Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains what data Proba.run (the “Service”) collects, how it is used, and what choices you have.
1. Who is responsible for your data
The Service is operated by Vladyslav Kaplin, a private entrepreneur (FOP) registered in Ukraine (“the Operator”). Contact: [email protected].
- For account data (your profile and login), the Operator acts as the data controller.
- For content your organization stores in the Service (test cases, runs, requirements, sessions, attachments, comments — “Customer Content”), the organization that invited you is the controller, and the Operator processes this data on its behalf to provide the Service.
2. Data we collect
- Account data: email address, name, avatar (if uploaded), authentication data managed by our authentication provider, and optional two-factor authentication settings.
- Organization data: organization name, membership, roles and permissions.
- Customer Content: the material your organization creates in the Service.
- Audit and security logs: records of significant actions (who did what and when), including the IP address of the request. Used for security and accountability inside your organization.
- Integration settings: if your organization connects third-party services, the connection settings (including access tokens) are stored encrypted (AES-256-GCM).
- API keys: stored only as cryptographic hashes; the full key is shown once at creation and cannot be recovered by us.
- Technical logs: basic server logs needed to operate and secure the Service.
- Waitlist (pre-launch): if you join the waitlist, we store your email address and interface language solely to contact you about the launch. These records are deleted after the launch announcement, or earlier on request.
We do not collect data for advertising and we do not sell personal data.
3. How we use data
- to provide the Service: authentication, authorization, storing and displaying Customer Content;
- to secure the Service: audit logs, abuse and rate-limit protection, incident investigation;
- to communicate service messages: invitations, email confirmations, password resets and similar transactional email;
- to provide support when you contact us.
Where the GDPR applies, we rely on the following legal bases: performance of our contract with you (providing the Service and sending service messages), our legitimate interests (securing the Service, preventing abuse and investigating incidents), and your request or consent for optional features (such as AI actions or joining the waitlist).
4. Cookies
The Service uses only cookies that are strictly necessary or set at your request:
- Authentication cookies — keep you signed in and secure your session. Set by our authentication provider when you log in.
- Language preference cookie — remembers the interface language you selected.
Traffic statistics are collected with a cookie-less analytics tool (Cloudflare Web Analytics), which does not store identifiers on your device and does not track you across sites.
We do not use advertising or cross-site tracking cookies. Because the Service sets no optional cookies, no cookie consent banner is required; if this ever changes, we will ask for your consent first.
5. AI features
AI-assisted features are optional and controlled per project (and can be disabled instance-wide). When a project has AI enabled and a member requests an AI action, the relevant project text is sent to the AI provider to produce the result. When AI is disabled, nothing is sent. Current AI provider: Anthropic (Claude models). We send only the data needed for the requested action, under the provider’s API terms.
6. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Supabase | Database hosting, authentication, file storage |
| Time4VPS | Server hosting for the application |
| Cloudflare | Content delivery, traffic protection, cookie-less web analytics |
| Resend | Transactional email delivery |
| Anthropic | AI features (only when enabled) |
A payment provider will be added to this list when paid subscriptions go live. We will update this Policy accordingly.
A Data Processing Agreement (DPA) covering our processing of Customer Content on behalf of your organization is available on request at [email protected].
7. Data retention
- Account data and Customer Content are retained while your account and organization use the Service.
- Audit logs are retained for 90 days (including IP addresses) and then deleted automatically.
- Backups are kept for a limited period as part of normal operations and then rotated out.
8. Account deletion and anonymization
When an account is deleted, we anonymize it: personal identifiers (name, email, avatar, login) are removed or replaced with neutral values. Contributions made to an organization (test cases, results, comments) are preserved in anonymized form, because they are part of the organization’s records — this reflects how deletion works in team tools. Deleting an entire organization permanently deletes its Customer Content.
9. Your rights
Depending on applicable law (including the GDPR for users in the EU/EEA), you have the right to access, rectify, erase and receive a copy of your personal data, to object to or restrict certain processing, and to lodge a complaint with a supervisory authority.
- Profile data can be viewed and edited directly in the Service.
- For erasure, use account deletion (Section 8) or contact us.
- For a copy of your personal data or other requests, contact [email protected] — we respond within the timeframes required by law.
- For Customer Content controlled by your organization, please contact the organization’s administrators; we will assist them as processor.
10. Security
We apply technical and organizational measures appropriate to the risk: encrypted connections (TLS), row-level access control in the database in addition to application-level permission checks, encryption of stored integration secrets, hashed API keys, optional two-factor authentication, and audit logging.
11. International data transfers
Our service providers may process data outside your country, including in the EU and the United States. Where required, transfers rely on appropriate safeguards such as the providers’ standard contractual clauses.
12. Children
The Service is intended for professional use and not directed at children under 16. We do not knowingly collect their data.
13. Changes to this Policy
We may update this Policy. For material changes we will give notice in the Service or by email before the changes take effect. The “Last updated” date above always reflects the current version.
14. Contact
Privacy questions and data requests: [email protected].