Privacy Policy

// Version 1.0 — Effective April 2026

This Privacy Policy explains how Sana Ventures Studio SL ("Company", "we", "us", or "our") collects, uses, and protects your personal data when you use TestPilot ("Service"). We are committed to complying with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

1. Data Controller

Sana Ventures Studio SL
Madrid, Spain
Contact: hello@testpilotapp.dev

2. Data We Collect

DataWhy we collect itLegal basisRetention
Email addressAccount creation, authentication via magic link, service communicationsContract performanceUntil account deletion
Plan / subscription statusFeature access control, billing managementContract performanceUntil account deletion
Test run historyTest results, bug reports, screenshots you generateContract performanceUp to 500 most recent runs
App URLs and credentialsRequired to perform tests you request. Credentials are used only during active test sessions and are not permanently stored.Contract performanceSession only
Claude API keyRequired to execute AI-powered tests. Stored only in your browser's local storage — never on our servers.Contract performanceBrowser local storage only
Terms acceptanceLegal compliance recordLegal obligationUntil account deletion
Last login timestampSecurity and account managementLegitimate interestUntil account deletion
Traffic logsAnalytics — page visits, referral source (no personal identifiers)Legitimate interest90 days rolling

3. Data We Do NOT Collect

4. Third-Party Services

ServicePurposeData shared
SupabaseDatabase hosting (EU region)Email, plan, test history
StripePayment processingEmail, payment details (we never see card numbers)
ResendTransactional emailYour email address, email content
AnthropicAI processing via your own API keyTest scenarios, screenshots (sent via your key)
Microsoft ClaritySession recording and heatmapsAnonymized browsing behavior
Microsoft AzureServer hosting (EU — Ireland region)All service data

5. Your Rights Under GDPR

As an EU resident, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at hello@testpilotapp.dev. We will respond within 30 days.

You also have the right to lodge a complaint with the Spanish data protection authority: Agencia Española de Protección de Datos (AEPD) at www.aepd.es.

6. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

7. Data Retention

We retain your personal data for as long as your account is active. If you request account deletion, we will delete your data within 30 days, except where we are required to retain it by law.

8. Cookies

TestPilot uses the following:

9. Children

TestPilot is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by requiring re-acceptance within the Service. The version number and effective date will be updated accordingly.

11. Contact

For privacy-related inquiries: hello@testpilotapp.dev
Sana Ventures Studio SL — Madrid, Spain

← Back to TestPilot