Privacy Policy

Last updated: March 2026

Your privacy is important to us. This Privacy Policy explains how TestBuggy collects, uses, and protects your information when you use our Chrome extension, website, and associated services.

1. Who We Are

TestBuggy is an AI-powered quality assurance platform consisting of a Chrome extension and a web dashboard. Our tool helps QA engineers and developers record browser sessions and automatically generate professional test cases, bug reports, and visual documentation. We are committed to transparency and privacy-first practices.

2. What Information We Collect

We collect the following types of information:

  • Account information: Your email address and display name, obtained from your authentication provider (Google OAuth) when you sign in
  • Purchase information: Transaction records for credit purchases processed through LemonSqueezy, our payment provider
  • Recorded test sessions: Browser interaction data (clicks, inputs, navigations, console errors, network failures) captured during active recording sessions. This data is processed transiently — it is sent to our AI pipeline, processed, and immediately discarded. We do not store session recordings.
  • Usage data: Basic analytics such as credit usage and feature interaction for improving the service

3. How We Collect Data

  • Google OAuth: When you sign in, we receive your email address and display name from Google. We do not access your Google contacts, calendar, drive, or any other Google services.
  • Chrome Extension: During active recording sessions (initiated by you), the extension captures page interactions, console output, and network request metadata. No data is captured when you are not actively recording.
  • Payment Provider: Purchase transactions are processed by LemonSqueezy. We receive transaction confirmation and credit amounts but do not handle or store payment card details.

4. Chrome Extension Permissions

The TestBuggy Chrome extension requires the following browser permissions, each for a specific purpose:

  • activeTab: Allows the extension to interact with the currently active tab during recording. Used to capture page elements, clicks, and inputs.
  • tabs: Enables detection of page navigations and URL changes during a recording session, ensuring complete step tracking.
  • storage: Stores your preferences, authentication state, and recording settings locally in your browser. No data is sent externally from storage.
  • webRequest: Monitors network requests during active recording to detect failed API calls and network errors, which are included in bug reports for debugging context.

All permissions are used exclusively during active recording sessions and only for the purposes described above.

5. AI Processing

When you generate a test case or bug report, your recorded session data is sent to OpenAI's API for processing. The AI analyzes your interactions and generates structured output. After the generation is complete, the session data is not retained by TestBuggy or stored in our systems.

OpenAI processes this data according to their own privacy policy and data processing agreements. We use OpenAI's API with data retention settings configured to minimize storage on their end.

6. How We Use Your Information

We use the collected information to:

  • Provide and maintain the TestBuggy service
  • Manage your account and credit balance
  • Process AI generation requests
  • Send transactional emails (purchase confirmations)
  • Improve the quality and reliability of our service
  • Respond to support inquiries

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

7. Third-Party Providers

We work with the following third-party services to deliver TestBuggy:

  • Supabase: Authentication, database, and backend infrastructure. Stores your account information and credit balance securely.
  • OpenAI: AI language model provider used for generating test cases and bug reports from recorded session data.
  • LemonSqueezy: Payment processing for credit purchases. Handles all payment card data securely — we never see or store your card details.

Each provider operates under their own privacy policies and is contractually obligated to protect your data.

8. Cookies

TestBuggy uses cookies solely for session management and authentication. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. The cookies we set are essential for the Service to function properly and cannot be opted out of while using the Service.

9. GDPR & KVKK Compliance

TestBuggy is designed to be compliant with the European Union's General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law (KVKK). Our compliance measures include:

  • Data minimization: We collect only the minimum data necessary to provide the Service
  • Purpose limitation: Data is used only for the purposes described in this policy
  • Transient processing: Session data is processed and immediately discarded, never stored
  • User rights: You have full control over your data (see Section 11)
  • Transparent processing: This policy clearly describes all data collection and processing activities

10. Data Security

We implement industry-standard security measures to protect your information, including:

  • Encrypted data transmission (HTTPS/TLS) for all communications
  • Secure authentication via OAuth 2.0
  • Row-level security policies on our database
  • Regular security reviews of our infrastructure
  • Minimal data retention — session data is never persisted

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We encourage you to take precautions to protect your own account credentials.

11. Your Rights

Under GDPR, KVKK, and other applicable data protection laws, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to correction: Request correction of any inaccurate or incomplete data
  • Right to deletion: Request deletion of your account and all associated personal data
  • Right to data portability: Request your data in a structured, machine-readable format
  • Right to object: Object to processing of your personal data in certain circumstances

To exercise any of these rights, please contact us at the email address below. We will respond to your request within 30 days.

12. Contact

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

testbuggy.extension@gmail.com