AlloyQA
How it worksSign inCreate account
Contents01Information We Collect02How We Use Your Information03Data Storage & Retention04Third-Party Services05Data Sharing06OAuth Tokens & Integration Security07Cookies & Local Storage08Your Rights & Choices09Children's Privacy10Security11Changes to This Policy12Contact Us
Legal

Privacy
Policy

AlloyQAEffective August 2, 202612 sections

This Privacy Policy explains how AlloyQA collects, uses, stores, and shares information when you use AlloyQA.

AlloyQA is an AI software engineer that takes assigned Jira work through development and testing, then returns it with evidence for approval. The Service is available at alloyqa.com ("Service"). This policy applies when you access or use the Service.

AlloyQA performs actions according to configured workflow rules and approval boundaries. Important product decisions, pull-request approval and production deployment remain under your team’s control.
01

Information We Collect

We collect information in three ways:

A — Directly from You

  • Account credentials — your email address and authentication information handled by Supabase Auth. AlloyQA does not store your password in plaintext.
  • Access-request information — work email, company name, role, selected delivery tools, and optional request context submitted when asking for access.
  • Ticket and delivery content — issue titles, descriptions, acceptance criteria, comments, workflow status, linked context, approved decisions, bug attachments, and reproduction evidence from tickets you connect or assign through Jira or GitHub.
  • Repository and code context — repository source code and configuration, branches, commits, pull requests, generated code changes, and delivery status from connected version control systems.
  • Execution and test data — commands, execution logs, test results, screenshots, browser traces, and console output generated during development and verification runs.
  • Integration credentials — OAuth tokens and API keys for connected services, encrypted before storage.

B — Automatically

  • Usage data — features used, delivery runs initiated, workflow status changes, and interactions with the Service.
  • Log data — IP address, browser type, operating system, and request timestamps.
  • Session data — authentication session tokens managed by Supabase.

C — From Third-Party Integrations

When you connect external tools, we access only the data necessary to provide the Service:

  • Atlassian Jira — issue content, workflow status, comments, attachments, and project metadata needed to process tickets, update status, and return completed work for review.
  • GitHub — repository source code, configuration, branches, commits, pull requests, diffs, comments, and status checks needed to investigate issues, develop changes, run tests, and create pull requests.
02

How We Use Your Information

We use the information we collect to:

  • Explore connected repositories to understand codebase architecture, configuration, and patterns.
  • Reproduce reported issues and verify expected behaviour.
  • Generate and modify code to implement requested changes and bug fixes.
  • Run repository and browser tests to verify delivered changes.
  • Create branches, commits, and pull requests in connected version control systems.
  • Update Jira delivery status as work progresses.
  • Produce verification evidence, execution logs, screenshots, and browser traces for review.
  • Prepare ticket and pull request updates for your team to review and approve.
  • Authenticate your identity and maintain your session securely.
  • Monitor Service performance, diagnose errors, and prevent abuse.
  • Communicate with you about your account or material changes to this policy.
03

Data Storage & Retention

Account, integration and delivery records are retained while your account is active and as needed to operate the Service. Temporary repository working files created by the managed runner are deleted after each run. Pull-request records, execution status, screenshots, videos and other verification evidence may be retained to provide delivery history, troubleshooting and auditability until deleted through available product controls or upon a valid deletion request, subject to legal and operational requirements.

04

Third-Party Services

The Service integrates with and relies on the following third-party providers:

  • Supabase — database, authentication, and storage infrastructure.
  • Netlify — application and serverless hosting.
  • Google Cloud — managed cloud infrastructure used to run delivery workers and temporarily process repository code, ticket context, tests, and verification artifacts.
  • OpenAI — enterprise AI infrastructure used for code generation, bug reproduction, browser test generation, and verification workflows.
  • PostHog — limited product analytics with automatic interaction capture and session recording disabled.
  • Resend — transactional and product email.
  • Atlassian Jira — issue tracking platform we connect to.
  • GitHub — version control and pull request platform we connect to.

Each third-party service is governed by its own privacy policy. These providers process information under their own terms and privacy notices. We transmit only the data required to perform the action requested.

05

Data Sharing

We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:

  • With connected third-party integrations (Jira, GitHub), at your direction, to inspect repositories, create branches, post pull requests, update ticket status, and return evidence for review.
  • With service providers (including Google Cloud and OpenAI) to process ticket context, repository code, execution logs, and generated changes for development and verification workflows.
  • With service providers who help us operate the platform, under confidentiality obligations.
  • If required by law, regulation, or valid legal process, or to protect the rights and safety of AlloyQA and its users.
  • In connection with a merger, acquisition, or sale of assets — we will notify you before your data is transferred.
06

OAuth Tokens & Integration Security

When you connect Atlassian Jira or GitHub via OAuth or API key, integration credentials are encrypted before storage. These tokens are used only to perform actions you initiate or configure within AlloyQA, such as reading issue context, exploring repositories, creating branches and pull requests, running tests, and updating ticket status.

You can revoke any integration at any time from the Integrations settings panel. Disconnecting removes the stored credentials from our database. You should also revoke access from the provider's own settings to fully terminate the connection.

07

Cookies & Local Storage

The Service uses session cookies managed by Supabase Auth to keep you logged in. We do not use third-party advertising cookies or tracking pixels.

We use PostHog analytics to understand how AlloyQA is used. We do not use advertising cookies or sell analytics data.

To prevent data loss if you accidentally refresh your page, active working session data may be temporarily held in your browser's sessionStorage. This data remains strictly local to your device and is automatically erased when the tab or window is closed.

08

Your Rights & Choices

Depending on your jurisdiction and applicable law, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request that we correct inaccurate or incomplete data.
  • Deletion — request that we delete your account and associated data.
  • Portability — request your saved data in a machine-readable format.
  • Objection — object to certain processing activities.

These rights may vary depending on your location and applicable law. To exercise any of these rights, contact us at privacy@alloyqa.com. We will respond within the period required by applicable law.

09

Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10

Security

AlloyQA uses TLS/HTTPS for data in transit, encrypts stored integration credentials, and applies authentication, workspace authorization, administrator permissions, and database access controls to protect customer information.

However, no method of transmission over the internet is 100% secure. We encourage you to use strong, unique passwords and to revoke integration tokens promptly if you suspect unauthorized access.

11

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a revised effective date. Your continued use of the Service after changes are posted constitutes acceptance. For significant changes, we will make reasonable efforts to notify you by email.

12

Contact Us

For privacy questions or requests, contact us at privacy@alloyqa.com.

AlloyQA
Last updated: August 2, 2026
AboutPrivacyTermsSecurityContact
© 2026 AlloyQA