What we capture, and where it goes.
AxonQA explores your application, clicks through it and takes pictures of it. You should know exactly what that means before you point it at anything. Every item below is listed with where it is stored, how long we keep it, and whether it reaches an AI provider.
Where something is a limitation rather than a reassurance, it is on this page too.
Data inventory
Everything AxonQA captures.
Twelve things, in full. Nothing is captured that is not on this list.
| What we capture | Why | Where it lives | How long | Reaches AI |
|---|---|---|---|---|
| Account detailsName, email address, password hash, two-factor secret | Create your account and sign you in | SupabaseIreland | Life of the account | Never sent |
| Sign-in and security eventsWho did what and when, including IP address | Security audit trail | SupabaseIreland | 12 months | Never sent |
| Your test contentRequirements, test cases, plans, automation code, results | The product itself | SupabaseIreland | Life of the account | Only when you ask |
| ScreenshotsImages of your application during exploration and test runs | Evidence, failure diagnosis, visual comparison | Cloudflare R2Western Europe | 90 days | Sent, not redacted |
| Videos, traces and HAR filesRecordings of a run and its network activity | Diagnosing a failure after the fact | Cloudflare R2Western Europe | 30 days | Never sent |
| Visual baselinesThe reference image a later run is compared against | Visual regression testing | Cloudflare R2Western Europe | Until you delete the test | Never sent |
| Page structureThe DOM of a page: elements, forms, attributes | Building locators and healing broken ones | SupabaseIreland | Life of the account | Text-scrubbed |
| Captured requestsRequests your application makes while being explored | Discovering your API surface | SupabaseIreland | Life of the account | Text-scrubbed |
| Console outputErrors and warnings your application logs | Page health signals | SupabaseIreland | Life of the account | Text-scrubbed |
| Test credentialsLogins you supply so tests can sign in to your application | Running tests that need an authenticated session | Supabase, AES-256-GCM encryptedIreland | Until you remove them | Never sent |
| Integration tokensJira, Azure DevOps and similar | Importing the issues you choose to import | Supabase, AES-256-GCM encryptedIreland | Until you disconnect | Never sent |
| Billing detailsContact and subscription data. Card details go straight to Stripe and we never store them | Taking payment | StripeSee subprocessors | As tax law requires | Never sent |
Screenshots are images, and we do not redact them.
We strip secrets and common identifiers from text before it reaches a model, everywhere, without exception. We cannot yet do the same to a picture. If your application displays personal data on screen, a screenshot of that screen will contain it, and that screenshot may be sent to an AI provider for analysis. Use a staging environment with representative rather than real data where you can.
European, except where it is not.
Your database, the application and your stored artifacts are all in Europe. Test execution can run in the United States, and our AI and email providers are US-based.
We do not claim EU-only data residency, because it would not be true.
Every transfer out of the UK and EU is covered by Standard Contractual Clauses and the UK Addendum with the provider concerned.
- DatabaseSupabase PostgreSQLIreland
- ApplicationVercelDublin
- Artifact storageCloudflare R2Western Europe
- Website analyticsPlausible, cookielessEuropean Union
- Test executionGoogle Cloud RunBelgium and United States
- AI processingAnthropic, OpenAIUnited States
- EmailResendUnited States
Run tests through the local agent instead and execution never leaves your own network.
Retention
How long we keep it.
Every window below is enforced by a scheduled job that deletes the data. None of them is a statement of intent.
- Screenshots90 daysSwept nightly at 02:00. Baselines are exempt and deleted with their test.
- Videos, traces, HAR30 daysSame nightly sweep. These are the storage cost, and the shortest window on this page.
- Security audit log12 monthsAppend-only, and purged by the same nightly sweep. It deliberately outlives a deleted account, because a security record that could be erased on request would not be a security record.
- Everything else you createdLife of the accountRemoved when you delete your account, or 30 days after an account is terminated.
- Backups7 further daysDeleted data persists this long in encrypted daily backups before ageing out.
Getting it deleted
- Delete it yourself, immediately. Account settings has a delete control. It is a real cascade delete, not a flag on a row, and it collects your stored files for removal before it runs.
- Delete a project or a run at any time, with the same treatment for its artifacts.
- If an account is terminated, we delete it after 30 days, and email the account administrators at 30, 7 and 1 days first so nobody is surprised.
- Ask us instead at privacy@axonqa.com and we will respond within one month.
What the AI sees
- Only what the task needs. Diagnosing a failed step sends that step and its context, not your workspace.
- Text is scrubbed first. Tokens, keys, passwords, card numbers and typed input values are stripped before any model call, at every point where content leaves the platform.
- Your content never trains a model. We use the commercial APIs, which do not train on customer data.
- Providers hold API content briefly. Anthropic and OpenAI each retain inputs and outputs for around 30 days for abuse monitoring. We do not currently have zero-retention terms, and we would rather say so than imply otherwise.
What we never do.
- We never sell your data.
- We never use your content to train AI models.
- We run no product analytics inside the application. What happens in your workspace is answered from our own records, not a tracker.
- We set no advertising or tracking cookies, which is why this site never asks you to accept any.
The documents behind this page
This page is a summary. The privacy policy sets out our lawful basis for each purpose and your rights over your data. Our security overview, subprocessor list and data processing agreement are available for your security team, and we will complete your security questionnaire.
Reviewed quarterly. Last reviewed 28 August 2026.
Ready to see AxonQA on your own app?
Create a project and generate your first test cases in minutes.