Privacy Policy
Effective 8 September 2026
This Policy explains how Qualium AI (“Qualium”, “we”, “us”) handles personal information when you visit our website, create an account, connect software, or use our automated quality-assurance service.
1. Information we collect
- Account and organisation data: name, email address, authentication identifiers, organisation membership, roles, and preferences.
- Billing data: plan, usage, transaction references, invoice status, and limited customer details. Payment-card details are handled by Stripe and are not stored by Qualium.
- Connected-system data: repository metadata and source content, staging URLs, encrypted access credentials, test identities, schemas, application responses, and configuration you choose to provide.
- QA evidence: test actions, screenshots, videos, logs, network observations, findings, reports, feedback, and generated patches. Evidence may contain data displayed by your staging application.
- Technical data: IP address, device and browser information, timestamps, diagnostic events, security logs, and service usage.
- Communications: support requests, survey responses, and correspondence with us.
2. Why we use information
We use information to authenticate users; provide repository discovery and QA runs; produce evidence, reports, and requested fixes; administer plans and billing; prevent abuse; protect customers and the Service; troubleshoot and support users; meet legal obligations; and improve reliability and product quality.
3. Legal bases and choices
Where applicable, we process information to perform our contract with you, pursue legitimate interests such as security and service improvement, comply with law, and act with consent where required. You can disconnect repositories, rotate credentials, cancel plans, and request access, correction, or deletion.
4. Service providers and disclosure
We disclose information only as needed to operate the Service, comply with law, protect rights and safety, complete a corporate transaction, or follow your instructions. Core providers may include GitHub for repository access, Supabase for authentication and databases, Fly.io for application hosting, OpenAI for AI processing, and Stripe for payments. These providers process data under their own terms and our applicable arrangements.
We do not sell personal information or use Customer Content for third-party advertising.
5. International processing
Our providers and their systems may process information outside your state or country. Where required, we use contractual and organisational safeguards for international transfers.
6. Security
We use access controls, tenant isolation, encryption in transit, encryption of repository and staging credentials at rest, private evidence storage, audit events, and protected source-control workflows. No security measure is perfect; use staging rather than production and avoid unnecessary personal or sensitive data in test environments.
7. Retention
We retain account, billing, QA, and audit information while needed to provide the Service, meet contractual and legal obligations, resolve disputes, and protect security. Retention varies by data type and plan. We delete or de-identify information when it is no longer required, subject to backups, fraud prevention, and legal obligations.
8. Your rights
Depending on where you live, you may request access to, correction of, deletion of, restriction of, or portability of personal information, or object to certain processing. You may also complain to your local privacy regulator. We may need to verify your identity and may retain information where law permits or requires.
9. Cookies and local storage
We use essential browser storage and authentication technologies to keep you signed in, protect sessions, remember workspace selections, and operate the Service. We do not currently use third-party advertising cookies.
10. Children
The Service is intended for business users and is not directed to children under 16. Do not provide children’s personal information through the Service.
11. Contact and complaints
For privacy requests or complaints, email privacy@qualium.aiworkerz.com. We will investigate and respond within a reasonable period. You may also contact the Office of the Australian Information Commissioner or the regulator in your jurisdiction.
12. Changes
We may update this Policy as the Service or law changes. We will publish the new effective date and provide reasonable notice of material changes.