Syntaxa LLC ("Company," "we," "us," or "our") operates the runQC platform at app.runqc.ai (the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect information when you use our Service.
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.
When you create an Account, we collect:
When you sign in using Google Sign-In, we receive your email address from Google. We do not receive your name, profile picture, or any other Google profile data. Your Google account password is never shared with us.
When you subscribe to a paid plan, payment information is collected and processed by Stripe, Inc. We receive limited billing information from Stripe, including:
We do not store full credit card numbers, CVVs, or other sensitive payment card data.
We automatically collect information about your use of the Service, including:
When you execute test runs through the Service, we process and store:
If you use BYOK configuration, your LLM provider API keys are stored encrypted in AWS Secrets Manager. We do not log, view, or use your keys for any purpose other than executing test runs on your behalf.
We automatically collect:
When you contact us for support, provide feedback, or communicate with us, we collect the content of those communications along with associated metadata.
We use the information we collect for the following purposes:
We do not sell your personal information. We share information only in the following circumstances:
We share information with third-party providers who assist us in operating the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| AWS (Amazon Web Services) | Cloud infrastructure, authentication (Cognito), email (SES), secrets management | Account data, usage data, encrypted secrets |
| MongoDB Atlas | Database hosting | All Service data (encrypted at rest) |
| Stripe | Payment processing | Billing information, subscription data |
| OpenAI | LLM provider for test execution | Test interactions (prompts and responses) |
| Anthropic | LLM provider for test execution | Test interactions (prompts and responses) |
| Cloudflare | DNS, CDN | Technical data (IP addresses, traffic metadata) |
| Authentication (Google Sign-In) | Email address (via OAuth) | |
| GitHub | Source-control integration (GitHub App: repository configuration, check runs, pull-request comments) | Repository metadata (repository names, commit SHAs, pull-request numbers, configuration files); test summaries and Test Result links posted as check runs and PR comments |
Important: When the Service executes test runs, test interactions (including questions sent to your Target Agent and responses received) are processed through third-party LLM Providers (OpenAI and/or Anthropic). This processing is necessary for the Service to generate AI-powered test questions, grade responses, and produce findings. Data shared with LLM Providers is subject to their respective privacy policies and terms of service:
When using BYOK configuration, your interactions with LLM Providers are governed by your direct relationship with those providers.
We may disclose information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to: (a) comply with applicable law; (b) protect the rights, property, or safety of Company, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues.
In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as part of the transaction. We will provide notice of any such transfer and any choices you may have regarding your information.
We may share your information with third parties when you give us explicit consent to do so.
runQC's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you use Google Sign-In to authenticate with the Service:
openid and email OAuth scopes).We retain Account information for as long as your Account is active and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements. Account data is deleted within ninety (90) days of Account termination.
Journals and Test Results are not deleted on a retention schedule. We store them for the lifetime of your Account, subject to deletion upon Account termination, deletion at your request under Section 6.3, and the deletion provisions of the Terms of Service and the Data Processing Agreement.
How long you can view a Journal and its full Test Results in the Service depends on your Account:
For an Account on the Free tier without Extended Beta Access, a Journal and its full Test Results cannot be opened from your Account after fourteen (14) days from Journal creation, but they are still stored. A summary of each test run (date, status, overall quality score and verdict, and finding counts) remains visible. Viewing limits are determined by your Account's Subscription Plan and Extended Beta Access at the time of viewing, so if your Account is later granted Extended Beta Access or moves to a paid Subscription Plan, older Journals and Test Results become viewable again. Upon transition to general availability, the viewing limits of your selected Subscription Plan apply.
Billing records and transaction history are retained for seven (7) years to comply with tax and accounting requirements.
Server logs and API request logs are retained in Amazon CloudWatch Logs for thirty (30) days, after which they are deleted. Company does not export CloudWatch log data to S3. Separately, load balancer access logs and infrastructure audit trail logs are delivered directly to Amazon S3, where they move to lower-cost storage classes after thirty (30) and ninety (90) days and are deleted after three hundred sixty-five (365) days.
We implement industry-standard security measures to protect your information:
In the event of a data breach affecting your personal information, we will notify you in accordance with applicable data breach notification laws.
You may access and update your Account information through the Service settings page or by contacting us at [email protected].
You may export your Journals, Test Results, and suite definitions through the Service API or web interface at any time during your subscription, provided that export of Journals and Test Results is limited to those you can view under the viewing limits described in Section 7.4 of the Terms of Service. Regardless of your Subscription Plan, you may request a copy of any other Journals, Test Results, or personal data associated with your Account by contacting [email protected]. This Section 6.2 does not limit your rights under Sections 6.5 and 6.6.
You may request deletion of your Account and associated data by contacting [email protected]. We will process deletion requests within thirty (30) days, subject to our retention obligations under applicable law.
You may manage your email notification preferences through the Service settings. You may unsubscribe from non-transactional communications using the unsubscribe link in any email. Transactional emails (security alerts, billing notifications, service announcements) cannot be opted out of while your Account is active.
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act and California Privacy Rights Act:
To exercise these rights, contact us at [email protected] or submit a request through the Service.
If you are located in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
To exercise your GDPR rights, contact our Data Protection contact at [email protected].
We use essential cookies and local storage for authentication (JWT tokens), session management, and Service functionality. These cannot be disabled without losing access to the Service.
We may use analytics tools to understand how the Service is used. Analytics data is aggregated and does not identify individual users.
We do not use advertising cookies or trackers. We do not display third-party advertisements within the Service.
For more information, see our Cookie Policy.
The Service is not directed to individuals under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child, we will take steps to delete such information promptly.
The Service is operated from the United States. If you are accessing the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Company makes available a Data Processing Agreement that incorporates the Standard Contractual Clauses; those clauses take effect only where that Data Processing Agreement has been executed by the parties, and Company has not executed one with any customer to date.
Test interactions processed through LLM Providers (OpenAI, Anthropic) may be subject to those providers' data retention and use policies. As of the effective date of this Privacy Policy:
These policies are controlled by the respective LLM Providers and may change. We recommend reviewing their current policies.
We do not use Customer Data to train or fine-tune third-party machine learning models, and we do not sell or share Customer Data for any third party's model training. We may use anonymized, aggregated insights derived from use of the Service to improve our own testing methodology, grading calibration, and Service features, consistent with the Terms of Service (Section 6) and, during the Beta Program, the Beta Program Agreement (Section 5).
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated Privacy Policy on the Service and updating the "Last Updated" date. For material changes that significantly affect the processing of your personal information, we will provide additional notice (such as email notification). Your continued use of the Service after the effective date of any changes constitutes acceptance.
For questions or concerns about this Privacy Policy or our data practices, contact:
Syntaxa LLC
Email: [email protected]
Website: https://runqc.ai
For data protection inquiries or to exercise your privacy rights:
Email: [email protected]
This Privacy Policy was last updated on September 14, 2026.