On this page · 15 sections
Introduction
This Privacy Policy explains how Smoketest collects, uses, stores, shares, and otherwise processes personal data when you use our website, product, APIs, and related services.
Smoketest is operated by Sayfun Studio, registered in the Netherlands under KvK number 42034313 and VAT ID NL005445100B28. In this policy, “Smoketest”, “we”, “us”, and “our” refer to Sayfun Studio and any entity that operates the service on its behalf, including any successor trade name or operating entity. For the purposes of applicable data protection law, including the General Data Protection Regulation ("GDPR"), we are the data controller for the personal data described in this policy unless stated otherwise.
Smoketest is intended for professional and business use, including prosumers testing software they own or are authorized to test.
This policy should be read together with our Terms of Service. If you do not agree with this policy, please do not use the service.
Information we collect
We collect the categories of information reasonably needed to operate, secure, support, and improve Smoketest.
How we collect information
- Directly from you when you sign up, configure a workspace, create tests, connect services, or contact us.
- From sign-in providers such as Google when you choose OAuth login.
- From Jira, Linear, and GitHub when a workspace member authorizes a Connection, including through their APIs and authenticated webhooks.
- Automatically when you use the service, through logs, analytics, cookies, and similar technologies.
- From payment and service providers when they send us billing, subscription, delivery, or account-related events.
How we use personal data
- Provide, maintain, and administer Smoketest and your workspace.
- Authenticate users and manage access, permissions, and security.
- Execute browser-based runs and return artifacts, logs, and results.
- Confirm when an issue enters a configured QA status, capture the issue context needed for a Test Request, prepare and run an Attempt, post a result comment, and request the configured issue transition.
- Reconcile active Test Sources, recover missed provider events, and monitor Connection and synchronization health.
- Process subscriptions, invoices, payments, refunds, and related billing operations.
- Send transactional communications such as sign-in links, product notices, billing messages, and support responses.
- Send marketing communications where permitted by law or where you have opted in, with an unsubscribe option where required.
- Monitor performance, detect abuse, troubleshoot issues, and improve reliability, usability, and product design.
- Comply with legal obligations, enforce our terms, and protect our rights, users, and systems.
Legal bases for processing under GDPR
If GDPR or similar European privacy law applies, we process personal data on one or more of the following bases:
AI and automated processing
Smoketest uses automated systems and AI-assisted tooling as a core part of the service to interpret instructions, drive browser interactions, and produce run outputs such as logs, recordings, and results.
For the purpose of providing, securing, and supporting the service, Smoketest and its service providers, including OpenAI, may process tests, prompts, target URLs, page observations, run artifacts, and related content. For tests created from Jira or Linear issues, this may also include the frozen issue context, recent human comments, bounded supported image attachment content and metadata, user-supplied retry context, and bounded code patches from a linked pull request. We do not sell customer data.
Issue, comment, attachment, and code context is treated as untrusted input. Smoketest limits and sanitizes that context, excludes known Smoketest-authored comments, rejects unsupported attachments, and redacts recognized secret patterns before it is used to prepare a test. These controls reduce risk but cannot identify every sensitive value, so customers should avoid placing unnecessary secrets or personal data in issues used for testing.
Where third-party AI or infrastructure providers are involved, their processing is subject to their own terms and data handling practices. We may update our AI data practices over time. If we make a material change to how customer content is used, we will update this policy and provide notice where required by applicable law.
International data transfers
Our providers may process personal data in countries other than the country where you are located, including outside the European Economic Area.
Where required, we take steps intended to ensure an appropriate level of protection for transferred personal data, such as relying on adequacy decisions, contractual safeguards, or other lawful transfer mechanisms recognized under applicable law.
Security
We use commercially reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption in transit, encryption for stored customer credentials and environment variables, signed URLs for run artifacts, role-based restrictions, backups, monitoring, and vendor security controls.
No system can be guaranteed to be perfectly secure. If we become aware of a personal-data incident requiring notification, we will respond in accordance with applicable law.
Data retention
We retain personal data for as long as reasonably necessary to provide the service, maintain records, resolve disputes, enforce agreements, and comply with legal obligations.
Run artifacts stored in Cloudflare R2, such as recordings, screenshots, transcripts, and traces, are generally deleted after 90 days. Run metadata in our database may be retained for longer to operate the service, show run history, maintain billing and usage records, investigate abuse or security issues, and improve reliability.
Disconnecting Jira or Linear stops new issue intake and removes the stored provider credentials and Connection registration. Historical Test Requests, Attempts, Results, issue snapshots, synchronization records, and audit history remain part of the workspace until they are deleted under a workspace or privacy request. Pausing or archiving a Test Source also preserves its history.
If you want to delete your account, workspace, Connections, issue snapshots, runs, or associated data, contact us. Deletion is currently handled manually. Workspace deletion covers Test Sources, Test Requests, Attempts, Results, frozen issue and supported attachment content, linked pull request context, webhook and synchronization records, and audit history owned by that workspace. We will delete or anonymize associated data within a commercially reasonable period unless longer retention is required for legal, accounting, fraud-prevention, security, backup, or similar legitimate reasons.
Your rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, object to, or export your personal data, and to withdraw consent where processing is based on consent.
If you are in the European Union, EEA, or a jurisdiction with similar rights, you may also have the right to lodge a complaint with your local supervisory authority, including the Dutch Data Protection Authority where relevant.
To exercise your rights, contact us at [email protected]. We may need to verify your identity before fulfilling a request.
An export may include structured issue-derived records and their provider provenance where this is necessary to answer a valid request. Exports do not include OAuth tokens, webhook secrets, or third-party data that the requester is not authorized to receive.
Children
Smoketest is not intended for children under the age of 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided personal data to us, contact us and we will take appropriate steps.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the policy on this page and provide any additional notice required by law. Your continued use of the service after the updated policy takes effect means you accept the revised policy to the extent permitted by law.
Contact
For privacy questions, requests, or complaints, contact:
Sayfun Studio
KvK: 42034313
VAT ID: NL005445100B28
Privacy: [email protected]
Support: [email protected]
Security: [email protected]
Need clarification?
Email [email protected]. A founder answers, usually the same day.
See also Terms of Service, Privacy Policy, and Security.