Privacy Policy

_Last updated: July 18, 2026_

This Privacy Policy explains how [Company Legal Name] ("BeyondTest", "we", "us") collects, uses, and protects information when you use the BeyondTest test management service (the "Service"). By using the Service you agree to this policy.

Who we are

BeyondTest is an AI-native test management application. For questions about this policy or your data, contact us at [email protected].

Information we collect

  • Account information — your name, email address, password (stored only as a

salted hash), and profile photo if you add one.

  • Content you create — test cases, requirements, runs, results, comments,

and any other data you enter or import (e.g. from TestRail). This may include information you choose to put in those records.

  • Usage and log data — actions taken in the app (recorded in the activity

log), plus standard server logs such as IP address, browser type, and timestamps used for security and troubleshooting.

  • Cookies — a single essential, http-only session cookie to keep you signed

in. We do not use advertising or third-party tracking cookies.

How we use information

We use your information to provide and secure the Service, authenticate you, operate the features you request (including AI features you invoke), notify you about your account and requests, and comply with legal obligations. Where required, our legal basis is performance of our contract with you, your consent (e.g. AI features), and our legitimate interests in operating a secure service.

Service providers (sub-processors)

We share data only with providers that help us run the Service:

  • Amazon Web Services (AWS) — hosting and infrastructure; Amazon SES for

transactional email (verification, password reset, notifications).

  • AI providers (Anthropic, OpenAI, or Google) — power the optional AI

features, using whichever provider your instance administrator selects. When you invoke an AI feature, the relevant content (e.g. a requirement's text, test case titles/steps, a pull request diff, or a mockup image) is sent to that provider's API to generate the result. We do not send more than the feature needs, and nothing is sent unless an AI feature is used.

  • Cloudflare — content delivery, network security, and the Turnstile CAPTCHA

on our public forms.

Each processes data on our behalf under its own terms. We do not sell your personal information.

AI features and your content

AI features are optional and act only on content you (or your organization's users) choose to submit to them. That content is processed by the selected third-party AI provider under that provider's own terms, security practices, and privacy policy, which we do not control. Where your instance is configured with your organization's own API key, the AI relationship is directly between your organization and the provider, governed by your agreement with them.

Do not submit personal data, credentials, or other sensitive or regulated information to AI features unless your organization has determined it is permitted to process such data with the selected provider. You are responsible for the content you submit. To the maximum extent permitted by law, we are not responsible for the security, retention, or handling of content once it is transmitted to the selected AI provider, or for any personal-data or confidentiality consequences of content you choose to submit to AI features.

Data retention and deletion

We keep your information for as long as your account or instance is active. You can delete records in the app; deleting your account or instance removes the associated data. Backups and logs are retained for a limited period and then deleted. You may request deletion at [email protected].

Security

We protect data with encryption in transit (HTTPS), hashed passwords, encrypted storage of integration credentials, per-instance isolation for hosted customers, and access controls. No method of transmission or storage is 100% secure, but we work to protect your information.

International transfers and residency

The Service may be hosted in the United States or another region. For hosted customers with residency requirements, we can provision a dedicated instance in a specific region — contact us. Transfers are made using appropriate safeguards where required by law.

Your rights

Depending on your location (e.g. the EEA/UK under GDPR, or California under CCPA), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact [email protected]. For data you manage inside a customer instance, your organization is the controller and we act as processor on its behalf.

Children

The Service is not directed to children under 16, and we do not knowingly collect their personal information.

Changes

We may update this policy; we will post the new version here and update the date above. Material changes will be communicated where appropriate.

Contact

Questions or requests: [email protected].