Privacy Policy
Effective date: March 19, 2026
NuralStack (“we”, “us”, “our”) operates TestPilot AI at www.nuralstack-testpilot.com. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding it. We are committed to protecting your privacy in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.
1. Data Controller
NuralStack is the data controller for personal data collected through the Service. For privacy enquiries, contact us at support@nuralstack-testpilot.com.
2. Information We Collect
2.1 Information You Provide
- Account data: Name, email address, company name, and password (stored as a bcrypt hash — we never store plain-text passwords).
- Requirements & test data: Requirements text, target URLs, test plans, and any other content you upload to run tests.
- Authentication credentials: If you configure auth testing (e.g. username/password for your app), these are stored encrypted and used only to execute your test runs.
- Support communications: Emails or messages you send to us.
2.2 Information Collected Automatically
- Usage data: Test run history, credit consumption, feature usage, and timestamps.
- Log data: IP address, browser type, operating system, pages visited, and error logs. These are retained for up to 30 days.
- Cookies: We use strictly necessary session cookies for authentication. We do not use advertising or third-party tracking cookies. See our Cookie Policy.
2.3 Information from Third Parties
- Storage providers: If you connect Google Drive or OneDrive, we receive OAuth tokens necessary to read/write test artefacts on your behalf. We do not access any files other than those created by the Service.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing and operating the Service | Contract performance (Art. 6(1)(b)) |
| Sending transactional emails (run completion, invitations, password reset) | Contract performance (Art. 6(1)(b)) |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Analytics to improve the Service (aggregated, anonymised) | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (if opted in) | Consent (Art. 6(1)(a)) |
4. AI Processing
TestPilot AI uses Anthropic’s Claude API to generate test cases and analyse results. When you submit requirements text, relevant portions are transmitted to Anthropic’s servers for inference. Anthropic processes this data under their own Privacy Policy. We do not send personally identifiable information to Anthropic unless it is present in the requirements text you provide. We recommend anonymising any sensitive personal data before uploading requirements.
We do not use your data to train or fine-tune AI models.
5. Data Sharing & Third Parties
We do not sell your personal data. We share data only with:
- Amazon Web Services (AWS): Hosting, database (DynamoDB), storage (S3), email (SES), and compute (Lambda). AWS is a sub-processor under our AWS Customer Agreement. Data is stored in the us-east-1 (N. Virginia) region.
- Anthropic: AI inference for test generation and analysis. Data is processed under Anthropic’s sub-processor terms.
- Google / Microsoft: If you connect Google Drive or OneDrive, OAuth tokens are exchanged with Google/Microsoft and used solely to store/retrieve your test artefacts.
- Legal authorities: We may disclose data when required by law, court order, or to protect the rights and safety of NuralStack or others.
6. International Data Transfers
Our infrastructure is primarily located in the United States (AWS us-east-1). If you access the Service from the European Economic Area (EEA) or the UK, your data may be transferred to the US. Such transfers are safeguarded by AWS’s and Anthropic’s Standard Contractual Clauses (SCCs) with the European Commission.
7. Data Retention
- Account data: Retained for the duration of your subscription and for up to 12 months after account closure.
- Test artefacts (screenshots, reports, requirements): Stored in your connected cloud storage. We do not independently retain these unless stored in our default S3 bucket, in which case they are retained for 12 months after run creation.
- Logs: Up to 30 days.
- Anonymised analytics: Retained indefinitely in aggregated form.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your data (“right to be forgotten”), subject to legal retention obligations.
- Restriction: Request that we restrict processing of your data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Lodge a Complaint: File a complaint with your local data protection authority (e.g. the ICO in the UK, or your national DPA in the EU).
To exercise any of these rights, contact us at support@nuralstack-testpilot.com. We will respond within 30 days.
9. Security
We implement technical and organisational security measures including:
- TLS encryption for all data in transit.
- Passwords hashed with bcrypt (never stored in plain text).
- JWT-based authentication with short-lived tokens.
- Role-based access control (owner, admin, member, viewer).
- Rate limiting on all API endpoints.
- AWS infrastructure security controls (VPC, IAM, CloudTrail).
- Regular security testing including OWASP Top 10 checks.
Despite these measures, no system is entirely secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.
10. Children’s Privacy
The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us immediately and we will delete it.
11. Cookies
We use only strictly necessary cookies required for session management and authentication. We do not use advertising, analytics, or third-party tracking cookies. See our full Cookie Policy.
12. Changes to this Policy
We may update this Privacy Policy periodically. We will notify you by email or in-app notice at least 14 days before material changes take effect. The updated policy will be posted at this URL with a revised effective date.
13. Contact
For privacy enquiries or to exercise your rights:
Email: support@nuralstack-testpilot.com
Website: www.nuralstack-testpilot.com