Privacy Policy
Last updated 2 August 2026
This policy explains what data AxonQA collects, why, how AI processing works, who our subprocessors are, and the rights you have over your data. It is written to be read, not skimmed past.
The short version
We collect what the service needs
Your account details, your workspace content, and the artifacts your testing produces. No advertising trackers, no data brokers.
AI never trains on your data
Axon uses AI providers to do its work. Secrets and personal data are scrubbed before any AI call, and your data is not used to train models.
Encrypted and isolated
Encryption in transit and at rest, two-factor authentication, role-based access, and organization-level tenant isolation.
Your rights are real
Access, correct, export, or delete your data at any time by emailing privacy@axonqa.com. We respond within 30 days.
The summary is for orientation only; the numbered sections below are the full, binding text.
1.Who we are
AxonQA Ltd (“AxonQA”, “we”, “us”) is a company registered in England and Wales, company number 17382382, with its registered office at 82A James Carter Road, Mildenhall, IP28 7DE, United Kingdom.
We provide an AI-powered quality assurance platform at axonqa.com: test creation, test automation, API testing, app exploration, and quality insight in one workspace.
For the personal data of people who create and use AxonQA accounts, we act as the data controller. For the content of the applications you test with AxonQA (your product, your test data, your users’ data where it appears in screenshots or recordings), we act as a data processor on your instructions.
Privacy questions and requests: privacy@axonqa.com. Your use of AxonQA is also governed by our Terms of Service, and the controls behind this policy are described on our Security page.
2.Data we collect
Account data. Name, email address, a hashed password (we never store the plain text), two-factor authentication settings, and your role within your organization.
Workspace content. The projects, epics, stories, test cases, test plans, runs, and reports you create in AxonQA, and any documents or screenshots you add to a project’s knowledge base.
Connected content. Work items and test cases you import from tools you connect, such as Jira, Azure DevOps, TestRail, or Zephyr Scale. We store the connection tokens you authorize, encrypted.
Testing artifacts. Screenshots, run videos, step logs, network captures, and exploration maps produced when AxonQA tests or explores your application. These can incidentally contain personal data shown inside your application; you control what AxonQA is pointed at.
Credentials you store. Login credentials and API keys for the applications you test. These are encrypted with AES-256-GCM and used only to run the testing you configure.
Usage and security data. Audit trails of writes and security-relevant events in your workspace, including Axon AI writes, sign-in events, and technical logs needed to keep the service secure and reliable.
Support communications. Emails you send to our support, sales, security, or privacy addresses.
We do not run advertising trackers or sell personal data to anyone.
3.How we use data
- To provide the service: running your tests and crawls, storing results, generating tests with AI, and showing your team its own data. Legal basis: performance of our contract with you.
- To keep accounts secure: authentication, two-factor codes, audit trails, rate limiting, and abuse prevention. Legal basis: legitimate interests.
- To communicate: transactional email such as verification, alerts you configure, run notifications, and replies to your requests. Legal basis: performance of contract and legitimate interests.
- To bill: when paid plans go live, processing payment through a payment provider. Legal basis: performance of contract.
- To improve AxonQA: aggregate, de-identified usage patterns. We do not use the content of your projects to improve or train AI models.
4.How AI processing works
Axon AI generates tests, explores applications, heals broken tests, and answers questions about your workspace. To do that, relevant content (for example a user story, a page structure, or a failing test step) is sent to our AI subprocessors for processing.
- Secrets, credentials, and common patterns of personal data are scrubbed before any AI call.
- Your data is never used to train our models or our providers’ models.
- AI usage is logged per organization, and destructive actions always require your explicit confirmation.
5.Subprocessors
We rely on a small set of infrastructure and AI providers to run AxonQA. Each processes data only to provide its function, under its own data protection terms.
| Provider | Purpose |
|---|---|
| Supabase | Managed PostgreSQL database hosting |
| Google Cloud | Cloud test runners, app exploration workers, and application infrastructure |
| Cloudflare | Storage of testing artifacts (screenshots, videos) and content delivery |
| Anthropic | AI processing for test generation, exploration, and the Axon assistant |
| OpenAI | AI processing for selected tasks and as a fallback provider |
| Resend | Transactional and notification email delivery |
| Upstash | Rate limiting infrastructure |
We will update this list before adding a new subprocessor, including a payment provider when paid plans go live. A copy of our data processing addendum is available on request from privacy@axonqa.com.
6.How long we keep data
The windows below are enforced by scheduled jobs that delete the data. They are not a statement of intent. Your results and run history are kept for the life of the account; it is the heavy evidence that expires, and you can export anything you need to keep.
- Account and workspace data: kept while your account is active.
- Screenshots: 90 days from the run, swept nightly. Visual comparison baselines are exempt and are deleted with the test they belong to, because expiring one would silently break the comparison it exists to serve.
- Run videos, traces, and HAR files: 30 days from the run.
- Security audit log: 12 months, purged by the same nightly job. It records who did what and when, including the IP address of the action, and it is append-only. It is deliberately kept after an account is deleted, because a security record that could be erased on request would not be a security record, which is permitted under Article 17(3) UK GDPR.
Self-serve deletion is immediate. Where an agreement ends without a deletion request, associated data is removed from live systems within 30 days. Deleted data then persists for up to a further 7 days in encrypted daily backups before those age out; we do not restore backups to reinstate deleted data. Deletion removes the stored files as well as the database records.
A fuller breakdown, item by item with where each is stored and whether it reaches an AI provider, is on our data handling page.
7.How we protect data
Encryption in transit and at rest, two-factor authentication, role-based access checked on every request, organization-level tenant isolation, private artifact storage with short-lived signed links, encrypted secrets, and audit trails. The full picture, including what is in place and what is on our roadmap, is on the Security page.
If we become aware of a personal data breach affecting you, we will notify you without undue delay and support your own notification obligations.
8.Your rights
Under UK and EU data protection law you can ask us to: access the personal data we hold about you, correct it, delete it, export it in a portable format, restrict or object to certain processing, and withdraw consent where processing is based on consent.
Email privacy@axonqa.com and we will respond within 30 days. You can also export your test cases and results yourself from inside the product at any time. If you are unhappy with our answer, you can complain to the UK Information Commissioner’s Office (ico.org.uk) or your local supervisory authority.
10.International transfers
Our subprocessors operate in the United Kingdom, the European Economic Area, and the United States. Where personal data leaves the UK or EEA, we rely on our providers’ standard contractual clauses and the UK addendum, alongside the technical measures described above.
11.Children
AxonQA is a business tool and is not directed at children. You must be at least 18 to create an account.
12.Changes and contact
When this policy changes materially we will update the date at the top and notify account owners by email before the change takes effect.
Questions, requests, or concerns: privacy@axonqa.com.
Questions about your data?
Email privacy@axonqa.com, or read how we protect your data on the Security page.