QAce
Product How it works Pricing Privacy
Sign in Start free →
Legal

Privacy Policy

Last updated: July 18, 2026 · Effective: July 18, 2026

This policy explains what QAce (“QAce”, “we”, “us”), operated by drinktea, collects when you use qace.io and the QAce platform, how we use and share it, and the choices and rights you have. QAce is an agentic end-to-end testing platform: we necessarily process data about the web apps you test and the results we generate.

On this page
  1. Who we are & scope
  2. Information we collect
  3. QA data you capture
  4. How we use information
  5. AI & LLM processing
  6. Cookies & local storage
  7. How we share information
  8. Data retention
  9. Security
  10. Your rights & choices
  11. International transfers
  12. Children’s privacy
  13. Changes to this policy
  14. Contact us

01 Who we are & scope

QAce is a product of drinktea. This policy covers the QAce marketing site at qace.io, the QAce dashboard, the in‑page QAce overlay/agent, the CLI, and the QAce API (together, the “Service”).

When you use QAce to test your own application, you are the controller of the data captured from that application and QAce acts as your processor for it, handling it on your behalf and under your instructions. For your own account and billing details, QAce is the controller. This policy does not cover third‑party websites or applications you test with QAce.

02 Information we collect

Account & profile

  • Identity — name and email address you provide at sign‑up, and a securely hashed password (we never store your password in plain text).
  • Single sign‑on — if you sign in with Google, GitHub, or an enterprise OIDC provider, we receive your verified email, name, and a provider subject identifier to link the account.
  • Team & project data — team names, project names, membership roles, and per‑project keys/tokens you create.

Billing

  • Subscription data — your plan, subscription status, and billing contact email.
  • Payment details — card and payment credentials are entered directly with our payment processors (Stripe, PayPal, or PayTabs) and are not stored on QAce servers. We retain only a processor reference and status.

Usage & technical

  • Log & device data — IP address, browser/user‑agent, timestamps, and pages/actions within the dashboard, used for security, debugging, and abuse prevention.
  • Audit records — security‑relevant actions (sign‑in, role/config/key changes) are recorded with actor, target, and time.

03 QA data you capture

The core of QAce is capturing evidence from the app under test so it can be analyzed and reported. Depending on how you use it, this can include:

  • Session events — clicks, form fills (field, label, and value), submissions, and navigations you record.
  • Screenshots & DOM snapshots — captured in the browser, including element selectors, geometry, text, and trimmed markup.
  • Console & network diagnostics — console errors/warnings and failed network requests observed during a session.
  • Annotations, test plans, and run results — the issues, steps, verdicts, and reports QAce generates.
Sensitive fields are redacted at capture. The overlay redacts values from password and payment‑card inputs before they leave the browser. QAce is a testing tool: please point it at test/staging environments and avoid capturing real end‑user personal data or production secrets. You control what you record, and you can delete sessions, screenshots, and reports at any time.

04 How we use information

  • Provide the Service — authenticate you, run and heal tests, generate reports, and store your projects and results.
  • AI analysis — analyze captured evidence to produce root‑cause hypotheses, fixes, and test plans (see §5).
  • Billing & entitlements — manage subscriptions, seats, and plan limits.
  • Security & integrity — detect, prevent, and investigate abuse, fraud, and technical issues.
  • Communications — respond to support requests and send essential service notices. We do not sell your data.
  • Legal — comply with applicable law and enforce our terms.

We rely on the following legal bases where GDPR applies: performance of a contract (providing the Service), legitimate interests (security, improving the product), consent (where required, e.g. non‑essential cookies), and legal obligation.

05 AI & LLM processing

QAce uses large language models to analyze issues, write and heal tests, and build test plans. To do this, relevant captured evidence (for example an annotation, DOM/selector context, console/network errors, and detected tech stack) is sent to an LLM gateway configured for the platform. Prompts are engineered to reason from observable browser behavior and your provided context.

  • We send the minimum context needed for the requested analysis.
  • Your captured data is used to serve your results; QAce does not use it to train foundation models.
  • The configured model provider processes prompts under its own terms; enterprise deployments can point QAce at a self‑hosted or private gateway.

06 Cookies & local storage

We use a small number of strictly necessary cookies and browser storage to run the Service:

Session tokenAn HttpOnly cookie (qa_token) that keeps you signed in. Its lifetime follows your session‑timeout setting.
Local storageStores your auth token and UI preferences in your browser so the dashboard and overlay work across page loads.
OAuth stateA short‑lived cookie used only during a sign‑in redirect to prevent CSRF.

These are essential to the Service and are not used for advertising. We do not run third‑party advertising or cross‑site tracking cookies.

07 How we share information

We do not sell your personal information. We share it only with service providers (sub‑processors) that help us run QAce, and only as needed:

  • AI / LLM gateway — processes prompts to generate analysis and test plans.
  • Payment processors — Stripe, PayPal, and/or PayTabs handle checkout and subscriptions.
  • Cloud & object storage — hosting and, where enabled, S3‑compatible object storage for screenshots and artifacts.
  • Integrations you enable — when you connect GitHub, Jira, or Slack, QAce sends the data needed to post comments, statuses, issues, or messages to those services on your instruction.

We may also disclose information to comply with law, respond to lawful requests, protect our rights and users, or in connection with a merger, acquisition, or asset sale (with continued protection under this policy).

08 Data retention

We keep information for as long as your account is active or as needed to provide the Service. QA sessions, screenshots, run history, and reports are retained until you delete them or according to your plan’s history limits. Audit records and billing records are kept as required for security and legal/accounting purposes. When you close your account, we delete or anonymize your data within a reasonable period, except where retention is legally required.

09 Security

  • In transit — traffic to qace.io is served over HTTPS/TLS.
  • Passwords — hashed with a strong, salted algorithm (scrypt); never stored in plain text.
  • Secrets at rest — platform credentials (API keys, provider secrets) are encrypted at rest with authenticated encryption.
  • Access controls — role‑based access, revocable sessions, optional multi‑factor authentication, and audit logging.

No method of transmission or storage is completely secure, but we work to protect your data using appropriate technical and organizational measures.

10 Your rights & choices

Depending on where you live (for example under the GDPR or CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. You can:

  • Update your profile and change your password in the dashboard.
  • Delete sessions, screenshots, reports, and projects directly in the app.
  • Enable or disable integrations and rotate your keys/tokens at any time.
  • Request account deletion or exercise any right by emailing us (see §14).

We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.

11 International transfers

QAce and our sub‑processors may process data in countries other than yours. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross‑border transfers of personal data.

12 Children’s privacy

QAce is a developer tool intended for use by adults in a professional capacity. It is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

13 Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of QAce after an update means you accept the revised policy.

14 Contact us

Questions, requests, or privacy concerns? We’re happy to help.

QAce — a product of drinktea

Email: accounts@drinktea.io

Web: qace.io · drinktea.io

QAce

An AI QA engineer that maps your app, writes the tests, runs them in a real browser, and gates every pull request.

Product

Overview How it works Pricing Start free

Surfaces

Browser overlay VS Code extension Chrome extension CI & PR gate

Company

Contact Privacy Sign in
© 2026 QAce by drinktea