Privacy Policy

Last updated: 22 September 2026

This policy explains what data Testorim collects, how we use it, and your choices. Testorim is operated by Fulgic (we, our), which is the controller of the account data described here. It covers two things: this website, and the Testorim product. We aim to collect only what is needed to provide and improve the Service.

1. Who we are

Testorim is a browser QA product. For any question about this policy or about data we hold, email info@fulgic.com. We answer within 30 days.

2. This website

The waitlist

If you submit the waitlist form, we collect the email address you type and the time you submitted it. We use it for one purpose: to tell you when Testorim opens for sign-up. We do not sell it, rent it, or use it for unrelated marketing.

There is no database behind the form. Your address is sent through Resend (our email provider) and lands in the Testorim team mailbox, which is where the list lives. To be removed, reply to the confirmation email with the word “unsubscribe”, or email info@fulgic.com. Removal is permanent and we keep no record of it beyond deleting the address.

Analytics and cookies on this site

This site loads no analytics and sets no analytics cookie until you choose “Accept” in the cookie banner. If you choose “Reject”, or ignore the banner, no analytics script is loaded at all.

If you accept, two things run:

  • PostHog (product analytics). Records page views and clicks on calls to action, with a first-party identifier stored in your browser so repeat visits are counted once. Hosted in the United States.
  • Vercel Web Analytics. Aggregate page-view counts, without cookies.

You can change your mind at any time. Changing your answer to “Reject” stops collection from that point and clears the choice we stored. The choice is stored in your browser, so it is per browser and per device.

Our host, Vercel, keeps short-lived server logs (including IP address) for security and abuse prevention. That is a legitimate-interest processing we cannot switch off, and it is not used to build a profile of you.

3. The product: data we collect

The following applies once you create an account.

Account information

Email, name, and profile image, obtained via our authentication provider (Clerk) when you sign up. You can update or remove this information from your account settings.

Usage and content

Test descriptions you submit, AI-generated test steps, target URLs, browser screenshots, execution logs, and reports. A run may also record a video of the browser session and a Playwright trace, which captures the network requests and DOM snapshots taken while your test ran. These are stored so you can review past runs and replay saved procedures.

Browser session state from the site under test

This is the most sensitive category we touch, so it is worth stating plainly. To run a test we drive a real browser against the site you point us at. When a test signs in, the browser accumulates that site's cookies, localStorage and session state, and we store them so a later run can reuse the login instead of signing in again. In practice that is a live session for a third-party system, held on your behalf.

We encrypt these artifacts with AES-256-GCM before they are written to the database, and we do not share them with anyone beyond the infrastructure providers listed in section 4. Do not point Testorim at an account you would not be willing to have us hold a session for. Values typed into password, secret, token, PIN, OTP, CVV and similar fields are redacted from the stored step log, and the same values in a saved procedure are encrypted at rest and masked wherever the procedure is shown or exported.

Billing data

If you upgrade to a paid plan, our payment processor (Polar) collects payment method information directly. We do not see or store card numbers. We receive your customer ID, subscription status, and invoicing metadata.

Technical data

IP address, browser type, and approximate location for security, abuse prevention, and debugging. Error reports go to Sentry. Product analytics go to PostHog, and only if you have agreed to them in the app. What PostHog receives is: an opaque account identifier, your organisation identifier, your plan, the pages you open inside the app, and a short list of product events (signing in, creating a project, finishing a test, saving a procedure, upgrading) with the project, run and step counts attached. The hostname of the site a project points at is included when a project is created. We do not send your email address or your name to PostHog, and click-level autocapture is switched off.

With the same consent, Microsoft Clarity records how the app is used: where you click and scroll, and a replay of your session. The live browser view of the site you are testing and the chat where you write test instructions are masked in those recordings, so the screenshots of your site and any credentials you type into a test are not captured. Clarity is off until you accept it and stops, with its cookies removed, if you withdraw.

4. How we use your data, and who processes it

  • To provide, operate, and secure the Service.
  • To enforce plan limits and prevent abuse.
  • To send essential transactional email (account, billing, security).
  • To debug failures and diagnose issues you or other customers experience.
  • To understand which parts of the product are used, so we know what to build and fix next.

We do not sell your personal data, and we do not use Your Content to train AI models.

The Service runs on top of the following processors. Each is bound by a data processing agreement or equivalent:

  • Google Cloud Platform (us-east1): the virtual machine that serves the application, the API, our database and the browsers your tests run in.
  • Clerk: authentication and identity.
  • Anthropic: your test descriptions and page snapshots are sent to Claude to generate test steps and reports. Content is not retained by Anthropic for model training.
  • Polar: subscription billing and payment processing.
  • Cloudflare R2: object storage for screenshots, session video, Playwright traces, visual-regression baselines, fixtures you upload, files a test downloads, and encrypted database backups.
  • Vercel: hosting for this website.
  • Resend: transactional email (welcome, billing notifications, alerts you configure, the waitlist confirmation).
  • Upstash: rate-limiting infrastructure.
  • Sentry: error tracking.
  • PostHog: product analytics, only with your consent.
  • Microsoft Clarity: session recordings and heatmaps in the app, only with your consent, with the test browser view and the chat masked.

Two further destinations are optional and only ever receive data after you connect them yourself:

  • Slack: if you connect a workspace, run results are posted to the channel you choose.
  • GitHub: if you install our app on a repository, run results are posted as pull-request comments.

We also disclose data where required by law, legal process, or to protect the rights, property, or safety of our users or the public.

5. Who controls the data you submit

The split matters, because it decides who answers to whom.

  • For your account (your email, your organisation, your billing record) we are the controller.
  • For everything inside a test run (the target you chose, the steps you wrote, the test data and credentials you supplied, and whatever your application rendered into the resulting screenshots, page text and stored browser state) you are the controller and we act as your processor, on your instructions.

Because you are the controller of run content, you are responsible for having a lawful basis for any personal data that reaches it, for telling the people it concerns, and for answering their requests. You agree not to submit special-category data, payment card data, or the personal data of third parties into test inputs unless you have that basis and have told us in writing.

A practical consequence worth stating plainly: a test run against a real application captures whatever that application displays. If you run against production with real customer records on screen, those records land in your run evidence. Use test accounts and seeded data. We cannot know what your application will render, and we do not inspect run content to find out.

6. Data retention

Waitlist addresses are kept until we have sent the announcement email, or until you ask to be removed, whichever comes first. We keep your account data for as long as your account is active.

Run history is kept for the period included with your plan: 30 days on Starter, 90 days on Pro and 365 days on Team, counted from when the run finished. When a run passes that age, the run and everything captured with it (its report, screenshots, video, trace and any downloaded files) are deleted automatically. Saved procedures and visual baselines are not runs and are kept until you delete them. Archiving a project hides it from your workspace but does not shorten its retention; if you need specific runs deleted sooner, email us and we will remove them.

To close your account and have your data deleted, email us at the address in section 1. We complete deletion within 30 days, except where retention is required by law (for example, billing records kept for tax purposes) and except for copies held in routine backups, which expire within a further 30 days (section 7).

7. Security

Data in transit is encrypted with TLS. Authentication is handled by Clerk and we never store your password. The session state captured from the sites you test, the database credentials and integration tokens you supply, the cookies attached to test environments, and the password values in saved procedures are all encrypted with AES-256-GCM before they are stored, using a key held outside the database. Our hosting and object storage providers encrypt disks at rest. We take periodic encrypted backups of the database, which are kept for up to 30 days; a copy of data you have deleted may therefore persist in a backup for up to that long before it is gone. Access to production systems is limited to authorised personnel.

No method of transmission over the internet and no method of electronic storage is completely secure. We work to protect your data with the measures described above, but we cannot guarantee absolute security, and we do not warrant that the Service or your data will be free from unauthorised access. You are responsible for keeping your own account credentials and API keys secret, and for the security of the accounts you use inside test runs.

8. Your rights

Depending on your jurisdiction (for example under GDPR or CCPA), you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data.
  • Export your data in a portable format.
  • Object to certain types of processing.
  • Withdraw consent to analytics, at any time, without penalty.

To exercise these rights, email info@fulgic.com. We respond within 30 days. You also have the right to complain to your local data-protection authority.

9. Cookies in the app

The app uses a strictly necessary cookie to keep you signed in, set by Clerk. It is what makes an authenticated session work, so it is not optional and is not covered by the analytics choice.

The app's analytics providers, PostHog and Microsoft Clarity, each store a first-party cookie and a browser identifier scoped to the app's own domain. Both are off until you accept them in the app: neither provider's code is even downloaded until you do, so nothing is written and nothing is sent before you decide. You can change your answer at any time from the Cookie preferences control in the app footer. We do not use advertising cookies.

10. International transfers

Our providers operate outside some users' home countries, including in the United States. Where data leaves your region it is transferred under the safeguards those providers offer, such as standard contractual clauses.

11. Children

The Service is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email, by notice on this site or in the app at least 14 days before they take effect, and the date at the top of this page will change.

13. Contact

Questions about privacy? Email info@fulgic.com.