TesterAgent

Data retention and deletion policy

TesterAgent keeps your reports while your account exists, deletes screenshots 90 days after an audit, deletes uploaded APKs right after the analysis and logged-in sessions when the audit ends. Deleting your account removes everything at once, except backups, which expire on their own schedule.

Retention schedule

How long we keep each kind of data
DataKept
Account: email, name, password hash (scrypt — never the password), report language, accepted Terms version and date, how you first found usUntil you delete your account
Websites you add: address, test settings, optional login-page addresses, the login steps a checkpoint learned (step names and page paths — never what you typed), your “I own this website” confirmationUntil you remove the site or delete your account
Audit reports: scores, findings, HTML / Markdown / JSON report, test casesIn your history until you remove the site or delete your account (app reports: until you delete your account)
Screenshots of tested pages and app screens, including logged-in areas (stored on Cloudinary under random addresses)Deleted automatically 90 days after the audit started (free check: 7 days)
Raw check files on our server (per-check results, audit log)Deleted 90 days after the audit ended
Screenshot upload records (which image, size, upload status — not the image)365 days after the upload; deleted with your account
Uploaded APK fileDeleted right after the analysis (or when the audit is cancelled)
The app installed on our test phone, with its dataDeleted when the audit ends
Logged-in browser session of your site (cookies and storage after you log in)Deleted when the audit ends — we never see or store your password or one-time codes
Free check without an account: the report7 days
Free check: one-way keyed hash of your IP address30 days
Sign-in session (random token, stored only as a hash)30 days, or until you sign out
Email links (confirm email, reset password)Until used, or 48 hours / 2 hours
Monthly usage countersUntil you delete your account
Billing status: plan, status, renewal dates, provider customer and subscription ids, card brand and last 4 digitsUntil you delete your account. Invoices and payment records are kept by Lemon Squeezy (or PayPal) under their own policies
Payment notifications (webhooks) from Lemon Squeezy / PayPal — contain your billing name and email90 days
Misuse reports and opt-out requests sent with our form (your email, the domain, your message)365 days
Blocked-domain list (domain, reason)Until the block is removed
Sign-ups and free checks counted per traffic channel (no personal data)400 days

Automatic deletion jobs

  • Every few minutes the worker deletes screenshots on Cloudinary whose time is up (90 days after the audit started; free checks 7 days), or whose audit, report or site was deleted.
  • Every hour the worker deletes raw check files older than 90 days, leftover folders and abandoned APK uploads.
  • Database expiry (MongoDB TTL indexes) removes free-check reports, IP hashes, sign-in sessions, email links, payment notifications, misuse reports and upload records when their time is up.
  • Logged-in sessions and the app on our test phone are deleted in the same step that ends the audit — including failed or cancelled audits — and leftovers of a crashed worker are swept every minute.
  • Removing a site deletes its audits and reports at once and its screenshots within minutes.

When you delete your account

Account → Delete my account (after cancelling a running subscription) immediately deletes your account, sites, audits, reports, usage counters, billing status, sessions and email links; deletes your screenshots on Cloudinary (if Cloudinary cannot be reached, the worker retries and deletes them within its next runs); deletes your upload history; and removes local files of your audits. Invoices stay with Lemon Squeezy as the seller, as tax law requires.

Backups and logs

  • Database backups: [[OWNER: Atlas backup retention, e.g. daily snapshots kept 7 days (BACKUP_RETENTION)]]. Deleted data disappears from backups when they expire.
  • Server logs: [[OWNER: server log retention, e.g. 14 days with Docker log rotation (LOG_RETENTION)]].

Exceptions

We may keep specific data longer when the law requires it or to handle a legal claim or an abuse investigation, and only for that purpose.