Privacy Policy
How RazeQA collects, handles, redacts, and stores telemetry and source code data.
1. Information We Collect
RazeQA collects authentication credentials via Supabase Auth (email address and GitHub OAuth user identifiers). During PR verification runs, we collect ephemeral test execution artifacts including DOM snapshots, Playwright execution traces, console logs, and network telemetry.
2. Automated Secret Redaction
All captured network waterfalls, HTTP request bodies, and console error diagnostics pass through an automated high-entropy regex redaction filter. Bearer tokens, private keys, API secrets, and sensitive authentication headers are stripped before storage.
3. Ephemeral Sandbox Retention
Containerized test instances and browser execution recordings are retained for diagnostic review and automatically expired pursuant to your project retention policy. Source code clones are kept in isolated, transient volumes discarded immediately following journey execution.
4. Third-Party Integrations
When utilizing AI remediation features, sanitized error diagnostics and AST code diffs are transmitted to AI providers solely for synthesized patch generation. Your private source code is never used to train generalized foundation models.
5. Contact & Data Subject Rights
To request deletion of your account, organization telemetry, or connected repositories, please contact your RazeQA workspace administrator or email privacy@razeqa.dev.
© 2026 RazeQA Platform. All rights reserved.