Last updated: July 22, 2026
I provide QA Genie Studio, a hybrid-powered test case generation tool for quality assurance professionals. I collect only what is necessary to deliver the service. This policy explains what data I collect and how it is handled.
When you sign in with Google, I receive your email address and display name through Firebase Authentication. I do not store your password. Guest accounts use an anonymous device identifier — no personal information is required.
When you generate test cases, your module name, feature name, platform selection, and prompt notes are sent to my server and then to my AI provider to produce test cases. Prompts are sanitized (HTML stripped, truncated) before transmission. An optional PII scrubber may redact emails, phone numbers, URLs, and other sensitive patterns from prompts before they leave your device.
I track generation and export counts to enforce daily quotas and improve the service. This includes basic metadata such as feature interactions and export format preferences. No test case content is included in usage tracking.
Firebase Analytics tracks app opens, screen views, generation events (started/completed/failed), exports, rewarded ad completions, upgrade interest, and bug report submissions. Parameters include platform, mode, counts, durations, and categories. This data is anonymized and used to improve the app experience.
Device model, app version, and platform (Android) are collected only when you submit an issue report or AI content report. A device identifier (Android ID) is used for guest identity and quota enforcement.
When you submit a bug report, you may optionally attach photos from your camera or gallery, or files from your device. These attachments are uploaded to encrypted cloud storage and permanently deleted when you delete your account. The app requests camera or storage access only when you choose to attach a file — these permissions are never used for any other purpose.
Firebase Crashlytics automatically collects crash logs, stack traces, device state, and error diagnostics when the app encounters a fatal error. This data is used solely to diagnose and fix bugs. Crash data is not used for advertising, analytics profiling, or any purpose other than app stability improvement. Crash logs are retained independently of your account and are not deleted when you delete your account.
When you watch a rewarded ad, Google AdMob and its mediation partners (Unity Ads) may collect advertising identifiers, device information, and IP address in accordance with their privacy policies.
When you are signed in with Google, your test suites and their test case content are securely transmitted to my cloud infrastructure (Google Cloud Storage + Firestore) to enable access across your devices. This data is encrypted in transit and at rest.
Guest accounts are local-only — test case content never leaves your device.
I never analyze, train on, or share your test case content with any third party beyond the cloud infrastructure required to operate the sync feature.
QA Genie Studio uses the following third-party services:
To learn how Google uses data collected through AdMob, visit How Google uses data when you use our partners' sites or apps.
All communications use HTTPS/TLS encryption. Data stored on my servers is encrypted at rest. Firebase App Check verifies app integrity. Access to your data is restricted by security rules — only you and my backend functions can access your information.
QA Genie Studio is operated from Australia, but the third-party infrastructure that powers the app (notably Google Firebase, Google Cloud, and our AI provider) may process and store your data on servers located outside your country of residence, including in the United States and the Asia-Pacific region.
For transfers of personal data out of the European Economic Area (EEA) or the United Kingdom, I rely on Standard Contractual Clauses (SCCs) together with Google's Data Processing Terms, which incorporate the European Commission's approved transfer mechanisms. These measures ensure your data receives a comparable level of protection when processed abroad. You may request a copy of the relevant safeguards by emailing hello@qagenies.com.
Where the GDPR applies, I process your personal data under the following legal bases (Article 6 GDPR):
You can delete your account at any time through the app settings (Account → Delete Account). This removes your profile, usage data, synced test cases, and authentication credentials from my servers. A 24-hour cooldown prevents immediate re-registration of the same Google account.
To request account deletion from the web (for example, if you have uninstalled the app), send an email to wipe@qagenies.com from your registered email address. Include your account details and reason for deletion. Your account will be completely deleted within 24–48 hours. No take backs: once you send this email, deletion is irreversible and all your data will be permanently removed.
Local data on your device (SQLite database) must be cleared by uninstalling the app or clearing app data through Android settings.
I keep personal data only as long as necessary:
Depending on your jurisdiction, you have the following rights. For EEA/UK residents these include the rights under Articles 15–22 of the GDPR:
For California residents (CCPA/CPRA), you have the right to know, delete, correct, and opt out of the sale or sharing of personal information. QA Genie Studio does not sell or share your personal information as those terms are defined under the CCPA. There is therefore no "Do Not Sell or Share My Personal Information" opt-out required, and I will never deny you service or degrade your experience for exercising your privacy rights.
To exercise any of these rights, email hello@qagenies.com or delete your account via Account Deletion. I will respond within the timeframes required by law (generally one month under the GDPR). You also have the right to lodge a complaint with your local data protection authority.
QA Genie Studio is intended for professional and educational use and is not directed to children. I do not knowingly collect personal data from children under 16 in the EEA/UK, or under 13 in the United States (or the equivalent minimum age in your jurisdiction).
If you believe a child under the applicable age has provided me with personal data, email wipe@qagenies.com and I will delete it promptly.
I may update this policy from time to time. Continued use after changes constitutes acceptance of the updated policy.
General enquiries: hello@qagenies.com
Creator contact: chenchuenay@qagenies.com
Account deletion requests: wipe@qagenies.com (no take backs)