Privacy
Policy
This Privacy Policy explains how AlloyQA collects, uses, stores, and shares information when you use AlloyQA.
AlloyQA is an AI software engineer that takes assigned Jira work through development and testing, then returns it with evidence for approval. The Service is available at alloyqa.com ("Service"). This policy applies when you access or use the Service.
Information We Collect
We collect information in three ways:
A — Directly from You
- Account credentials — your email address and authentication information handled by Supabase Auth. AlloyQA does not store your password in plaintext.
- Access-request information — work email, company name, role, selected delivery tools, and optional request context submitted when asking for access.
- Ticket and delivery content — issue titles, descriptions, acceptance criteria, comments, workflow status, linked context, approved decisions, bug attachments, and reproduction evidence from tickets you connect or assign through Jira or GitHub.
- Repository and code context — repository source code and configuration, branches, commits, pull requests, generated code changes, and delivery status from connected version control systems.
- Execution and test data — commands, execution logs, test results, screenshots, browser traces, and console output generated during development and verification runs.
- Integration credentials — OAuth tokens and API keys for connected services, encrypted before storage.
B — Automatically
- Usage data — features used, delivery runs initiated, workflow status changes, and interactions with the Service.
- Log data — IP address, browser type, operating system, and request timestamps.
- Session data — authentication session tokens managed by Supabase.
C — From Third-Party Integrations
When you connect external tools, we access only the data necessary to provide the Service:
- Atlassian Jira — issue content, workflow status, comments, attachments, and project metadata needed to process tickets, update status, and return completed work for review.
- GitHub — repository source code, configuration, branches, commits, pull requests, diffs, comments, and status checks needed to investigate issues, develop changes, run tests, and create pull requests.
How We Use Your Information
We use the information we collect to:
- Explore connected repositories to understand codebase architecture, configuration, and patterns.
- Reproduce reported issues and verify expected behaviour.
- Generate and modify code to implement requested changes and bug fixes.
- Run repository and browser tests to verify delivered changes.
- Create branches, commits, and pull requests in connected version control systems.
- Update Jira delivery status as work progresses.
- Produce verification evidence, execution logs, screenshots, and browser traces for review.
- Prepare ticket and pull request updates for your team to review and approve.
- Authenticate your identity and maintain your session securely.
- Monitor Service performance, diagnose errors, and prevent abuse.
- Communicate with you about your account or material changes to this policy.
Data Storage & Retention
Account, integration and delivery records are retained while your account is active and as needed to operate the Service. Temporary repository working files created by the managed runner are deleted after each run. Pull-request records, execution status, screenshots, videos and other verification evidence may be retained to provide delivery history, troubleshooting and auditability until deleted through available product controls or upon a valid deletion request, subject to legal and operational requirements.
Third-Party Services
The Service integrates with and relies on the following third-party providers:
- Supabase — database, authentication, and storage infrastructure.
- Netlify — application and serverless hosting.
- Google Cloud — managed cloud infrastructure used to run delivery workers and temporarily process repository code, ticket context, tests, and verification artifacts.
- OpenAI — enterprise AI infrastructure used for code generation, bug reproduction, browser test generation, and verification workflows.
- PostHog — limited product analytics with automatic interaction capture and session recording disabled.
- Resend — transactional and product email.
- Atlassian Jira — issue tracking platform we connect to.
- GitHub — version control and pull request platform we connect to.
Each third-party service is governed by its own privacy policy. These providers process information under their own terms and privacy notices. We transmit only the data required to perform the action requested.
Data Sharing
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
- With connected third-party integrations (Jira, GitHub), at your direction, to inspect repositories, create branches, post pull requests, update ticket status, and return evidence for review.
- With service providers (including Google Cloud and OpenAI) to process ticket context, repository code, execution logs, and generated changes for development and verification workflows.
- With service providers who help us operate the platform, under confidentiality obligations.
- If required by law, regulation, or valid legal process, or to protect the rights and safety of AlloyQA and its users.
- In connection with a merger, acquisition, or sale of assets — we will notify you before your data is transferred.
OAuth Tokens & Integration Security
When you connect Atlassian Jira or GitHub via OAuth or API key, integration credentials are encrypted before storage. These tokens are used only to perform actions you initiate or configure within AlloyQA, such as reading issue context, exploring repositories, creating branches and pull requests, running tests, and updating ticket status.
You can revoke any integration at any time from the Integrations settings panel. Disconnecting removes the stored credentials from our database. You should also revoke access from the provider's own settings to fully terminate the connection.
Your Rights & Choices
Depending on your jurisdiction and applicable law, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that we correct inaccurate or incomplete data.
- Deletion — request that we delete your account and associated data.
- Portability — request your saved data in a machine-readable format.
- Objection — object to certain processing activities.
These rights may vary depending on your location and applicable law. To exercise any of these rights, contact us at privacy@alloyqa.com. We will respond within the period required by applicable law.
Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Security
AlloyQA uses TLS/HTTPS for data in transit, encrypts stored integration credentials, and applies authentication, workspace authorization, administrator permissions, and database access controls to protect customer information.
However, no method of transmission over the internet is 100% secure. We encourage you to use strong, unique passwords and to revoke integration tokens promptly if you suspect unauthorized access.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a revised effective date. Your continued use of the Service after changes are posted constitutes acceptance. For significant changes, we will make reasonable efforts to notify you by email.
Contact Us
For privacy questions or requests, contact us at privacy@alloyqa.com.