TestForge Logo TestForge Logo TestForge Product Services About Contact
Sign In Start Building
Legal

Privacy Policy

This Privacy Policy explains what information TestForge collects, how we use it, how we store it, and what rights you have regarding your data.

On This Page
  • Overview
  • Data Collected
  • How Data Is Used
  • Data Storage
  • Cookies & Local Storage
  • Security Practices
  • Third-Party Services
  • Your Rights
  • Children's Privacy
  • Changes to Policy
  • Contact
Section 01

Overview

TestForge ("we", "us", "our") operates the testforge.in platform ("Platform"). This Privacy Policy describes our practices regarding the collection, use, and protection of information when you use our Platform.

By creating an account and using TestForge, you consent to the data practices described in this policy. This policy should be read alongside our Terms & Conditions.

Our approach: TestForge is designed with a local-first architecture. The Platform executes test operations within your browser environment. We collect only the data necessary to provide account management, organization collaboration, and platform functionality.

Section 02

Data Collected

We collect the following categories of information when you use the Platform:

Account Information

When you register, we collect:

  • Full name (display name)
  • Username
  • Email address
  • Password (stored in hashed form)
  • Timestamp of account creation
  • Timestamp of consent acceptance (Terms & Privacy Policy)

Organization Data

If you create or join an organization, we collect:

  • Organization name
  • Organization membership information (user ID, role, join method)
  • Organization join key usage
  • Membership approval/rejection records

Platform Usage Data

As you use the Platform, we may store:

  • Test suite configurations, API collections, and flow designs you create
  • Test execution history and results
  • Workboard items (tasks, issues, assignments)
  • Manual test case records and step results
  • Notification records and preferences

Session & Authentication Data

  • Session tokens and authentication state
  • Login timestamps
  • Role and permission assignments

API Metadata

When you use the API Lab, we may store request configurations (URLs, headers, methods) as part of your saved collections. We do not store API response data from third-party systems on our servers — responses are processed locally in your browser.

Data Category Stored Where Purpose
Account credentials Supabase / localStorage Authentication
Organization membership Supabase / localStorage Team collaboration
Test configurations localStorage / Supabase Platform functionality
Execution history localStorage Insights & diagnostics
Notifications Supabase Team communication
Session state sessionStorage Authentication persistence
Section 03

How Data Is Used

We use the information we collect for the following purposes:

Platform Operation

  • Authenticating your identity and maintaining your session
  • Providing access to Platform features (test execution, flow automation, API testing)
  • Persisting your configurations, test data, and preferences across sessions
  • Generating insights and diagnostics from test execution results

Account & Organization Management

  • Managing your account settings and profile
  • Facilitating organization creation, membership, and role management
  • Processing organization join requests and approval workflows
  • Enforcing role-based access controls

Notifications

  • Delivering in-platform notifications about organization events, membership changes, and task assignments
  • Respecting your notification preferences and settings

Platform Improvement

  • Understanding how features are used to improve Platform functionality
  • Identifying and resolving technical issues

We do not: sell your data to third parties, use your data for advertising, or share your testing data with other users outside your organization.

Section 04

Data Storage

Organization-Scoped Storage

Data created within an organization context (test suites, API collections, workboard items) is scoped to that organization. Members of an organization may have access to shared data based on their assigned role and permissions.

Local Browser Storage

TestForge uses browser-based storage mechanisms (localStorage and sessionStorage) for certain data persistence. This data remains on your device and is not transmitted to our servers unless explicitly synced through Platform features.

Cloud Storage (Supabase)

When connected to our cloud infrastructure, data such as account credentials, organization memberships, and notification records is stored on Supabase, a third-party database and authentication provider. Supabase stores data in managed PostgreSQL databases.

Realtime Systems

The Platform uses Supabase's realtime capabilities for delivering notifications and enabling collaboration features. Realtime data is transient and processed in-memory for delivery purposes.

Logs & History

Test execution logs, insight records, and workflow history are stored primarily in browser localStorage. These records are associated with your account and organization context.

Data Retention

We retain your data for as long as your account is active or as needed to provide Platform services. If you delete your account, we will make reasonable efforts to remove your personal data from our active systems, subject to technical feasibility and legal requirements.

Section 05

Cookies & Local Storage

Transparency: TestForge does not use tracking cookies, advertising cookies, or third-party analytics cookies. We use only browser storage APIs (localStorage and sessionStorage) for functional purposes.

What We Store Locally

Storage Key Type Purpose
tf_session sessionStorage Current authentication session
tf_theme localStorage Theme preference (dark/light)
tf_users localStorage User account data (local fallback)
tf_orgs localStorage Organization data (local fallback)
tf_notification_prefs localStorage Notification channel preferences

Supabase Authentication Cookies

When authenticated through Supabase, the Supabase client library may store authentication tokens in localStorage using keys prefixed with sb-. These tokens are used solely for maintaining your authenticated session with the Supabase backend.

No Tracking

We do not use cookies or any local storage mechanism for tracking, advertising, or behavioral profiling. All stored data serves a direct functional purpose for Platform operation.

Section 06

Security Practices

We implement reasonable security measures to protect your data. These measures include:

Role-Based Access Control

TestForge enforces a deny-by-default role-based access control (RBAC) system. Every action within the Platform is gated by permissions tied to the user's assigned role (Owner, Manager, Tester). Permissions are checked both at the UI level and in data access logic.

Organization Isolation

Data created within an organization is scoped to that organization. Users cannot access data belonging to other organizations unless they are members with appropriate permissions.

Authentication

The Platform supports authentication through Supabase Auth (email/password) with session-based access management. Passwords are not stored in plaintext.

Security Headers

The Platform is served with security headers including X-Content-Type-Options, X-Frame-Options, and X-XSS-Protection to mitigate common web vulnerabilities.

Honest assessment: While we implement reasonable security measures, no system is completely secure. We do not guarantee absolute security of your data. We encourage you to use strong, unique passwords and to safeguard your account credentials.

Section 07

Third-Party Services

TestForge uses the following third-party services as part of its infrastructure:

Service Purpose Data Shared
Supabase Database, authentication, realtime Account data, organization data, notifications
Google Fonts Typography (Inter, JetBrains Mono) Standard font loading request (IP address)
Formspree Contact form processing Contact form submissions (name, email, message)
Vercel Hosting & deployment Standard web server access logs

Each third-party service operates under its own privacy policy. We encourage you to review their respective policies:

  • Supabase: supabase.com/privacy
  • Google Fonts: policies.google.com/privacy
  • Vercel: vercel.com/legal/privacy-policy

We do not currently integrate third-party analytics, advertising networks, or payment processing services.

Section 08

Your Rights

You have the following rights regarding your data:

Account Deletion

You may request deletion of your account by contacting us at hello@testforge.in. Upon account deletion, we will remove your personal data from our active systems. Data associated with organization workspaces may be retained for the organization's operational purposes.

Data Access & Export

You may request a copy of the personal data we hold about you. We will respond to data access requests within a reasonable timeframe.

Data Correction

You can update your account information (display name, email) through the Platform's profile settings. For changes that cannot be made through the Platform, contact us directly.

Organization Data Control

Organization owners have administrative control over their organization's data, including the ability to manage members, control access, and manage workspace content. If you are a member of an organization and wish to have your data removed, contact your organization's owner or reach out to us.

Local Data

Data stored in your browser's localStorage and sessionStorage can be cleared directly through your browser settings. Clearing browser data will remove locally-stored Platform data from your device.

Section 09

Children's Privacy

TestForge is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

If you believe we have inadvertently collected information from a child under 16, please contact us immediately at hello@testforge.in.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Effective" date at the top of this page
  • Where practical, notify users through in-platform notifications

Your continued use of the Platform after changes to this policy constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.

Section 11

Contact

If you have any questions about this Privacy Policy, your data, or your rights, please contact us:

  • Email: hello@testforge.in
  • Contact Page: testforge.in/contact

We will respond to all privacy-related inquiries within a reasonable timeframe.

Terms & Conditions · Privacy Policy · Contact · How It Works · Services
© 2026 TestForge. All Rights Reserved.