← Back to home
Last updated July 23, 2026
Privacy Policy
This Privacy Policy explains what data Sugarssoft (“we”, “us”), the operator of
Test Chain, collects when you use the service, why we collect it, and the choices you have.
By using Test Chain you agree to the practices described here.
What we collect
- Account data. When you create a workspace we store your email address
and a securely hashed password. We never store your password in plain text.
- Recorded flows. The test suites you record — selectors, input values,
assertions, and navigation steps — are stored so you can replay them. If you record real
credentials or personal data into a step, that data is stored as part of the suite; use
the built-in template variables (e.g.
{{testEmail}}) to avoid persisting real
secrets where possible.
- Proxied content. When you point Test Chain at an application, we fetch
that application's pages and assets on your behalf through our proxy in order to inject the
recorder and drive the flow. Cookies set by the target app are held in an in-memory,
per-session cookie jar for the duration of the run.
- Run data. Results of replays and scheduled runs, including pass/fail
status, timing, and screenshots of failing steps.
- Technical data. Standard server logs (IP address, browser type,
timestamps) needed to operate and secure the service.
How we use it
- To provide the core service: recording, replaying, and scheduling your flows.
- To send you operational email — including failure alerts for scheduled runs to the
notify address you configure.
- To secure, debug, and improve the service.
Third-party processors
Test Chain relies on a small number of third parties to function. Data is shared with
them only as needed to perform the feature you invoke:
- Email verification (Mailsac). Email testing steps poll a real inbox
through Mailsac. Messages sent to the test addresses you use pass through Mailsac.
- AI steps (OpenAI / Anthropic). If you use a natural-language AI step,
the relevant page context and your instruction are sent to the configured AI provider to
generate the action. Steps that don't use AI never leave our infrastructure for this
purpose.
- Infrastructure. Application data is stored in PostgreSQL and Redis on
infrastructure we operate or rent.
We do not sell your personal data, and we do not share it with advertisers.
Cookies
We use a single first-party session cookie to keep you signed in. Cookies belonging to
the applications you proxy are isolated per session and are not used to track you across
sites.
Data retention
Account and suite data is retained for as long as your workspace exists. Per-session
cookie jars are held in memory only and are discarded when the session ends. You can delete
individual suites at any time, or contact us to delete your workspace entirely.
Your rights
You may request access to, correction of, or deletion of your personal data. To exercise
these rights, email us at rodi@sugarssoft.com.
Changes
We may update this policy from time to time. Material changes will be reflected by the
“Last updated” date above.
Contact
Questions about this policy or your data? Reach us at
rodi@sugarssoft.com.