How the ReleaseTwin project handles data for the hosted ReleaseTwin dashboard. Last updated August 2026. A counsel review is planned before general availability.
Account & identity — via our authentication provider (Clerk): your email, name if you provide one, and authentication events. Passwords are handled by the provider; we never see them.
Project & usage data — the projects, journeys, API tokens, and settings you create; and per run: case identifiers, oracle references, fixture hashes, pass/fail, failure classification, flag-proof outcome, and timestamps. Counts of uploaded runs and active projects, for plan metering.
Evidence documents (opt-in only) — if you enable evidence upload for a project, per-step request/response summaries, assertion detail, and screenshots. These are redacted in your own CLI before upload (auth headers, credential-shaped fields, resolved secrets, and your own masking rules) and stored opaquely — our systems don’t parse them.
Operational data — server logs, IP address and user agent on requests, and error diagnostics, kept for security and debugging.
Marketing site — if analytics are enabled they are privacy-respecting and cookie-free (aggregate page counts, no cross-site tracking, no profiles).
Legal bases (where the GDPR applies): performance of our contract with you, our legitimate interests in a secure and improving product, and your consent where required.
Only the sub-processors needed to run the Service, each under a data-processing agreement:
We don’t sell or rent personal data. We may disclose data if legally required, and we’ll tell you unless prohibited.
You can access, export, correct, or delete your data from the dashboard, or by emailing ernestoalejo22@gmail.com. Depending on where you live you may also have the right to object to or restrict processing, or to lodge a complaint with a supervisory authority. We’ll respond within the time the applicable law requires.
The Service is hosted in the United States; using it involves transferring your data there. We rely on standard contractual clauses with sub-processors where required. Data is encrypted in transit and at rest; API tokens and stored project secrets are encrypted at rest and shown only once. See the Security page for detail.
The Service isn’t for anyone under 16, and we don’t knowingly collect their data.
We’ll post the updated date above and email account holders before a material change takes effect. Privacy questions or requests: ernestoalejo22@gmail.com.