runQC
Home Features Pricing Docs About Contact Request access

Privacy Policy

Effective Date: June 5, 2026 · Last Updated: September 14, 2026 · Syntaxa LLC

Syntaxa LLC ("Company," "we," "us," or "our") operates the runQC platform at app.runqc.ai (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.


1. Information We Collect

1.1 Account Information

When you create an Account, we collect:

  • Email address
  • Name (if provided)
  • Organization name
  • Password (stored as a cryptographic hash by AWS Cognito; we do not have access to your plaintext password)
  • Account role and team membership

When you sign in using Google Sign-In, we receive your email address from Google. We do not receive your name, profile picture, or any other Google profile data. Your Google account password is never shared with us.

1.2 Billing Information

When you subscribe to a paid plan, payment information is collected and processed by Stripe, Inc. We receive limited billing information from Stripe, including:

  • Subscription plan and status
  • Payment history and invoice amounts
  • Last four digits of payment card (for display purposes)
  • Billing contact email

We do not store full credit card numbers, CVVs, or other sensitive payment card data.

1.3 Usage Data

We automatically collect information about your use of the Service, including:

  • Run history (dates, duration, cost, mode, quality scores, verdicts)
  • Credit consumption and balance
  • API request logs (endpoint, timestamp, response code)
  • Feature usage patterns (suite creation, live monitoring, analytics views)
  • Login timestamps and session information

1.4 Test Run Data

When you execute test runs through the Service, we process and store:

  • Target Agent Configuration: The endpoint URL, authentication type, and request headers you provide. We store API keys and authentication tokens for your target agent encrypted via AWS Secrets Manager.
  • Test Interactions: The questions sent to your Target Agent and the responses received, as recorded in Journals.
  • Test Results: Quality scores, verdicts, findings, grades, and recommendations generated by the Service.
  • Context Documents: Any documentation you upload to provide context about your Target Agent.
  • Suite Definitions: Test suite configurations you create or import.
  • GitHub Integration Data: If you enable the GitHub integration, repository metadata (repository names, commit SHAs, pull-request numbers) and the contents of your runQC configuration file.

1.5 LLM Provider API Keys (BYOK)

If you use BYOK configuration, your LLM provider API keys are stored encrypted in AWS Secrets Manager. We do not log, view, or use your keys for any purpose other than executing test runs on your behalf.

1.6 Technical Data

We automatically collect:

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Referral URLs
  • Pages viewed and actions taken within the Service

1.7 Communication Data

When you contact us for support, provide feedback, or communicate with us, we collect the content of those communications along with associated metadata.


2. How We Use Information

We use the information we collect for the following purposes:

2.1 Service Delivery

  • Providing, operating, and maintaining the Service
  • Executing test runs and generating Test Results
  • Managing your Account, subscriptions, and credits
  • Processing payments and billing
  • Authenticating users and managing access control

2.2 Service Improvement

  • Analyzing usage patterns to improve Service features and performance
  • Debugging errors and resolving technical issues
  • Developing new features and capabilities
  • Creating aggregated, anonymized benchmarks and metrics
  • Human review during the Beta Program: authorized Company personnel may manually review your interaction Journals (test questions, Target Agent responses, grades, and findings) to improve the Service, subject to the purpose and access limitations in the Beta Program Agreement (Section 5). We never access credential values you store in secret-designated fields (e.g., target agent API keys, BYOK LLM provider keys); these are stored in an encrypted vault (AWS Secrets Manager) and are used only to execute your test runs.

2.3 Communications

  • Sending transactional emails (run completion notifications, credit alerts, payment confirmations)
  • Sending security alerts and Account notifications
  • Responding to support inquiries
  • Sending product updates and announcements (with opt-out available)

2.4 Security and Compliance

  • Detecting, preventing, and responding to fraud, abuse, and security incidents
  • Enforcing our Terms of Service and Acceptable Use Policy
  • Complying with legal obligations
  • Protecting the rights, property, and safety of Company, our users, and the public

2.5 Aggregated Analytics

  • Creating de-identified, aggregated data for product benchmarking, research, and marketing
  • Analyzing platform-wide trends in AI agent quality and testing patterns
  • Generating industry reports and insights (using only anonymized data)

3. How We Share Information

We do not sell your personal information. We share information only in the following circumstances:

3.1 Third-Party Service Providers

We share information with third-party providers who assist us in operating the Service:

ProviderPurposeData Shared
AWS (Amazon Web Services)Cloud infrastructure, authentication (Cognito), email (SES), secrets managementAccount data, usage data, encrypted secrets
MongoDB AtlasDatabase hostingAll Service data (encrypted at rest)
StripePayment processingBilling information, subscription data
OpenAILLM provider for test executionTest interactions (prompts and responses)
AnthropicLLM provider for test executionTest interactions (prompts and responses)
CloudflareDNS, CDNTechnical data (IP addresses, traffic metadata)
GoogleAuthentication (Google Sign-In)Email address (via OAuth)
GitHubSource-control integration (GitHub App: repository configuration, check runs, pull-request comments)Repository metadata (repository names, commit SHAs, pull-request numbers, configuration files); test summaries and Test Result links posted as check runs and PR comments

3.2 LLM Providers

Important: When the Service executes test runs, test interactions (including questions sent to your Target Agent and responses received) are processed through third-party LLM Providers (OpenAI and/or Anthropic). This processing is necessary for the Service to generate AI-powered test questions, grade responses, and produce findings. Data shared with LLM Providers is subject to their respective privacy policies and terms of service:

  • OpenAI: https://openai.com/policies/privacy-policy
  • Anthropic: https://www.anthropic.com/privacy

When using BYOK configuration, your interactions with LLM Providers are governed by your direct relationship with those providers.

3.3 Legal Requirements

We may disclose information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to: (a) comply with applicable law; (b) protect the rights, property, or safety of Company, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues.

3.4 Business Transfers

In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of the transaction. We will provide notice of any such transfer and any choices you may have regarding your information.

3.5 With Your Consent

We may share your information with third parties when you give us explicit consent to do so.

3.6 Google API Services User Data Policy Compliance

runQC's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you use Google Sign-In to authenticate with the Service:

  • We request only the minimum permissions needed: your email address (via the openid and email OAuth scopes).
  • Your email address is used solely for authentication, account creation, and Service communications as described in this Privacy Policy.
  • We do not sell, share for advertising, or use your Google user data for surveillance, credit assessment, or any purpose not disclosed in this Privacy Policy.
  • We do not allow humans to read your Google user data except as necessary for security investigations, legal compliance, or with your explicit consent.
  • You may revoke runQC's access to your Google account at any time through your Google Account permissions page.

4. Data Retention

4.1 Account Data

We retain Account information for as long as your Account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Account data is deleted within ninety (90) days of Account termination.

4.2 Test Run Data

Journals and Test Results are not deleted on a retention schedule. We store them for the lifetime of your Account, subject to deletion upon Account termination, deletion at your request under Section 6.3, and the deletion provisions of the Terms of Service and the Data Processing Agreement.

How long you can view a Journal and its full Test Results in the Service depends on your Account:

  • Free tier, without Extended Beta Access: 14 days from Journal creation
  • Extended Beta Access: no viewing limit while Extended Beta Access is in effect for your Account. Extended Beta Access (as defined in the Terms of Service) is granted by Company to specific Accounts at its discretion; accepting the Beta Program Agreement does not by itself grant Extended Beta Access
  • Paid Subscription Plans: no viewing limit

For an Account on the Free tier without Extended Beta Access, a Journal and its full Test Results cannot be opened from your Account after fourteen (14) days from Journal creation, but they are still stored. A summary of each test run (date, status, overall quality score and verdict, and finding counts) remains visible. Viewing limits are determined by your Account's Subscription Plan and Extended Beta Access at the time of viewing, so if your Account is later granted Extended Beta Access or moves to a paid Subscription Plan, older Journals and Test Results become viewable again. Upon transition to general availability, the viewing limits of your selected Subscription Plan apply.

4.3 Billing Data

Billing records and transaction history are retained for seven (7) years to comply with tax and accounting requirements.

4.4 Technical Logs

Server logs and API request logs are retained in Amazon CloudWatch Logs for thirty (30) days, after which they are deleted. Company does not export CloudWatch log data to S3. Separately, load balancer access logs and infrastructure audit trail logs are delivered directly to Amazon S3, where they move to lower-cost storage classes after thirty (30) and ninety (90) days and are deleted after three hundred sixty-five (365) days.


5. Data Security

5.1 Technical Measures

We implement industry-standard security measures to protect your information:

  • Encryption at Rest: MongoDB Atlas storage-layer encryption at rest (Atlas platform default; Company has not configured customer-managed encryption keys), AWS Secrets Manager KMS encryption, S3 SSE encryption
  • Encryption in Transit: TLS 1.2+ for all data transmission
  • Access Control: Role-based access control, API key hashing (SHA-256), JWT authentication via AWS Cognito
  • Network Security: Private subnets, security groups, SSRF protection, rate limiting
  • Tenant Isolation: All data is scoped by tenant ID; each test run executes in an isolated compute container

5.2 Organizational Measures

  • Access to customer data is restricted to personnel who require it for Service operation
  • All Company personnel are bound by confidentiality obligations
  • We conduct regular security reviews of our infrastructure and code

5.3 Incident Response

In the event of a data breach affecting your personal information, we will notify you in accordance with applicable data breach notification laws.


6. Your Rights and Choices

6.1 Account Access and Updates

You may access and update your Account information through the Service settings page or by contacting us at [email protected].

6.2 Data Export

You may export your Journals, Test Results, and suite definitions through the Service API or web interface at any time during your subscription, provided that export of Journals and Test Results is limited to those you can view under the viewing limits described in Section 7.4 of the Terms of Service. Regardless of your Subscription Plan, you may request a copy of any other Journals, Test Results, or personal data associated with your Account by contacting [email protected]. This Section 6.2 does not limit your rights under Sections 6.5 and 6.6.

6.3 Data Deletion

You may request deletion of your Account and associated data by contacting [email protected]. We will process deletion requests within thirty (30) days, subject to our retention obligations under applicable law.

6.4 Email Preferences

You may manage your email notification preferences through the Service settings. You may unsubscribe from non-transactional communications using the unsubscribe link in any email. Transactional emails (security alerts, billing notifications, service announcements) cannot be opted out of while your Account is active.

6.5 California Residents (CCPA/CPRA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale: We do not sell personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at [email protected] or submit a request through the Service.

6.6 European Economic Area, United Kingdom, and Switzerland Residents

If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Legal Basis: We process your personal data based on: (a) performance of a contract (Service delivery); (b) legitimate interests (security, improvement, analytics); (c) consent (marketing communications); (d) legal obligation (compliance).
  • Data Subject Rights: You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.
  • Data Transfers: Your data is processed in the United States. We make available a Data Processing Agreement that incorporates the European Commission's Standard Contractual Clauses (SCCs) for international data transfers. The SCCs apply only where that Data Processing Agreement has been executed by both parties; we have not executed one with any customer to date.
  • Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.

To exercise your GDPR rights, contact our Data Protection contact at [email protected].


7. Cookies and Tracking

7.1 Essential Cookies

We use essential cookies and local storage for authentication (JWT tokens), session management, and Service functionality. These cannot be disabled without losing access to the Service.

7.2 Analytics

We may use analytics tools to understand how the Service is used. Analytics data is aggregated and does not identify individual users.

7.3 No Third-Party Advertising

We do not use advertising cookies or trackers. We do not display third-party advertisements within the Service.

For more information, see our Cookie Policy.


8. Children's Privacy

The Service is not directed to individuals under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete such information promptly.


9. International Data Transfers

The Service is operated from the United States. If you are accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Company makes available a Data Processing Agreement that incorporates the Standard Contractual Clauses; those clauses take effect only where that Data Processing Agreement has been executed by the parties, and Company has not executed one with any customer to date.


10. AI-Specific Privacy Considerations

10.1 LLM Processing

Test interactions processed through LLM Providers (OpenAI, Anthropic) may be subject to those providers' data retention and use policies. As of the effective date of this Privacy Policy:

  • OpenAI API usage data is not used to train OpenAI's models (per OpenAI's API data usage policy)
  • Anthropic API usage data is not used to train Anthropic's models (per Anthropic's API data usage policy)

These policies are controlled by the respective LLM Providers and may change. We recommend reviewing their current policies.

10.2 No Model Training

We do not use Customer Data to train or fine-tune third-party machine learning models, and we do not sell or share Customer Data for any third party's model training. We may use anonymized, aggregated insights derived from use of the Service to improve our own testing methodology, grading calibration, and Service features, consistent with the Terms of Service (Section 6) and, during the Beta Program, the Beta Program Agreement (Section 5).


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on the Service and updating the "Last Updated" date. For material changes that significantly affect the processing of your personal information, we will provide additional notice (such as email notification). Your continued use of the Service after the effective date of any changes constitutes acceptance.


12. Contact Information

For questions or concerns about this Privacy Policy or our data practices, contact:

Syntaxa LLC
Email: [email protected]
Website: https://runqc.ai

For data protection inquiries or to exercise your privacy rights:
Email: [email protected]


This Privacy Policy was last updated on September 14, 2026.

Other Legal Documents

  • Terms of Service
  • Acceptable Use Policy
  • Cookie Policy
  • DMCA Policy
  • Security Disclosure
  • Service Level Agreement
  • Data Processing Agreement
  • Beta Agreement
runQC

Comprehensive AI agent testing and verification platform for reliable deployments.

Product

  • Features
  • Pricing
  • Documentation
  • API Reference

Company

  • About
  • Contact
  • Blog
  • Careers

Legal

  • Privacy Policy
  • Terms of Service
  • Security
  • Status

© 2026 Syntaxa LLC. All rights reserved.

runQC - AI Agent Quality Control