Let QATE discover your app and build a map and knowledge base in minutes: Discover your app in minutes: Discover Now →

Privacy Policy

Last updated: July 26, 2026

At Qate AI, we are committed to protecting your privacy and ensuring the security of your personal information. As a European company, we adhere to the highest standards of data protection under the General Data Protection Regulation (GDPR) and other applicable privacy laws. This Privacy Policy explains how we collect, use, and safeguard your data when you use our AI-powered UI testing platform.

1. Information We Collect

1.1 Personal Information

We collect personal information that you voluntarily provide to us when you:

  • Register for early access or schedule a demo
  • Create an account with Qate AI
  • Contact us for support or inquiries
  • Subscribe to our newsletter or marketing communications

This information may include:

  • Name and contact information (email address, phone number)
  • Company name and job title
  • Account credentials and preferences
  • Payment information (processed securely through third-party providers)

1.2 Usage Data

We automatically collect certain information when you use our platform:

  • IP address and device information
  • Browser type and version
  • Pages visited and time spent on our platform
  • Test execution logs and performance metrics
  • Feature usage and interaction patterns

1.3 Testing Data

When you use our AI testing services, we collect:

  • Screenshots and UI structure of the applications you test
  • Your conversations with the AI agent
  • Test scenarios and workflow configurations
  • Test results and performance metrics
  • Error logs and debugging information
  • Credentials you choose to store for logging in to your own test targets (stored encrypted — see Section 3.1)

Because Qate is an AI product, most of this data is sent to an AI provider in order to produce, run and analyse your tests. Section 4.2 explains exactly what that involves. If the applications you test contain personal data, you remain the controller of that data and we process it on your behalf as described in this policy.

2. How We Use Your Information

We use the collected information for the following purposes:

2.1 Service Provision

  • Provide and maintain our AI testing platform
  • Execute automated tests and generate reports
  • Authenticate users and maintain account security
  • Process payments and manage subscriptions

2.2 Service Improvement

  • Analyze usage patterns to improve our AI algorithms
  • Develop new features and enhance existing functionality
  • Monitor system performance and troubleshoot issues
  • Conduct research and development for better testing capabilities

2.3 Communication

  • Send important service updates and security notifications
  • Provide customer support and technical assistance
  • Send marketing communications (with your consent)
  • Respond to your inquiries and feedback

3. Data Security and Protection

3.1 Security Measures

We implement industry-standard security measures to protect your data:

  • End-to-end encryption for data transmission
  • Secure cloud infrastructure with regular security audits
  • Access controls and authentication mechanisms
  • Regular security training for our team members
  • Incident response procedures and monitoring systems

3.2 Data Processing Location

Your data is primarily processed:

  • Locally on your devices when using desktop testing features
  • On secure cloud servers located primarily in the European Union
  • Through encrypted connections to ensure data integrity and GDPR compliance
  • With limited processing in other regions only when necessary for service delivery, with appropriate safeguards

4. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

4.1 Sub-processors

We use the following sub-processors to operate the Service. Each processes data on our instructions under a data processing agreement, and transfers outside the EEA are covered by Standard Contractual Clauses where applicable.

Sub-processorPurposeData processedLocation
Anthropic (Claude)AI model powering test creation, analysis and healingConversation content, screenshots and page structure of the applications you test, test definitions and resultsUnited States
OpenAIAlternative AI model, used only if you select itAs aboveUnited States
Microsoft Azure (AI Foundry)Alternative AI model hosting, used only if you select itAs aboveEU or United States, depending on deployment
Microsoft AzureCloud hosting, container registry and platform infrastructureAll Service data at rest and in transitEuropean Union
StripePayment processing, invoicing and subscription managementBilling name, e-mail, payment details, transaction historyUnited States / EU
Microsoft Azure Communication ServicesTransactional e-mail (verification, notifications, support)E-mail address, message contentEuropean Union
TidioLive chat on our website (loads only with marketing-cookie consent)Chat messages, visitor identifiersEuropean Union
GoogleSign-in with Google, advertising conversion measurement, web fontsAccount identifier and e-mail (sign-in); ad interaction data with marketing consentUnited States

4.2 AI Processing of Your Testing Data

Qate is an AI product: to create, run, analyse and heal tests, the content of your conversations with the agent, screenshots and structural data from the applications you test, and your test definitions and results are sent to the AI provider selected for your account (Anthropic by default). This is necessary to provide the Service.

Our AI providers act as processors and are contractually prohibited from using your data to train their models. We do not use the content of your conversations or test data to train our own models.

You control what the agent can reach. Credentials you store for your own test targets are encrypted at rest and are substituted into requests only at execution time, so they are not included in the prompts sent to AI providers. Please avoid entering personal data into chat messages or test data where it is not necessary for testing.

4.3 Legal Requirements

  • When required by law or legal process
  • To protect our rights, property, or safety
  • To investigate potential violations of our terms of service

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction, subject to the same privacy protections.

5. Your Rights Under GDPR

5.1 Your Legal Rights

As a data subject under GDPR, you have the following rights:

  • Right of Access - Request access to your personal data and information about our processing
  • Right to Rectification - Request correction of inaccurate or incomplete personal data
  • Right to Erasure - Request deletion of your personal data under certain circumstances
  • Right to Restrict Processing - Request limitation of processing in specific situations
  • Right to Data Portability - Receive your personal data in a structured, machine-readable format
  • Right to Object - Object to processing of your personal data for direct marketing or legitimate interests
  • Right to Withdraw Consent - Withdraw consent for processing based on consent at any time
  • Right to Lodge a Complaint - File a complaint with your local data protection authority

5.2 Exercising Your Rights

You can exercise two of these rights directly from your account settings at any time, without contacting us:

  • Export your data — downloads a machine-readable JSON copy of your account and its content (right of access and portability).
  • Delete your account — permanently erases your account and all associated content (right to erasure). This is immediate and cannot be undone.

For any other request, or if you cannot access your account, contact us using the details in Section 10. We respond within one month, or two months for complex requests, and will explain any action taken.

5.3 Data Retention

We keep data for the following periods:

  • Account and testing data (your account details, applications, tests, test results, conversations with the agent, stored credentials for your test targets): retained for as long as your account exists. It is deleted when you delete your account, and we do not delete it automatically before then, because your test history is the working record you rely on.
  • Screenshots captured during test runs: automatically deleted after their retention period expires.
  • Knowledge entries learned about your application: automatically deleted after 180 days without use.
  • Outbound HTTP request audit records (which host a test called, when, and the result — used for abuse prevention): automatically deleted after 90 days.
  • Short-lived operational records such as scheduling progress, sign-in tokens and OAuth session data: minutes to 24 hours.
  • Billing records: invoices are held by Stripe, our payment processor, for the period required by accounting and tax law (generally seven years in Belgium). These survive account deletion because we are legally required to keep them.
  • Website analytics: collected only with your consent, and limited to the events described in Section 6.

When you delete your account, we erase your account record, all users on it, and all of the content listed above from our systems, and cancel any active subscription. Backups are overwritten on their normal rotation cycle.

6. Cookies and Tracking Technologies

6.1 What Are Cookies

Cookies are small text files stored on your device when you visit a website. They help us provide you with a better experience by remembering your preferences and understanding how you use our site.

6.2 Cookie Categories

We categorise cookies into three groups:

Strictly Necessary

These cookies are essential for the website to function. They cannot be disabled.

  • qate_cookie_consent — Stores your cookie preferences (1 year, Qate AI)
  • hp_variant — Ensures consistent page rendering across visits (1 year, Qate AI)

Analytics

These help us understand how visitors interact with our website. They require your consent.

  • Session analytics — CTA click tracking and session ID (session only, Qate AI)

Marketing

Used to deliver relevant ads and measure ad campaign effectiveness. They require your consent.

  • Google Ads (_gcl_*) — Conversion tracking for advertising campaigns (90 days, Google)
  • Tidio Chat — Live chat widget and visitor data (session/persistent, Tidio)

6.3 Third-Party Scripts

  • Google Ads (AW-17951931961) — Conversion tracking for advertising campaigns
  • Tidio Chat — Live chat customer support widget
  • Google Fonts — Web font delivery (functional, no tracking cookies)

6.4 Cookies on app.qate.ai

Our application at app.qate.ai uses the following cookies, all of which are strictly necessary for the service to function:

  • authToken — Authentication (HTTP-only, 24 hours)
  • refreshToken — Session refresh (HTTP-only, 30 days)
  • testmind-theme — Theme preference (permanent)
  • qate-last-selected-application — Last selected application (permanent)
  • auth-storage — Authentication state (permanent)
  • OAuth state tokens — OAuth CSRF protection (session)

6.5 Managing Your Preferences

You can manage your cookie preferences at any time by clicking "Cookie Settings" in the website footer. You may also control cookies through your browser settings, though some features may not function properly if cookies are disabled.

7. Children's Privacy

Qate AI is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take immediate steps to delete it.

8. International Data Transfers

As a European-based company, we primarily process your data within the European Economic Area (EEA). When we do transfer personal data outside the EEA, we ensure adequate protection through:

  • Adequacy Decisions - Transfers to countries with adequate data protection as determined by the European Commission
  • Standard Contractual Clauses - EU-approved contractual terms with third-party processors
  • Binding Corporate Rules - Internal data protection policies for multinational service providers
  • Explicit Consent - Your specific consent for transfers when other safeguards are not available

We regularly review and update our transfer mechanisms to ensure ongoing compliance with European data protection standards.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending email notifications to registered users
  • Displaying prominent notices in our platform

Your continued use of our services after any changes indicates your acceptance of the updated Privacy Policy.

10. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email

privacy@qate.ai

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority. For our primary jurisdiction, go to:
https://www.dataprotectionauthority.be/citizen