Skip to content

Legal

Privacy Policy

This Privacy Policy describes how QA Workflow Assistant collects, uses, stores, and deletes information when you use the Service.

Effective date: August 3, 2026

1. Introduction

QA Workflow Assistant is a software service that helps users generate QA artifacts—such as test cases, edge cases, and related workflow output—from requirements and Jira stories. This policy explains what information we process to operate that service as it is implemented today.

The service is operated by Can Yavas, based in Florida, United States. Our product market is US-first; international users may use the service subject to applicable local laws.

2. Information We Collect

Depending on how you use the service, we may collect or process the following categories of information:

  • Account information. Email address, name, and authentication identifiers associated with your account. If you sign in with Google, we may receive profile information provided by Google for authentication (such as name, email, and profile image).
  • Billing information. Subscription and customer identifiers needed to manage Pro billing. Payment card processing is handled by Stripe. We do not receive or store raw card numbers.
  • Generated content. Content you submit for generation (including Jira stories and optional acceptance criteria), generated QA outputs, and saved generations you choose to keep in history.
  • Integration settings. Jira site URL, email used for Jira authentication, default project key, preferred issue type, encrypted Jira API token, and encrypted Xray client credentials when you configure those integrations.
  • Usage and diagnostics. Generation and feature usage records used for rate limiting and product operation, plus error diagnostics that help us investigate failures.

3. How We Use Information

We use information to:

  • Authenticate users and maintain signed-in sessions
  • Generate QA outputs from the content you submit
  • Provide billing and subscription management through Stripe
  • Operate user-requested Jira and Xray integrations (for example, connection tests and push workflows)
  • Improve reliability and diagnose errors
  • Help prevent abuse and fraud
  • Provide customer support when you contact us

4. AI Processing

When you generate QA output, the story text, acceptance criteria, and related generation inputs you provide are processed using OpenAI services to produce QA artifacts. Processing is subject to OpenAI's applicable platform terms and data handling policies.

Do not submit passwords, API keys, secrets, payment card data, regulated health information, unnecessary personal information, or other confidential material unless your organization has authorized that use. Prefer only the Jira story details required to generate QA artifacts.

5. Jira & Xray Integrations

If you connect Jira or Xray, we store the settings needed to perform actions you request (such as testing a connection or pushing generated work). Jira API tokens and Xray client secrets are encrypted before storage using AES-256-GCM. Credentials are decrypted only on the server when needed to perform those user-requested actions.

You can disconnect Jira or remove Xray credentials at any time from the product settings. Disconnecting removes the stored credentials and related settings from your QA Workflow Assistant account. It does not delete issues, tests, test sets, or test executions already created in Jira or Xray.

6. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information, including:

  • Encryption of integration secrets at rest (AES-256-GCM)
  • HTTPS for data in transit to our application
  • Authentication and session controls
  • Access controls for application and database operations
  • Error monitoring via Sentry with scrubbing intended to reduce sensitive data in diagnostic events

No method of transmission or storage is completely secure. We do not guarantee that unauthorized access, disclosure, or loss can never occur. For a product-focused overview of current safeguards, see the Security page.

7. Data Retention

Saved generations remain in your history until you delete them. From the product, you may delete a single saved generation, delete all generation history, or delete your account.

After account deletion, application data associated with your account is permanently removed from our production database, including profile and authentication records we store, saved generations, local Jira push history records, integration credentials and settings, and related application usage rows tied to your user id.

The following may remain outside the live application database for operational or legal reasons:

  • Stripe billing and payment records
  • Sentry diagnostic events
  • Hosting provider logs
  • Backup copies retained according to operational retention schedules

Retained data of this kind is used only for legal, security, fraud-prevention, accounting, or disaster recovery purposes.

8. Account Deletion

You can request account deletion from the dashboard danger zone. If you have an active paid subscription (including a subscription that remains active until the end of a canceled billing period), account deletion is blocked until you cancel through the Stripe Customer Portal (Manage billing) and paid access is no longer active. We do not silently cancel billing on your behalf, and we do not automatically delete your Stripe customer object.

After a successful deletion:

  • Your signed-in session ends
  • Live application data for that account is removed from our production database
  • Signing in again with the same identity may create a new account
  • Previous history and settings cannot be recovered

External Jira and Xray items already created remain in those systems and are not deleted by account deletion.

9. Third-Party Services

We use third-party services to operate QA Workflow Assistant. Those providers process information according to their own terms and privacy policies. Current service categories include:

  • Stripe — billing and subscription management
  • Google Authentication — optional sign-in
  • OpenAI — AI generation processing
  • Atlassian Jira — optional issue workflows you request
  • Xray — optional test management workflows you request
  • Vercel — application hosting
  • Supabase — managed PostgreSQL database hosting
  • Sentry — error monitoring and diagnostics

10. International Users

The service is operated from the United States and is designed primarily for a US-first market. If you access the service from outside the United States, you are responsible for determining whether your use complies with laws that apply to you, including any restrictions on transferring or processing information across borders.

11. Children

QA Workflow Assistant is intended for users who are 18 years of age or older. We do not knowingly collect account information from children under 18. If you believe a minor has created an account, contact us so we can take appropriate action.

12. Changes

We may update this Privacy Policy from time to time to reflect product, operational, or legal changes. When we do, we will update the effective date at the top of this page. Continued use of the service after an update means you acknowledge the revised policy.

13. Contact

For privacy questions or account deletion support, contact:

Can Yavas

Operator, QA Workflow Assistant

Florida, United States

info@qaworkflow.net