Privacy

Privacy policy.

Short version: we store what QA Reef needs to run your tests, we run it on our own servers, and we don't sell it. Longer version below.

What we store

Running QA Reef means we hold onto a few kinds of data — nothing beyond what's needed to build and rerun your tests:

  • Flows — the recorded steps of a test: clicks, typed values, navigation, and the locators used to find things on the page.
  • Run artifacts — screenshots, Playwright traces, and run logs produced while a flow executes, kept as evidence for pass/fail/unmeasured verdicts.
  • Crawl reports — the pages, links, console errors, and timing data collected when QA Reef crawls a site or deployment.
  • Lead-form submissions — if you use a form on this marketing site, we store the name, work email, company, and message you submit, sent to https://app.qareef.com/api/lead.

We don't ask for more than that. If a future feature needs a new kind of data, this page gets updated before it ships, not after.

Where it runs

QA Reef runs on our own servers. Your flows, artifacts, and reports live there — not spread across a chain of unrelated vendors. We don't resell this data or sell it on to anyone.

That also means there's no ad pixel, no analytics tracker, and no session-replay tool watching what you do on this site or inside the product.

We do not sell data

No advertising, no data brokers, no selling access to your flows, artifacts, or contact details. This isn't a "sell anonymized data" carve-out either — we just don't do it.

Third parties we actually use

We keep this list short on purpose, and only name what's verifiably true today:

  • This site loads webfonts from Google Fonts (fonts.googleapis.com / fonts.gstatic.com), which sees the visiting browser's IP address like any font CDN.
  • Model calls made by the product (for example, reading a screen or writing test code) go to OpenRouter. Every call is cost-logged — provider, model, tokens, and cost — so usage is auditable, not silent.

If it isn't on this list, we haven't verified it, so we're not claiming it. We'll update this page the moment that changes.

Retention

Today, pre-launch, flows and run artifacts stay on our servers for as long as your workspace is active so you can review past runs. We have not yet fixed a hard deletion window. TBD [Retention window not yet set — this section will be updated with a concrete number before general availability].

Your choices

Email hello@qareef.com to ask what we hold on you or your workspace, or to have it deleted. We'll respond directly — there's no ticket queue.

Changes to this policy

We're a small, pre-launch team and this policy will change as the product does. Meaningful changes will be reflected on this page with an updated date below.

Last updated: 2026-08-30.