Privacy Policy

Effective September 20, 2026

1. Overview

This Privacy Policy explains how X & Company LLC ("X & Company LLC", "we", "us", or "our") collects, uses, and shares information in connection with TestKit, our test case management software-as-a-service platform available at testkit.app (the "Service"). It applies to visitors to our marketing pages and to registered users of the Service. It should be read alongside our Terms of Service.

2. Information We Collect

We collect the following categories of information:

  • Account information: your name, email address, and password (stored only as a salted hash — we never store or have access to your plaintext password). If you sign in with Google, we receive your name, email address, and Google account identifier from Google.
  • Your Content: the test cases, test suites, test runs, test plans, releases, attachments, and any other data you or your team members submit to the Service, as described in our Terms of Service.
  • Billing information: if you subscribe to a paid plan, our payment processor, Stripe, collects your payment card details directly. We receive only a billing identifier, subscription status, and related metadata from Stripe — we never see or store your full card number.
  • Integration credentials: if you connect a third-party tool such as Jira or Slack, we store the API token or webhook URL you provide, encrypted at rest, solely to perform the integration you configured.
  • Usage and device information: IP address, browser type, and general usage activity (such as pages visited and actions taken within the Service), collected automatically for security, rate-limiting, and troubleshooting purposes.
  • Communications: if you contact us (for example, via legal@testkit.app or our Contact page), we keep a record of that correspondence.

3. Cookies and Session Storage

Signing in sets two small, essential cookies on your browser — one identifying your session, and one used only to refresh it — both marked HttpOnly, so they cannot be read by JavaScript running on any page (ours or anyone else's), and Secure wherever the Service is served over HTTPS. These cookies are required for the Service to function (you cannot stay signed in without them) and are not used for advertising or cross-site tracking. If a member of our support team temporarily views your account to help diagnose an issue (see Section 7), a third cookie marks that session as a support-initiated view so it can be safely handed back.

We also use two third-party tools that set their own cookies or similar browser storage, described further in Section 8: Google Ads, to measure whether a visit that started from one of our ads led to a sign-up (present only on our homepage, pricing, test case management, and sign-up/verification pages — not on this page); and PostHog, our product analytics provider, present across the whole Service including our marketing pages, to understand how it's used — which pages are visited and which features are used — including by signed-in users, whom PostHog identifies by account ID and email so usage can be tied to a real account. Neither is used to show you ads on other sites.

4. How We Use Information

We use the information we collect to:

  • Provide, maintain, and secure the Service, including authenticating you and keeping your account and Your Content accessible only to you and those you authorize;
  • Process payments and manage subscriptions through Stripe;
  • Send transactional email, such as email verification codes, password reset links, and release digests you or your team have configured (delivered via Amazon SES);
  • Check proposed passwords, at signup and at reset, against a breach database (Section 5) to warn you away from a password already known to be compromised;
  • Operate AI-assisted features, such as AI test case and test strategy generation, which send content you explicitly submit for that purpose to our AI provider (Section 6);
  • Respond to support requests and, where you've asked us to, troubleshoot issues with your account;
  • Detect, prevent, and investigate fraud, abuse, and security incidents; and
  • Comply with legal obligations.

We do not sell your personal information, and we do not use Your Content to train AI models offered to other customers.

5. Password Breach Checking

When you set or reset a password, we check it against the Have I Been Pwned Pwned Passwords database to warn you if it has appeared in a known data breach. This check only ever sends the first five characters of a one-way hash of your password to that service — never your password itself, and never the full hash. If that check fails or is unreachable, we let account creation or reset proceed rather than block you; it is a courtesy check, not a gate enforced against you.

6. AI-Assisted Features

When you use an AI-assisted feature (such as AI test case or test strategy generation), the input you provide for that request — and only that input, not your broader account data — is sent to our AI provider, Anthropic, to generate the output. We do not send Your Content to any AI provider except when you affirmatively invoke one of these features.

7. Support Access to Your Account

Our support staff can view account details to help resolve support requests, and, in limited cases, a support administrator can temporarily view the Service as you would see it ("impersonation") to reproduce or confirm a bug you've reported. Impersonation is logged, restricted to support administrators, and never used to access another support account. You can request an export or deletion of Your Content at any time; see Section 9.

8. How We Share Information

We share information only as follows:

  • Service providers who process information on our behalf to operate the Service: Amazon Web Services (hosting and infrastructure), Stripe (payment processing), Amazon SES (transactional email delivery), Anthropic (AI-assisted features you invoke), Cloudflare (bot-mitigation on our registration form), and Have I Been Pwned (password breach checking, as described in Section 5). Each is bound by its own terms to use information only to provide its service to us.
  • Analytics and advertising: PostHog (product analytics — page views and feature usage across the Service, tied to your account ID and email once you're signed in) and Google Ads (conversion tracking on select marketing and sign-up pages only, to measure ad performance), as described in Section 3. Each is bound by its own terms to use information only to provide its service to us.
  • Third-party integrations you configure, such as Jira or Slack — data flows to these only when and as you set up the integration, governed by that provider's own terms.
  • Other members of your Team account can see Your Content, consistent with the access your account administrator has granted them within the Service.
  • Legal and safety — we may disclose information if required by law, subpoena, or legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of X & Company LLC, our users, or the public.
  • Business transfers — if X & Company LLC is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a policy at least as protective.

9. Data Retention and Deletion

We retain your account information and Your Content for as long as your account is active. You may delete your own account at any time from your account settings; if you are the last member of a Team account, deleting your account deletes the account and everything it owns. We may retain limited information after deletion where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.

10. Data Security

We use industry-standard safeguards to protect your information, including encryption in transit (TLS) and at rest for sensitive fields such as integration credentials, hashed (never plaintext) password storage, and httpOnly session cookies that are not readable by page scripts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. International Data Transfers

We are based in the United States and our infrastructure providers host data in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those of your jurisdiction.

12. Your Rights and Choices

Depending on your location, you may have rights to access, correct, export, or delete the personal information we hold about you, or to object to or restrict certain processing. You can access and update most account information directly from your account settings, export Your Content, or delete your account as described in Section 9. For any other request, contact us at legal@testkit.app and we will respond consistent with applicable law.

13. Children's Privacy

The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at legal@testkit.app and we will take steps to delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice, such as by emailing the address associated with your account or displaying a notice within the Service, before the changes take effect. Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes.

15. Contact Us

Questions about this Privacy Policy, or requests regarding your personal information, can be sent to legal@testkit.app.