Skip to content

Privacy Policy

Last updated: February 16, 2026

1. Introduction

NexGen QA Systems Inc. ("NexGen QA", "we", "us", or "our") is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, store, and protect your information when you use our AI-powered quality assurance platform and marketing website.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, organization name, and role. Passwords are hashed using bcrypt with 12 salt rounds and are never stored in plain text.

Usage Data: We collect information about how you interact with our platform, including test cases created, scans run, and AI features used. This data is aggregated for analytics and is tied to your organization.

Technical Data: We collect IP addresses, browser user agents, and session metadata for security purposes (account lockout, audit logging, and session management).

AI Interactions: Prompts and responses from AI-powered features are processed in real-time and are NOT stored on our servers unless you explicitly save test cases or reports. Our zero-knowledge architecture ensures your application data remains confidential.

3. How We Use Your Information

We use your information to: provide and maintain the platform; authenticate your identity and manage sessions; enforce role-based access control (RBAC); process billing and subscriptions; send service-related communications; improve our AI models and platform features (using aggregated, anonymized data only); comply with legal obligations.

4. Data Storage & Security

Data is stored in PostgreSQL databases hosted on Neon with encryption at rest. Sensitive fields (MFA secrets, integration tokens) are encrypted using AES-256-GCM. All data in transit is protected by TLS 1.2+. We implement HSTS with a 1-year max-age and preload. Session tokens are stored as SHA-256 hashes to prevent database-compromise session hijacking.

5. Data Retention

Account data is retained for the duration of your active account. Test results and audit logs are retained for the duration of your subscription plus 90 days. Session data is automatically cleaned up every 6 hours for expired sessions. You may request deletion of your account and all associated data at any time.

6. Third-Party Processors

We use the following third-party services: Neon (database hosting), Stripe (payment processing), Google Gemini / OpenAI / Anthropic (AI model providers — data is processed in real-time and not retained by providers per our enterprise agreements), Sentry (error monitoring — no PII is transmitted), EmailJS (demo booking notifications).

7. Your Rights

GDPR (EU/EEA users): You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.

CCPA (California users): You have the right to know what personal information we collect, request deletion, and opt-out of the sale of personal information. We do not sell personal information.

To exercise any of these rights, contact us at privacy@qa-automation.com.

8. Cookies

We use essential cookies for authentication (JWT tokens) and session management. We do not use third-party advertising or tracking cookies.

9. Contact

For privacy inquiries: privacy@qa-automation.com

NexGen QA Systems Inc., San Francisco, CA, United States