Privacy Policy
Last updated: 2026-05-16
1. Introduction
Test4All ("we", "us") respects your privacy. This policy explains how we collect, use, share, and protect the personal data you provide when using our service.
2. Information We Collect
- Account data: name, email, password (hashed), company.
- Payment data: processed via LemonSqueezy; we do not store full card numbers.
- Usage data: request history, login times, IP address, browser information.
- Testing materials you upload: app files, URLs, descriptions, etc.
- Test accounts (test_accounts): optional application credentials you may provide for our testers to use against your app during a test request. Stored in an encrypted field, readable only by the admin assigned to that request. We strongly recommend rotating or disabling such credentials after the test is complete.
- Report processing state (derived metadata): each test report tracks its retention deadline (expires_at), archive state (archived / archived_at / archive_storage_key), and retention-paused flag (retention_paused). These fields are computed automatically by the system based on your subscription plan and payment status (see §6); they are not directly supplied by you.
- Cookies and tracking technologies (see our Cookie Policy).
3. How We Use Data
- To provide, operate, and improve the service.
- To process payments, subscriptions, and customer support.
- To send transactional and important account notifications.
- To prevent service abuse (API rate limiting, login throttling), detect payment fraud through our payment processor (LemonSqueezy), and respond to violations of our Terms of Service.
- To comply with legal obligations.
4. Data Sharing
We do not sell your personal data. We share data only with the following essential processors:
- LemonSqueezy — payments and invoicing.
- Supabase — database and authentication hosting.
- Cloudflare — content delivery, DDoS protection, and R2 object storage.
- Resend — transactional email delivery (verification, subscription notifications, retention reminders).
- When required by law (e.g., court order).
Each of these providers uses the EU Standard Contractual Clauses (SCCs) as their international data transfer safeguard and publishes a Data Processing Agreement (DPA). Details: Supabase · Cloudflare · LemonSqueezy · Resend.
5. Share Links & View Analytics
When you generate a "Share with client" link from your dashboard to let a client view a test report, we record the following technical data to help you track link usage:
- View count (view_count): cumulative number of times the link was opened.
- First and last view timestamps (first_viewed_at / last_viewed_at).
- A hash of the link token (one-way, used to authenticate requests).
We do not record the viewing client’s IP address, User-Agent, or geolocation. Links can be revoked at any time from your dashboard; revocation takes effect immediately, and view records are removed alongside the link per the retention rules in §6 upon account deletion or link revocation.
6. Data Retention
We retain your data only for as long as necessary to provide the service and comply with legal obligations. Upon account deletion, we remove or anonymize data within a reasonable period, except where retention is legally required (e.g., accounting records).
Test reports are retained based on your subscription plan:
- Free trial / Essential plan: 90 days. (Email reminder 14 days before expiry; after 90 days, reports enter a 7-day cold-archive grace window during which you can manually restore them; then permanently deleted.)
- Professional plan: 365 days (with the same 14-day reminder and 7-day archive grace).
- Enterprise plan: retained indefinitely unless you delete them.
When your subscription expires or you downgrade, we process existing reports per the schedule shown in the "downgrade confirmation" dialog; during payment-retry windows (up to 30 days), your previous plan’s retention period is preserved. Share links and their view records (§5) are deleted alongside the report.
7. Your Rights
Depending on applicable laws (e.g., GDPR, CCPA), you have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing activities.
- Data portability.
- Withdraw consent (without affecting prior lawful processing).
- Lodge a complaint with a supervisory authority.
8. International Transfers
Your data may be transferred to servers outside your country of residence. We implement appropriate safeguards (such as Standard Contractual Clauses) to meet legal requirements.
9. Children
This service is not intended for users under 18. If we discover data of minors, we will delete it promptly.
10. Changes to this Policy
Material changes will be announced via email to your registered address. Continued use after an update constitutes acceptance.
11. Contact Us
For any privacy-related inquiries, contact us at: hello@test4all.info