Legal

Privacy Policy

Last updated: September 13, 2026

This Policy explains what data inverseStory collects, how we use it, and the choices you have.

1. Scope of this Policy

This Privacy Policy explains how inverseStory ("inverseStory", "we", "us") collects, uses, and shares information in connection with the inverseStory Service. It covers information about the people who use the Service ("Account Data") and, separately, describes our role with respect to the Test Data your Organization uploads.

For Test Data, your Organization is the data controller (it decides what to upload and who can access it) and inverseStory acts as a service provider / processor, handling that data to operate the Service on your Organization's instructions. For Account Data (registration and billing information about the people using the Service), inverseStory acts as the controller.

2. Information We Collect

Account and profile data

  • Name, work email address, password (stored as a salted hash, never in plain text), job title, and Organization/Project role.
  • Login activity: last login time, failed login attempts, IP address, and browser/user-agent string, used for account security (e.g., temporary lockout after repeated failed logins).
  • Invitations you send or receive, and an audit log of administrative actions taken in your Organization (who did what, and when).

Organization and billing data

  • Company/Organization name, approximate team size, and stated use cases, collected at signup.
  • Billing profile details you provide: legal/billing name, tax ID, billing address, invoice email, and currency.
  • Limited payment method metadata (card brand, last four digits, expiry) and invoice history. Full payment card numbers are handled by our payment processor, not stored on our servers.

Customer Data / Test Data

Test execution results, suite and test case metadata, run history, logs, stack traces, and screenshots or other attachments that you or your CI/test tooling upload. This is content your Organization controls; see the "Customer Data" section above.

Local storage and cookies

The web app stores your session token and interface preferences (such as light/dark theme and sidebar state) in your browser's local storage so you stay signed in and your preferences persist across visits. As of this policy's date, we do not use third-party advertising or analytics cookies. If that changes, we will update this Policy.

3. How We Use Information

  • To provide the Service: authenticate you, enforce Organization/project roles, ingest and display your Test Data as dashboards, reports, and executions.
  • To operate AI Insights where your Organization has it enabled (see the dedicated section below).
  • To bill your Subscription, send invoices, and manage trials, upgrades, and downgrades.
  • To send transactional email: verification links, invitations, password resets, and service notices.
  • To secure the Service: detect abuse, enforce account lockout after repeated failed logins, and investigate suspicious activity via audit logs.
  • To provide support when you contact us, and to improve the Service based on aggregated usage patterns.
  • To comply with legal obligations.

4. AI Insights Processing

Where an Organization's plan includes AI Insights and an Owner has left it enabled, the feature processes that Organization's Test Data through automated analysis to produce insights, summaries, or suggestions shown back to that Organization's users. An Organization Owner can turn AI Insights off at any time, and we also support a platform-level control that disables AI Insights for an Organization entirely.

We do not use Test Data to train general-purpose AI models shared across customers, and we do not sell Test Data or Account Data to anyone.

5. How We Share Information

We do not sell personal data. We share information only in these circumstances:

  • Service providers who process data on our behalf and under contract — for example, email delivery for transactional messages, and (when a paid plan is active) a payment processor to handle billing.
  • At your direction — for example, when an Organization chooses "External" storage and connects its own database, or when an Owner exports data.
  • Legal reasons — to comply with applicable law, regulation, or valid legal process, or to protect the rights, safety, or property of inverseStory, our customers, or others.
  • Business transfers — if inverseStory is involved in a merger, acquisition, or asset sale, data may be transferred as part of that transaction, subject to this Policy or a successor policy of at least equivalent protection.

6. Data Storage and Security

By default, an Organization's data is stored in shared infrastructure we operate, logically isolated by Organization. Enterprise plans can choose a dedicated database, a dedicated cluster, or a database the Organization itself owns and operates.

Where an Organization supplies its own database credentials (the "External" option), we store those credentials encrypted (AES-256-GCM) and never in plain text. Passwords for inverseStory accounts are stored as salted hashes, not in plain text. We use role-based access control internally and log administrative actions performed within your Organization.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We work to apply reasonable, industry-standard safeguards appropriate to a service handling engineering and business data.

7. Data Retention

We retain Account Data and Test Data for as long as your Organization's account is active, plus a reasonable period afterward to allow for export requests and to meet legal, billing, or dispute-resolution needs.

When an Organization closes its account or requests deletion, we delete or anonymize the corresponding data from active systems within a reasonable period, and it is then removed from backups in the ordinary course of our backup rotation.

8. Your Rights and Choices

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can update most Account Data yourself from your profile settings; for anything else, or for Organization-level data requests, contact us at privacy@inversestory.dev.

Because Test Data belongs to your Organization, requests concerning it are generally directed to your Organization's Owner or Admin, who controls access within the Service.

9. International Use

inverseStory is operated from India. If you access the Service from another country, your information may be processed in India or wherever your Organization's chosen storage tier places it, which may have different data protection laws than your own jurisdiction.

10. Children's Privacy

inverseStory is a business tool intended for use by engineering teams and is not directed at, or knowingly used to collect data from, children under 16.

11. Changes to this Policy

We may update this Policy as the Service evolves. Material changes will be announced in-product or by email to Organization Owners before they take effect. The "Last updated" date at the top of this page reflects the current version.

12. Contact Us

Questions about this Policy or your data can be sent to privacy@inversestory.dev.