Privacy Policy
Last updated: August 13, 2026
Core Architecture & Privacy
AutomationTester.in is browser-first. Most deterministic tools (including XPath Tester, CSS Selector, JWT Decoder, Regex Tester, and Test Failure Triage) process input within the current browser tab. Each workflow states its own processing boundary rather than relying on one blanket claim.
Test failure evidence
The Test Failure Triage web page does not make a network request with pasted or uploaded evidence. It does not store the log, result, file name, input length, selectors, tokens, error text, or identifiers. Its deterministic rules run in the browser and the data disappears when the tab is cleared or closed.
The separately documented triage API has a different boundary: callers deliberately send input to the AutomationTester.in server. The endpoint processes the request in memory, does not persist it, and does not call a third-party model. Sensitive evidence should use the local browser workflow unless the caller's policy permits server processing.
Analytics and tool telemetry
We load two aggregate product measurement scripts on public pages: Google Analytics 4 and PostHog. Both record the page path you visited, a coarse section label for that path, referrer, and standard browser and approximate-location data those services derive from the request. Beyond page views, we record only fixed action names, such as which tool was run.
We do not measure tools by capturing pasted content, generated output, raw logs, selectors, tokens, file names, input lengths, or content hashes. Session replay and automatic click capture are disabled. Measurement is switched off on authenticated and administrative pages: the dashboard, admin, and every sign-in, registration, and password-reset route are never tracked.
PostHog sets a first-party cookie so repeat visits from the same browser are counted once, and honours your browser's Do Not Track setting. If you sign in to an enabled account, the only identifier attached is your opaque account ID — never your email address or profile details.
1. Information We Collect
We collect information you deliberately provide through an enabled account, submission, newsletter, or contact workflow. This may include:
- Your name and email address (via OAuth or email registration)
- Professional details (skills, links, bio) added to your profile
- Contact form submissions (name, email, message)
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process a payment only if a clearly presented paid workflow is explicitly enabled and you choose it
- Communicate with you about your account and our services
- Protect AutomationTester.in and our users from fraud and abuse
3. Payment Data & Security
Monetization and public paid plans are currently disabled. If a clearly presented payment workflow is enabled later, payments will be processed by Razorpay, a PCI DSS Level 1 compliant Payment Aggregator regulated by the Reserve Bank of India (RBI).
- We never store your credit/debit card numbers, CVVs, expiry dates, or UPI PINs on our servers.
- Payment information is transmitted directly to Razorpay over encrypted (TLS/SSL) connections.
- We store only transactional metadata (order ID, payment status, amount) for record-keeping and refund processing.
For more information on how Razorpay handles your data, please refer to Razorpay's Privacy Policy.
4. Data Localisation
In compliance with RBI requirements, all payment-related data is processed and stored on servers located within India. Our database is hosted on Supabase with an India (Mumbai) region deployment.
5. Data Security
We take reasonable measures to help protect information about you from loss, theft, misuse, and unauthorized access, including:
- HTTPS encryption across the entire website
- Secure API key management (server-side only)
- Cryptographic verification of all payment and webhook signatures
- Content Security Policy (CSP) headers to prevent cross-site scripting
6. Third-Party Services
Depending on the workflow you deliberately use, the application is configured to work with these third-party services:
- Razorpay — Payment processing when a paid workflow is enabled; monetization is currently disabled
- Supabase — Database hosting (India region)
- NextAuth.js — Authentication (OAuth via GitHub, Google)
- Resend — Transactional emails
Each of these services maintains their own privacy policies governing data they process on our behalf.
7. Your Rights — Data Deletion
You have the right to request deletion of your personal data. To exercise this right:
- Send an email to [email protected] with the subject "Data Deletion Request"
- Include your registered email address for verification
- We will process your request within 30 calendar days
- Upon deletion, your profile, activity history, and associated data will be permanently removed
Please note that we may retain certain transactional records as required by law (e.g., payment records for tax compliance).
8. Cookies
We use essential cookies required for authentication (session tokens), and aggregate measurement cookies set by Google Analytics and PostHog to count a repeat visit once. We do not use third-party advertising cookies.
9. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- Email: [email protected]
- Phone: +91 84467 37046
- Address: Flat No. 1302, A3 - Crimson Tower, Mi Retreat Center, Arjunganj, Sultanpur Road, Lucknow, Uttar Pradesh 226002, India