Privacy Policy

How the ReleaseTwin project handles data for the hosted ReleaseTwin dashboard. Last updated August 2026. A counsel review is planned before general availability.

The short version

  • Your test cases run in your infrastructure. We don’t execute them and we don’t receive your test data by default.
  • What we store: your account details, your projects, and the metadata of runs you upload.
  • Evidence (request/response detail, screenshots) is only stored if you opt a project in, and it’s redacted by the CLI on your side first.
  • We don’t sell personal data and we don’t run ad tracking.

What we collect

Account & identity — via our authentication provider (Clerk): your email, name if you provide one, and authentication events. Passwords are handled by the provider; we never see them.

Project & usage data — the projects, journeys, API tokens, and settings you create; and per run: case identifiers, oracle references, fixture hashes, pass/fail, failure classification, flag-proof outcome, and timestamps. Counts of uploaded runs and active projects, for plan metering.

Evidence documents (opt-in only) — if you enable evidence upload for a project, per-step request/response summaries, assertion detail, and screenshots. These are redacted in your own CLI before upload (auth headers, credential-shaped fields, resolved secrets, and your own masking rules) and stored opaquely — our systems don’t parse them.

Operational data — server logs, IP address and user agent on requests, and error diagnostics, kept for security and debugging.

Marketing site — if analytics are enabled they are privacy-respecting and cookie-free (aggregate page counts, no cross-site tracking, no profiles).

What we do not collect

  • Your fixture file contents, request or response bodies, or credentials — the default upload path has no field for them, and they never leave your infrastructure unless you turn on evidence upload.
  • Your source code or CI configuration.
  • Behavioral advertising data. There is none.

Why we use it

  • To provide the Service — authenticate you, store and display your run history and evidence, enforce plan limits.
  • To keep it secure — detect abuse, investigate incidents.
  • To improve it — in aggregate and de-identified form; and to contact early-access users for feedback.
  • To bill you, if you’re on a paid plan, through our payment processor.

Legal bases (where the GDPR applies): performance of our contract with you, our legitimate interests in a secure and improving product, and your consent where required.

Who we share it with

Only the sub-processors needed to run the Service, each under a data-processing agreement:

  • our cloud host (compute, database, object storage);
  • our authentication provider;
  • our payment processor (paid plans only);
  • our email provider (transactional and, if you opt in, product email).

We don’t sell or rent personal data. We may disclose data if legally required, and we’ll tell you unless prohibited.

Retention

  • Account data: while your account is open, then deleted within 30 days of account deletion.
  • Run metadata: until you delete the project, or per your plan’s retention setting.
  • Evidence documents: your project’s retention window (default 30 days, up to 365), enforced by a daily purge; the metadata report survives the evidence.
  • Logs: a rolling window measured in weeks.

Your rights

You can access, export, correct, or delete your data from the dashboard, or by emailing ernestoalejo22@gmail.com. Depending on where you live you may also have the right to object to or restrict processing, or to lodge a complaint with a supervisory authority. We’ll respond within the time the applicable law requires.

International transfers & security

The Service is hosted in the United States; using it involves transferring your data there. We rely on standard contractual clauses with sub-processors where required. Data is encrypted in transit and at rest; API tokens and stored project secrets are encrypted at rest and shown only once. See the Security page for detail.

Children

The Service isn’t for anyone under 16, and we don’t knowingly collect their data.

Changes & contact

We’ll post the updated date above and email account holders before a material change takes effect. Privacy questions or requests: ernestoalejo22@gmail.com.