Privacy Policy
This policy explains what Botsona collects when you visit botsona.io or use the app at app.botsona.io, why, who else handles it, how long we keep it, and how to turn usage data off or have your data deleted.
Who we are
Deep Variance Inc., a Delaware corporation at 447 Sutter St, Suite 506-1420, San Francisco, CA 94108, USA, provides Botsona and is the controller of the personal data described here. Questions about this policy or your data: founders@deepvariance.com, or by post to the address above.
The short version
- We do not sell personal data, share it for advertising, or use your content to train AI models.
- We collect usage data inside the app to improve it, with personal details masked. It is on by default and you can turn it off in Settings → Privacy at any time.
- Tests record the websites you choose to test. Before anything from a tested site is stored or sent to our AI provider, we mask sensitive form fields and remove email addresses, phone numbers, card numbers and secrets from its text.
- botsona.io sets no cookies and loads no analytics.
When you visit botsona.io
Cloudflare hosts and delivers botsona.io and processes the technical data every web request carries, such as your IP address, browser type and the page requested, to serve the site and protect it from abuse. The site loads no analytics. It stores one item on your device, botsona-theme, only if you choose light or dark mode.
Your account
An account needs an email address and either a password or a Google or GitHub sign-in. Supabase stores the account and sends the confirmation and password reset emails; we never store your password ourselves. If you sign in with Google or GitHub, they tell us your email address and name. We keep your email address, your name, which version of the Terms you accepted and when, your usage settings, and a sign-in session that lasts 30 days.
Your tests
When you run a test, we store the website address and the task you gave, and what the testers did: their steps and thoughts, the pages they visited, problems the pages reported (such as failed requests and script errors), screenshots, screen recordings, the accessibility check and the report.
A tested website can show personal data, for example a contact address on a page. To limit how much of it we keep:
- Fields that hold passwords, email addresses, phone numbers, card numbers or one-time codes are shown masked in the browser the testers use, so they are masked in screenshots, recordings and what the AI sees.
- What testers type into those fields is recorded as hidden. Testers are told to use made-up details everywhere else.
- Email addresses, phone numbers, card numbers, bank account numbers, US social security numbers and secrets such as API keys are removed from page text, step records and our logs before they are stored or sent to our AI provider, and web addresses are cut to their host and path.
Other text and images on the tested pages are kept as the testers saw them. Do not test pages that show other people's personal data unless you are allowed to share it with us.
To play the testers and write reports, we send our AI provider, OpenAI, the screenshots, the masked page text and the step records of the test, together with your task and the site's address. OpenAI processes it to give us answers and does not use it to train its models. It keeps it for up to 30 days to let a tester's conversation continue and to monitor for abuse.
Usage data inside the app
Unless you turn it off, the app records how it is used: which screens are opened, when tests are started, opened, stopped or deleted, when reports and recordings are viewed, when feedback is sent, and errors in the app. Each record carries a time, a random identifier for the browser tab, and an identifier derived from your account that we cannot turn back into your email address. It never includes your email address, your IP address, what you type, or full web addresses, and any text is cleaned of personal details before it is stored.
You can turn usage data off in Settings → Privacy. From then on, the app sends nothing, and anything it does send is discarded.
Feedback
When you send feedback in the app, we store your message, the kind you chose, the screen you were on, your account's email address and your browser type, and email a copy to our team through Azure Communication Services so that someone reads it.
Logs and security
Our servers record errors and the progress of tests, with personal details removed as described above. To protect the service from abuse, we limit requests by account or IP address; these limits are counted in memory and not stored.
Storage on your device
The app sets no cookies. It keeps these items in your browser's storage: your sign-in session and Supabase's sign-in state; your default testers; when you last saw or answered the feedback prompt and how long you have used the app this visit; and the random tab identifier for usage data. Signing out removes your session.
Why we use personal data
- To provide Botsona and operate your account and tests (performance of a contract).
- To keep Botsona secure, prevent abuse and fix problems (our legitimate interests).
- To understand how Botsona is used and improve it, through usage data you can turn off at any time (our legitimate interests).
- To read and reply to feedback and keep records we are required to keep (legitimate interests and legal obligations).
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.
Who else handles it
| Provider | What for | What they receive |
|---|---|---|
| Microsoft (Azure) | Hosting the app, its database (United States), test files and logs; sending feedback emails through Azure Communication Services | Account records, tests and their files, usage data, feedback, logs |
| OpenAI | Running the testers and writing reports | Screenshots, masked page text and step records of tests, your task and the site's address |
| Supabase | Sign-in | Email address, name, password (processed, not stored by us), Google or GitHub identity |
| Cloudflare | Hosting botsona.io, DNS and network protection | Web request data |
| Google, GitHub | Sign-in, only if you choose them | That you are signing in to Botsona |
Where data is processed
Deep Variance is based in the United States, and our providers process data in the United States and other countries. Where the law requires a safeguard for data transferred out of the EU, UK or Switzerland, we and our providers use the EU standard contractual clauses (with the UK addendum) or the provider's certification under the EU-US Data Privacy Framework.
How long we keep it
- Account: until you ask us to delete it.
- Tests: until you delete them. Deleting a test removes its steps, screenshots, recordings and report; we keep a bare record that it existed, without its content, so it still counts toward your test limits.
- Usage data: deleted automatically after 13 months.
- Feedback: deleted automatically 24 months after we receive it.
- OpenAI conversation state: up to 30 days.
- Server logs: 30 days. Database backups: 7 days.
Your rights
Depending on where you live, you can ask to access, correct, delete or receive a copy of your personal data, object to or restrict how we use it, and withdraw consent. Email founders@deepvariance.com from your account's address and we will respond within 30 days. You can also complain to your data protection authority. California residents: we do not sell or share personal information as those terms are defined in California law.
Children
Botsona is not for anyone under 18, and we do not knowingly collect their personal data.
Security
Data is encrypted in transit and at rest with our providers. Test files are reachable only through links that expire after an hour, and our staff access data only to provide and support Botsona.
Changes
If we change this policy in a way that matters, we will update the date above and tell account holders by email or in the app before the change takes effect.