Privacy policy
Last updated: 2026-09-25
The short version
We never ask you to upload your real architecture diagram or describe your real system in confidential detail. Matching works entirely against a library of generic, industry-standard reference architectures. The component names you type when confirming a diagram stay in your session and are never used to grow our library or train anything.
What we collect
- Wizard answers. Your industry selection and the multiple-choice answers you give during matching (e.g. "inbound", "event-driven"). These describe the shape of an integration pattern, never your real system.
- Match-miss feedback (optional). If you tell us what's different about your architecture when confidence is low, that free-text note is recorded to help us grow the reference library.
- Component names. When you confirm a diagram, the names you type stay in your session (and, once you sign in, in your account) so your generated artifacts read in your vocabulary. These are never sent anywhere else and never used to grow our library.
- Email address. Collected when you sign in to unlock checkpoints, test paths, plans, and reporting, or when you request the demo. Used to identify your saved workspace and to reach you about product updates — never sold, never spammed.
- Progress and report data. Checkpoint pass/fail status you record, and any notes you add to a status report, are stored with your account so your workspace persists between visits.
What we never collect
In the architecture product we never collect real architecture diagrams, real system credentials, production data or payloads, or any confidential business information. Test Automation works differently, because it tests a real application — see Test Automation below. Sample test-data payloads generated in the product are synthetic and generic — editing them in your real expectations happens entirely in your browser and is not transmitted anywhere by that action alone.
How the plain-English summary works
The summary may be generated with the help of a third-party large language model, using only the generic pattern facts and the component names you provided — never your wizard answers' underlying business context beyond what you typed, and never used to train any model.
Test Utilities — a different data model
Everything above describes the core product: matching, checkpoints, paths, and reporting, none of which ever require your real system. Test Utilities is the one deliberate exception. Tools there — starting with the Payload Chain Builder — work directly with real sample JSON you provide: field names, structure, and example values from your own APIs or documents.
- Kept private to your account. Uploaded payload schemas and field-dependency rules are stored only against your own login, never analyzed in aggregate, and never used to grow any shared library — the same treatment component rename strings get elsewhere in the product.
- You control what you paste. We recommend using representative/fake values rather than real production data, same as the Test Data payloads generated elsewhere in the product — the tool only needs real field names and structure to work, not real data.
- Deleted with your account. Right-to- erasure (below) removes saved chains along with everything else tied to your login.
Applications and Test Automation — a real app
When you add an Application, you give us the URL of a web app you confirm you own or are authorized to test, and Test Automation (in closed beta) runs a real browser against it. That means we handle information about that app, not a generic pattern.
- What we store about the app. The pages the explorer reaches — headings, buttons, form fields and their declared rules, visible text, and the API paths each page calls — plus business rules quoted from those pages, the test scenarios, and each run's results, including a screenshot of every step and the requests it made. Screenshots show whatever your app displayed to the test account, so point it at a staging site or a test account, never real customer data. Old screenshots may be removed after a retention period; the results themselves are kept.
- Test logins and other test data. Values you give it — such as a test account's password — are stored encrypted, are never shown back to anyone once saved, and are never sent to an AI model; they are only typed into your own site during a run. Each person can keep their own values, which nobody else can use or see. Use test accounts only, never a real person's login.
- What AI models see. To write and repair scenarios, explain failures, read your pages' stated rules and compare your manual test cases, we send page structure and text, scenario text and the pasted test cases to Anthropic's Claude. When a step's target can't be found without it, the page's accessibility tree may be sent to an NVIDIA-hosted model to locate it. Test data values are never included. Neither is used to train any model on our side.
- Private to your workspace. Everything above belongs to your workspace — today, your own personal one — and is never pooled across customers or used to grow our shared knowledge base. We record how many model tokens each workspace uses, not what was in the calls. Deploy-hook tokens are stored only as a hash.
- Deleted with the Application. Deleting an Application deletes its pages, rules, scenarios, runs, screenshots and test data; deleting your account deletes all of it.
Deletion
You can clear your local session at any time with the "Start over" control in the header, and delete your account — with everything tied to it — from your Profile page. For anything else, email us at support@qualityaiq.com.
Contact
Questions about this policy? Email support@qualityaiq.com. QualityAIQ is a product in active development; this policy will be updated as the product matures, and material changes will be reflected on this page.