Legal

Privacy Policy

Last updated: 29 September 2026

In short

  • We never store your app's screenshots, only a small fingerprint of each that can't be turned back into the image.
  • The real values of your test secrets never leave your computer.
  • Runs, logs, and error reports are deleted after 90 days at most.
  • We keep only the personal data we need to run your account and bill you. We don't sell it, and this website has no cookies or analytics.

1. Who is responsible

qAuto is run by an individual based in Vietnam, who decides how your personal data is used. Contact: support@qauto.ai.

2. What we collect, and why

  • Your account: your GitHub user ID, login, and email address, from GitHub when you sign in. We use them to run your account and to contact you about it.
  • API keys: stored only as hashes, so we can check a key but can't read it back.
  • Runs: each test's text, with its placeholders such as {{secrets.TEST_PASSWORD}} instead of the real values; the emulator's Android version and screen size, the qauto version, and whether a person, a coding agent, or an automated build started the run; for each step, the action qAuto decided, a short description of the screen written by the AI, a fingerprint of the screenshot, and which AI model decided it; and the verdict. We keep them to run the test, charge for it, and help when something goes wrong.
  • Plans, payments, and credits: your plan, your payments and refunds, and the credits added and used. Paddle handles the payment itself, so we never see your card details.
  • Technical data: IP addresses and request logs, to keep the service secure and working, and error reports when something breaks.
  • Emails you send us, to answer them.

We don't use your runs to improve qAuto or to train AI models.

3. Screenshots

At each step, the qauto tool sends a screenshot of your app to our service, which passes it through OpenRouter to an AI model to decide what to do next. We don't store screenshots. They only go to model providers that never train on them. Some of those providers keep requests for a short time, for example to check for abuse. On a zero data retention run, which you can turn on for every run or for one test, they only go to providers that keep nothing, and within an hour after the run ends, we delete its test and its steps too (section 5).

What we keep of each screen:

  • A fingerprint: 64 bits, worked out from a tiny grayscale copy of the screenshot (a difference hash). It tells us whether two screens look alike, for example when an app is stuck, and can't be turned back into the image.
  • A short description of the screen, written by the AI to explain its decision, such as "The login form is showing, with the email field empty." It can mention text shown on the screen, which is one more reason to test with test accounts and test data (terms, section 6).

The screenshots, video, and reports of your runs are saved on your own computer.

4. Who else handles your data

We use these services to run qAuto. Each one only gets what it needs for its part:

  • GitHub: signing in.
  • OpenRouter and the AI model providers it routes to: the test and the screenshot for each step.
  • Paddle: payments, subscriptions, tax, receipts, and refunds. Paddle is the merchant of record, and its own privacy notice applies to the data it collects at checkout.
  • Sentry: error reports.
  • Our server's hosting provider: running the service and storing its database.
  • Cloudflare: serving this website, and forwarding email sent to support@qauto.ai.

Some of these are in the United States or other countries outside Vietnam, so your data may be processed there. We don't sell your data, and we don't share it for advertising.

5. How long we keep it

  • Runs, with their descriptions and fingerprints: 90 days, then deleted.
  • Zero data retention runs: within an hour after one ends, its test, its steps, and the reason for its result are deleted. Only when it started and ended, its result, its number of steps, and its credits stay, for 90 days, so your account can show what it cost.
  • Your account: until you ask us to delete it. We then revoke your API keys and remove your email address and GitHub login.
  • Payments and credits: as long as the law requires us to keep financial records, even after an account is deleted.
  • Logs and error reports: up to 90 days.

6. Cookies

This website sets no cookies and has no analytics. The account pages at app.qauto.ai use one cookie, only to keep you signed in.

7. Your choices and rights

You can ask us for a copy of your data, to correct it, or to delete it, by emailing support@qauto.ai from the email address on your account. We answer within 30 days. Depending on where you live, you may also have the right to object to how we use your data, and to complain to your data protection authority.

8. Security

All connections are encrypted. API keys are stored as hashes. Secret values stay on your computer: the qauto tool fills them in locally, and only the placeholders are sent.

9. Children

qAuto is for developers, and not for anyone under 16.

10. Changes

We'll post any change to this policy here, and update the date at the top.