentication and application data.
  • Stripe — processes payments and manages subscriptions.
  • PostHog — collects product usage analytics.
  • Sentry — collects error and performance diagnostics.

5. Data Retention

We retain your account data and generation history for as long as your account is active, so you can revisit past QA plans. You can request deletion of your account and associated data at any time (see Section 7).

6. Cookies

We use essential cookies to keep you signed in, and analytics cookies (via PostHog) to understand product usage. You can control cookies through your browser settings; disabling essential cookies may prevent sign-in from working.

7. Your Rights

You may request access to, correction of, or deletion of your personal data by emailing support@qacopilot.com. Depending on your location, you may have additional rights under laws such as the GDPR or CCPA.

8. Security

We use industry-standard measures — including encryption in transit and access controls — to protect your data. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the Service or by email.

10. Contact

Questions about this policy can be sent to support@qacopilot.com.