Privacy Policy
Effective 2026-09-02 · Testosaurus is operated by Goose Data S.R.L., Strada Liviu Rebreanu nr. 10, Corp C, Camera 1, Bistriţa, jud. Bistriţa-Năsăud, Romania · Trade Registry J2024049768006 · CUI 55278862 ("Testosaurus", "we") · Contact: privacy@testosaurus.dev
1. Our two roles
For your account data, Testosaurus is the controller: we decide why and how it is processed. For the feedback data your application's users submit through widgets you embed, you (the Testosaurus customer) are the controller and we are the processor, acting on your instructions. If you are an end-user who sent feedback through a widget on someone else's site, that site's operator is responsible for your data — their privacy notice applies, and this policy describes how we handle it on their behalf.
2. What we collect
- Account data: email address and a password hash (authentication is handled by Better Auth; we never store plaintext passwords), plan and billing state, invite code provenance.
- Billing data: Stripe customer and subscription identifiers, prepaid balance ledger, usage counters (accepted submissions, storage bytes). Card details are entered in Stripe Checkout and never reach our systems.
- Feedback data (submitted via the widget on your site): the report text, page URL, browser context (user agent, viewport, console output), optionally a screenshot and a session replay recording. Screenshots and replays are opt-in and require end-user consent in the widget.
- Security data: IP addresses (from the trustworthy
cf-connecting-ipheader only) for rate limiting and abuse protection, Cloudflare Turnstile verification tokens, spam-filter signals such as duplicate text detection. - Operational data: queue and delivery logs (for example, distillation failures and webhook delivery results).
3. What we do with it
- Operate the service: store, show, filter, and export your feedback.
- AI distillation: feedback content (and screenshots where the configured provider supports vision) is sent to third-party LLM providers to generate the structured report — title, category, severity, steps. Providers are configurable per deployment; ask us for the current list. Your data is never used to train models.
- Notify you: email alerts on high-severity reports (Cloudflare Email) and webhook deliveries to URLs you configure.
- Integrations: if you connect GitHub or Linear, issue payloads are sent to those services when you raise a report.
- Billing: Stripe processes payments and sends receipts.
- Abuse protection: Turnstile verification, rate limits, and content filters run on the public submission path.
4. Legal bases (GDPR)
Contract performance for account and service operation; legitimate interests for security, abuse prevention, and service improvement; consent, obtained by the widget, for screenshots and session replays. End-user feedback is processed under the site operator's instructions — their lawful basis covers the submission.
5. Processors and sub-processors
- Cloudflare — hosting and data storage (Workers, D1, R2, Queues), email delivery, Turnstile bot protection.
- Stripe — payments and customer portal. Stripe receives your billing email and payment details.
- LLM providers — configured per deployment for distillation; feedback text and optionally screenshots are routed through the Vercel AI Gateway to the active provider to produce structured reports.
- GitHub / Linear — only when you connect them; issue payloads you raise are sent to your repositories and projects.
6. Where data lives and how long
Data is stored in Cloudflare D1 (metadata and feedback) and R2 (screenshots and replays) with edge locations worldwide. Account and feedback data are kept until you delete them: project purge and full account deletion (with confirmation phrase) are built into the dashboard and remove production data. Orphaned screenshots and replays are cleaned up automatically. Billing and audit records are kept as long as required for accounting and dispute resolution.
7. Your rights
You can access and export all of your data as JSON at any time from the dashboard, and delete a project or your entire account yourself. On top of that, EU residents have the usual GDPR rights: access, rectification, erasure, restriction, portability, and objection — write to privacy@testosaurus.dev. End-users should contact the site operator they submitted feedback to; we support operators in fulfilling such requests through export and deletion tools.
8. Cookies and local storage
The dashboard uses a session cookie for sign-in. The widget uses browser local storage only to queue reports offline. We use no advertising cookies and no cross-site trackers, and the marketing site runs no analytics that profile you.
9. Changes
Material changes to this policy will be announced in advance (changelog and, for account holders, email). The effective date above always reflects the current version.