Effective: August 19, 2026
Privacy Policy
Daniel Feinberg, doing business as QA Mode ("we," "us," "our"), operates the QA Mode mobile app for iOS and Android and the web app at qamode.io. This Privacy Policy explains what data we collect, how we use it, and your rights.
1. What We Collect
We collect data only when you actively use QA Mode — signing in, sending a report, or connecting an issue tracker. Nothing leaves your device unless you take one of those actions.
1.1 Account Data
| Data | Source | Purpose |
|---|---|---|
| Email address | Sign-in | Account creation, communication |
| Name | Optional, you can edit it in the app | Showing who sent a report |
| User ID | Assigned when you sign in | Identify your account |
| Issue tracker access tokens | The connection flow you complete with your tracker | Create issues on your behalf. Encrypted and stored server-side. |
1.2 Report Data
A report is created when you share a screenshot or screen recording into QA Mode and send it. It contains:
| Data | What's Included |
|---|---|
| Images and recordings | Exactly the screenshots or screen recordings you chose to share into QA Mode |
| Your note | The text you type describing the issue — its first line becomes the report title |
| Device context | Device model, operating system and version, language, and time zone |
| Sender and time | Who sent the report, which team it went to, and when |
Older reports: reports created before August 2026 with our discontinued browser extension may also contain browser details and recent console and network entries captured at the time. We keep and display them unchanged. Delete the report to remove them.
QA Mode has no photo library access and no in-app photo picker. Images reach the app only through the iOS share sheet or the Android share menu, when you pick QA Mode as the destination. The app never uses your microphone or camera.
1.3 Usage Data
| Data | Purpose |
|---|---|
| Reports captured and sent, by team | Understand product usage and enforce plan limits |
These are counts and identifiers, not the content of your reports. They are sent to our own servers — QA Mode contains no third-party analytics or advertising SDK.
1.4 What We Do NOT Collect
- No microphone, voice, or camera data
- No photo library browsing — only what you deliberately share
- No location data
- No contacts
- No browsing history or website tracking
- No advertising identifiers, tracking pixels, or fingerprinting
- No financial or health information
2. How We Use Your Data
| Use | Data Involved |
|---|---|
| Show reports in your team's inbox and on the web dashboard | Report data (Section 1.2) |
| Create an issue in your connected tracker | Report title, your note, device context, capture time, your name, image and recording links, and a link to the full report |
| Provide a shareable link to a report | Report data |
| Enforce plan limits | Usage data |
| Sign you in and keep you signed in | Account data |
What We Do NOT Do
- We do not sell your data
- We do not use your data for advertising
- We do not share your data with data brokers
- We do not use your data to train AI models
- We do not profile you for marketing
QA Mode does not send your reports to any AI service. There is no automated content generation in the product.
3. Who Can See Your Reports
- You can see every report you send.
- Your teammates can see reports sent to a team you both belong to. A team inbox is shared by design — that is the point of it.
- Anyone with a share link. When a report is sent to an issue tracker, we create a link to a read-only view of that report so people reading the issue can see the screenshot and note. That link works without signing in. Treat it as public and share it accordingly. A share link stays valid until the report is deleted. We do not currently offer a way to revoke a link on its own — delete the report if you need the link to stop working.
- Images and recordings are served from long, unguessable web addresses so they can be embedded in your issue tracker. Anyone holding the address can view the file.
4. Data Controller and Processor
You (or your organization) are the Data Controller. You decide what to screenshot, what to write, and where to send it.
We are the Data Processor. We process your data solely to run QA Mode, on your instructions — you sharing an image, typing a note, and tapping send.
In plain terms: you decide what gets collected (controller), and we only handle it on your instructions (processor).
5. Third-Party Services We Use (Sub-Processors)
| Service | Data Shared | Purpose | Location |
|---|---|---|---|
| Clerk | Email, name, user ID, session tokens | Authentication and team membership | US |
| Supabase | Account references, report data, usage counts, encrypted tracker tokens | Database | US |
| Cloudflare | Images, recordings, and all API traffic | File storage and our API | Global |
| Vercel | Web app traffic | Hosting the web dashboard | Global |
| Expo (EAS Update) | App version and device/runtime metadata | Delivering app updates | US |
| GitHub | Issue title, body, image links | Issue creation on your account | US |
| Atlassian (Jira) | Issue summary, description, image links | Issue creation on your instance | US/EU |
| Linear | Issue title, description, image links | Issue creation on your workspace | US |
| Trello | Card name, description, image links | Card creation on your board | US |
We rely on each sub-processor's standard data processing commitments. Where no standalone DPA exists, we rely on the data processing terms in their standard terms of service.
Important: Issues are created on your tracker account using your access token. Once an issue exists in your tracker, its content is also governed by that tracker's privacy policy.
6. Storage and Retention
6.1 Where Data Lives
| Data | Location | Protection |
|---|---|---|
| Reports and their images | Cloud database and storage (US/Global) | Encrypted at rest, encrypted in transit |
| Tracker access tokens | Cloud database (US) | Encrypted at rest |
| Usage counts | Cloud database (US) | Encrypted at rest |
| Account data | Authentication provider (US) | Encrypted at rest |
| Reports waiting to send | Your device only, in the app's private storage | Protected by your device |
Offline queue: if you send a report with no connection, the image and note wait in the app's private storage on your device and upload when you are back online. Nothing in that queue has left your device yet.
6.2 How Long
| Data | Retention |
|---|---|
| Reports and images | Deleting a report in the mobile app hides it and can be undone; the report and its files are removed permanently when deleted from the web dashboard, when the team is deleted, or when you delete your account |
| Tracker tokens | Until you disconnect the integration, the token expires, or you delete your account |
| Usage events | Kept in our server logs for a limited period; not deleted individually when you delete your account |
| Account data | Until you delete your account |
6.3 Deleting Your Account
You can delete your account in the mobile app (Settings → Account → Delete account) or on your account page at qamode.io. When you do, we immediately delete:
- Your personal reports and the images and recordings attached to them
- Your issue tracker access tokens
- Your team memberships
- Your account with our authentication provider
Reports you sent to a team are not deleted. They belong to that team's shared inbox and stay there for your teammates, along with their images and recordings, the same way a message you sent to a shared inbox does. If you want a team report removed, delete it before deleting your account, or ask a teammate to delete it. Deleting an entire team deletes its reports.
Anything still queued on your device is erased from the device as part of deletion.
7. Data About Other People
A screenshot you share may contain information about other people — customers, end users, colleagues. QA Mode does not alter or redact your images; it sends exactly what you shared.
Your responsibilities as Data Controller:
- Only share screenshots you have the right to share
- Check what is on screen before you share it
- Follow your organization's data handling policies
- Do not use QA Mode to capture other people's sensitive personal data (health records, financial data, government IDs) without proper authorization
Our responsibilities as Data Processor: we process this data only to run the Service. We do not analyze your images, and we do not attempt to identify people in them.
8. Your Rights
8.1 Everyone
You can:
- See your reports in the app and at qamode.io
- Edit or delete individual reports — deleting a report also stops its share link from working
- Disconnect issue trackers in your account settings
- Delete your account in the app or on the web
8.2 EU/EEA/UK Users (GDPR)
You have the right to access, rectification, erasure, restriction of processing, data portability, objection, and to lodge a complaint with your local data protection authority.
Legal bases:
- Contract performance — processing needed to provide QA Mode (Art. 6(1)(b))
- Legitimate interest — usage counts, to prevent abuse and enforce plan limits (Art. 6(1)(f))
International transfers: data is transferred to the US for processing by our sub-processors. We rely on Standard Contractual Clauses approved by the European Commission — a standard EU-approved contract for sending data to the US.
Contact danny@qamode.io with "GDPR Request" in the subject line.
8.3 California Users (CCPA/CPRA)
You have the right to know what we collect, to delete it, to opt out of sale (we do not sell), and not to be discriminated against for exercising these rights.
Categories collected: identifiers (email, name, user ID); visual information (screenshots and recordings you share); other user content (your note); device information (model, OS version, language, time zone); coarse location inferred only from your time zone.
We do not sell personal information and we do not share it for cross-context behavioral advertising.
Contact danny@qamode.io with "CCPA Request" in the subject line.
8.4 Other US State Laws
We comply with applicable state privacy laws including the Virginia CDPA, Colorado CPA, Connecticut CDPA, and Utah UCPA. Residents have rights similar to those above. Contact danny@qamode.io.
9. Cookies
Our web app at qamode.io uses first-party cookies from our authentication provider to keep you signed in. That is all. No analytics cookies, no advertising cookies, no tracking pixels. The mobile app does not use cookies.
10. Children's Privacy
QA Mode is a professional software testing tool. We do not knowingly collect personal information from children under 16. If you believe we have, contact danny@qamode.io and we will delete it promptly.
11. Security
- Encryption in transit for all communication
- Encryption at rest for stored data
- Issue tracker tokens encrypted before they are stored
- Authentication required on every API endpoint except the file and share-link URLs described above
- Rate limits and usage limits to prevent abuse
A note on file and share links: images, recordings, and shared reports are reachable by anyone who has their web address, because your issue tracker needs to load them. Those addresses are random and unguessable, but they are not access-controlled. A share link stays valid until the report is deleted; we do not currently offer a way to revoke a link on its own.
Breach notification: we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, and affected users without undue delay where required by law.
Security concerns: danny@qamode.io.
12. Changes to This Policy
We will post any updated version at qamode.io/privacy with a new effective date, and email you at least 30 days ahead of material changes. Continued use after the effective date means you accept the update.
13. Contact
QA Mode
Email: danny@qamode.io
Website: https://qamode.io