Privacy

Privacy policy

Short and clear. The desktop app is local first. Most of this policy describes what we do not do.

Last updated: 2026-05-18

1. The website

Standard hosting logs from our static site provider: requested URL, timestamp, user agent, referrer, IP address. Used only for diagnosing abuse and capacity planning. Retained for 30 days then rotated out.

The website does not use third party analytics, advertising trackers, cookies, or fingerprinting.

2. The desktop app

By default, nothing leaves your machine. Scenarios, runs, screenshots, and network captures all live in your local data folder.

The app fetches a single JSON file from this site once per launch to check for a new version. That request sends only a generic user agent.

Telemetry is off by default and opt in. When enabled, the app appends structural events to a local audit file. Nothing is sent off the device.

3. What we never collect

  • The text of your scenarios
  • The URLs you test against
  • Your LLM API key
  • Your LLM prompts or responses
  • Screenshots, network captures, or browser content
  • Your name, email, or identity

4. Third parties you involve

The LLM provider you configure receives your prompts and, for vision assertions, your screenshots. Their privacy policy applies to that traffic.

The websites you test see your IP and browser fingerprint exactly as if you visited them yourself.

5. Cookies on this website

None. This site uses no cookies, no local storage tracking, and no browser fingerprinting.

6. Your rights

Because we do not collect personal data on the desktop, there is no profile to access, correct, or delete. For website hosting logs, contact us and we will purge any request matching an IP you specify.

7. Changes

We will update the date at the top of this page if anything changes, and we will never weaken these protections without a major version bump.

8. Contact

Privacy questions go through the contact form.