Legal
Privacy Policy
Last updated 6 September 2026
- Who we are
- What we collect
- Data captured during a run
- Why we process it
- Who we share it with
- How long we keep it
- How we protect it
- Your rights
- International transfers
- Changes to this policy
- Contact
This policy explains what personal data BitAssure collects, why we collect it, and what you can do about it. It covers the marketing site and the signed-in application.
1. Who we are
BitAssure provides automated testing for websites and mobile applications, and is based in Gaborone, Botswana. For the data described in this policy we are the data controller, except for the content of your test runs, where we act as a processor on your instructions (see section 3).
2. What we collect
Account data
Your name, email address, hashed password, and the name of your organisation. We need these to create your account and to tell members of an organisation apart.
Usage data
Records of the projects, journeys and checks you create, and of the runs you start, including when they ran, how long they took, and whether they passed. This is the service doing its job.
Technical data
IP address, browser type and timestamps in our server logs, plus a request identifier attached to each request so a problem can be traced. We use these to operate the service securely and to debug faults.
Billing data
Where you pay for usage, our payment provider handles your card details directly. We receive a record that a payment succeeded and the billing details needed to issue an invoice. We never see or store your full card number.
3. Data captured during a run
This is the part of the policy specific to what BitAssure does, and it is worth reading carefully.
When a run executes, the service opens your application on a real browser or device and captures screenshots and a video recording of what appears on screen. If your application displays personal data during the walk, a customer name, an account balance, an email address, that data is captured in those artefacts and stored with the run.
You can delete a run, and its screenshots and recording, at any time from within the application.
4. Why we process it
- To provide the service, running your checks, storing your results, showing you reports. This is necessary to perform our contract with you.
- To keep the service secure, detecting abuse, rate-limiting sign-in attempts, investigating incidents. This is our legitimate interest in a safe service.
- To bill you, where you use paid features.
- To communicate with you, service notices, billing messages, and replies to your questions. Marketing email is sent only with your consent, and every one carries an unsubscribe link.
- To meet legal obligations, such as keeping accounting records.
5. Who we share it with
We do not sell personal data, and we do not share it for advertising. We use a small number of processors to run the service, each bound by contract to handle data only on our instructions:
- cloud hosting and object storage providers;
- a payment provider, for paid accounts;
- an email provider, for service and account messages;
- device and browser infrastructure providers, where a run executes on hardware we do not own.
We may also disclose data where we are legally required to, or to establish or defend legal claims. If we are ever party to a merger or acquisition, we will tell you before your data becomes subject to a different policy.
6. How long we keep it
- Account data, for as long as your account is open, then deleted within 30 days of closure.
- Screenshots and recordings, according to the retention period on your plan, after which they are deleted automatically. They can be deleted sooner on request.
- Run results, kept while the account is open so that history and trends remain meaningful.
- Server logs, a rolling window, typically 30 days.
- Invoices and accounting records, for as long as tax law requires, which is longer than the rest.
7. How we protect it
Passwords are hashed, never stored in a readable form. Session tokens are stored only as a hash, so a copy of our database does not hand over live sessions. Traffic is encrypted in transit, and stored screenshots and recordings are encrypted at rest. Every request is scoped to the organisation that owns the data, and checked on the server rather than trusted from the client.
More detail is on our security page .
8. Your rights
You can ask us to:
- give you a copy of the personal data we hold about you;
- correct anything that is wrong;
- delete your data, where we are not required to keep it;
- restrict or object to how we process it;
- provide it in a portable, machine-readable form.
Email privacy@bitassure.app and we will respond within 30 days. You can close your account yourself at any time without asking us. If you believe we have mishandled your data, you may complain to your local data protection authority.
9. International transfers
Your data is held in the United States. The service runs on servers on the west coast of the United States, and that is where your account, your recordings, your screenshots and your run results are stored. A run on a real phone or tablet executes on a device in a United States data centre, which means the app you are testing is reached from there.
So if you are in Botswana, or anywhere else, your data leaves your country to be processed. Where it does, we rely on recognised safeguards such as standard contractual clauses to keep the same level of protection with it. If your organisation needs its data to stay in a particular country, write to privacy@bitassure.app before you record anything, it is a question about where we run, and we would rather answer it honestly up front.
10. Changes to this policy
We will update this page when our practices change, and update the date at the top. If a change materially affects your rights, we will tell you by email or in the application rather than relying on you to notice.
11. Contact
Privacy questions go to privacy@bitassure.app. Suspected security issues go to security@bitassure.app.