Last updated: February 16, 2026
NexGen QA Systems Inc. ("NexGen QA", "we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, store, and protect your information when you use our AI-powered quality assurance platform and marketing website.
Account Information: When you create an account, we collect your name, email address, organization name, and role. Passwords are hashed using bcrypt with 12 salt rounds and are never stored in plain text.
Usage Data: We collect information about how you interact with our platform, including test cases created, scans run, and AI features used. This data is aggregated for analytics and is tied to your organization.
Technical Data: We collect IP addresses, browser user agents, and session metadata for security purposes (account lockout, audit logging, and session management).
AI Interactions: Prompts and responses from AI-powered features are processed in real-time and are NOT stored on our servers unless you explicitly save test cases or reports. Our zero-knowledge architecture ensures your application data remains confidential.
We use your information to: provide and maintain the platform; authenticate your identity and manage sessions; enforce role-based access control (RBAC); process billing and subscriptions; send service-related communications; improve our AI models and platform features (using aggregated, anonymized data only); comply with legal obligations.
Data is stored in PostgreSQL databases hosted on Neon with encryption at rest. Sensitive fields (MFA secrets, integration tokens) are encrypted using AES-256-GCM. All data in transit is protected by TLS 1.2+. We implement HSTS with a 1-year max-age and preload. Session tokens are stored as SHA-256 hashes to prevent database-compromise session hijacking.
Account data is retained for the duration of your active account. Test results and audit logs are retained for the duration of your subscription plus 90 days. Session data is automatically cleaned up every 6 hours for expired sessions. You may request deletion of your account and all associated data at any time.
We use the following third-party services: Neon (database hosting), Stripe (payment processing), Google Gemini / OpenAI / Anthropic (AI model providers — data is processed in real-time and not retained by providers per our enterprise agreements), Sentry (error monitoring — no PII is transmitted), EmailJS (demo booking notifications).
GDPR (EU/EEA users): You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.
CCPA (California users): You have the right to know what personal information we collect, request deletion, and opt-out of the sale of personal information. We do not sell personal information.
To exercise any of these rights, contact us at privacy@qa-automation.com.
We use essential cookies for authentication (JWT tokens) and session management. We do not use third-party advertising or tracking cookies.
For privacy inquiries: privacy@qa-automation.com
NexGen QA Systems Inc., San Francisco, CA, United States