Privacy Policy
Quality Assistant Lab (“QAL”, “we”, “our”) provides a browser extension and related cloud services that help software testers capture, structure, review and route bug reports. This policy explains what information QAL may process, why it is processed, how it is stored, and the choices available to users.
1. Information QAL may process
Depending on the features you choose to use, QAL may process:
- Account information such as email address and authentication status.
- Bug report text, including summaries, expected behavior, actual behavior, steps to reproduce, classification and technical notes.
- Page and environment metadata such as browser information, viewport size, URL context and selected-element information.
- Screenshot evidence that you explicitly capture for a report.
- Technical error evidence such as uncaught JavaScript errors, unhandled promise rejections, resource failures and failed network requests.
- Destination configuration needed to route reports to services such as GitHub, Jira, Linear, GitLab and Azure DevOps.
- Support messages you choose to submit.
2. Sensitive information QAL is designed not to collect in report evidence
QAL applies sanitization and redaction intended to reduce exposure of sensitive values. The current extension is designed to avoid including raw cookies, authorization headers, OAuth tokens, request or response bodies, passwords and similar secrets in Machine Learning improvement signals. URLs and technical text may also be sanitized before being used as evidence.
3. Screenshots and evidence
When screenshot evidence is used, QAL compresses screenshots before routing. The extension can create a derived evidence preview that marks the selected area while preserving the clean capture separately. Secure routed evidence may use private QAL storage with a temporary link rather than publicly accessible storage.
4. Local history
QAL may keep report history locally in the browser. Local history is intended to store report text and metadata and not raw screenshot image bytes. Users can clear local history from QAL settings.
5. Machine Learning improvements
If the Machine Learning improvements option is enabled, QAL may use sanitized report signals and user corrections to improve future classification and technical suggestions. Raw screenshots, cookies, request/response bodies, authorization headers and OAuth tokens are excluded from these improvement signals. Users can control this setting from QAL privacy settings.
6. Connected services
QAL can connect to third-party issue tracking and development services, including GitHub, Jira, Linear, GitLab and Azure DevOps. When you choose to connect or route a report to one of these services, the information required for that action is processed according to both this policy and the privacy terms of the selected third-party service.
7. Authentication and cloud processing
QAL uses cloud infrastructure for account authentication, billing-related access, integrations, support and selected evidence workflows. OAuth connection tokens used for supported integrations are handled by QAL Cloud. QAL access tokens are stored in browser session storage where supported by the extension architecture.
8. Contact and feedback forms
If you use QAL's website contact or feedback forms, we may process the name, email address, role/company information, rating and message content you choose to submit. Contact information is used to respond to your request. Feedback is not displayed publicly unless it has been reviewed and approved for publication. Email addresses are not displayed with public feedback.
10. Why QAL uses this information
- To provide account access and subscription features.
- To create and review bug reports.
- To attach technical evidence requested by the user.
- To route reports to connected issue trackers.
- To provide support and maintain product security.
- To improve QAL where the user has enabled applicable improvement features.
10. Data sharing
QAL does not sell personal information. Information may be shared with service providers required to operate QAL, or with third-party destinations that the user explicitly connects or chooses for report routing.
11. Data retention
Retention depends on the type of information and feature used. Local history remains in the browser until removed by the user or application lifecycle. Temporary evidence links are intended to expire after a limited period. Account, billing, support and integration data may be retained as required to provide the service, maintain security and meet legal obligations.
12. User choices
Users can review reports before routing them, control supported privacy settings, disconnect integrations, clear local report history and disable applicable Machine Learning improvement participation from QAL settings.
13. Permissions
The QAL browser extension requests browser permissions required for its current functionality, including storage, active-tab/tab access and access to web pages where the extension is used. These permissions support page-side QA capture, screenshot workflows, selected-element context and technical evidence collection.
14. Security
QAL uses technical and organizational measures intended to protect stored and transmitted information. No online service can guarantee absolute security, and users should avoid intentionally entering secrets into bug descriptions or reports.
15. Changes to this policy
We may update this Privacy Policy when QAL features, legal requirements or data practices change. The updated date at the top of this page will indicate the latest revision.
16. Contact
For privacy questions, users may contact QAL through the support channel provided in the product or on the official QAL website.