Privacy Policy
Last updated: August 2026
This policy covers everything under the QA and AI name: this website (qaandai.com), QA Analyzer, and QAandAI Verify. It explains what we collect, why, and who it's shared with.
Information we collect
When you contact us through the form on this site, we collect your name, email address, project type, and whatever you write in your message — used only to respond to you.
When you call our AI voice assistant ("Call us" on this site), your call may be recorded and processed by our voice AI provider, Retell AI, to understand and respond to your question. We disclose this before any call connects, and speaking with an AI (not a person) is also disclosed up front.
When you create a QAandAI Verify account, we collect your email address and a password. Your password is never stored or logged in plain text — it's run through a one-way cryptographic hash (scrypt) with a random salt unique to your account, so even we can't recover it. If you enable two-factor authentication, we store the authenticator secret needed to verify your 6-digit codes (compatible with Google Authenticator, Microsoft Authenticator, Authy, 1Password, etc.).
QAandAI Verify usage data: the plain-English requirements you write, the test steps generated from them, run results (pass/fail, videos, screenshots on failure), defects opened from failed runs, and any target URLs your workspace configures. QAandAI Verify is provisioned per organization for a specific list of authorized email addresses — it is not a general public signup product, and within a given deployment, authorized users share one workspace of requirements, tests, and results rather than having fully isolated private accounts.
QA Analyzer: when you run a scan, we process the URL you provide and generate a report of UI, accessibility, API, and security findings. Scans are read-only by design — QA Analyzer inspects pages and replays safe GET/HEAD API calls only; it does not submit forms or modify data on the site being scanned.
How we use information
- To respond to inquiries submitted through the contact form or voice assistant.
- To operate your QAandAI Verify account: authenticating logins, generating and running tests, and tracking defects.
- To generate QA Analyzer scan reports.
- To notify your team of real test failures — if your workspace administrator has connected Slack and/or Jira, a failed test automatically posts a Slack message and opens or updates a Jira ticket in your organization's own configured workspace. We don't share this data with anyone outside the integrations your own admin has set up.
- To improve reliability and accuracy of AI-generated tests and reports.
AI processing
When you write a requirement in QAandAI Verify and generate a test, the requirement text (and, for web/mobile-web platforms, information read live from the page you're testing) is sent to Anthropic's Claude API to produce the test steps. Anthropic processes this text to generate a response; we do not send it anywhere else for this purpose.
Who we share information with
We don't sell your information. We share it only with the service providers needed to run the product, and only for that purpose:
- Anthropic — processes requirement text to generate AI test steps.
- Retell AI — powers and may record calls to our voice assistant.
- Slack and Jira — only if your own workspace administrator has connected them; notifications go to your organization's own Slack workspace and Jira project, not ours.
- GitHub — only if your workspace administrator has configured a deploy token; approved tests are committed to your organization's own repository.
- Render and Netlify — our hosting providers for QAandAI Verify and this website, respectively.
Data retention
Contact form submissions are kept only as long as needed to respond to you. QAandAI Verify account and usage data is kept for as long as your account is active, or until your workspace administrator or you request deletion by contacting us below.
Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information (for example under the GDPR if you're in the EU, or the CCPA/CPRA if you're a California resident). Contact us below to make a request.
Security
Sessions use signed, HttpOnly cookies that can't be read or forged from client-side script. Passwords are hashed with scrypt and a per-account salt, never stored in plain text. Two-factor authentication (TOTP) is available on every account. Traffic to our sites and products is encrypted in transit (TLS).
Children
Our products and this site are not directed at children, and we don't knowingly collect information from anyone under 18.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
Contact us
Questions about this policy, or want to exercise a data request? Reach us through the contact form on the homepage, or by email at hello@qaandai.com.