Privacy policy
Last updated 22 September 2026
qarunbook (qarunbook.com) is an app-testing runbook: teams write test plans, record results and raise issues against the apps they build. This page says what we keep to make that work. We do not sell data, show ads, or use analytics or tracking scripts.
What we store
- Your account: name, email address, and a salted hash of your password — never the password itself.
- Your workspace: its name, its members and their roles, and invitation or join links you create.
- What you put in: test plans, results, issues, their edit history, and files you attach to issues.
- An access token for each member, so an AI assistant you connect acts as you. You can replace it at any time.
- A usage record of actions (such as a result recorded), shown to your workspace on its Usage page.
Cookies and browser storage
One cookie, qa_session, keeps you signed in. It is HttpOnly and sent only to qarunbook.com. Your browser also remembers your light/dark choice and whether you have signed in before, so the right screen shows while the page loads. There are no advertising or third-party tracking cookies.
Visitors to the public pages
We count page views on the public pages — the home page, the guides, and these policies — so we know which pages are useful and roughly where readers are. It uses no cookies and no third-party analytics. For each view we keep the page, the site that linked to it, the country and city our host reports at the network edge, and whether the device is a phone, tablet or computer.
We do not store IP addresses. To avoid counting one person ten times in a day, the address and browser are turned into a one-way code with a salt that changes daily, so the same reader cannot be recognised from one day to the next. If your browser sends “Do Not Track” or Global Privacy Control, nothing is recorded at all. None of this runs inside the app once you are signed in.
Who processes it for us
- Vercel — hosts the website and the API.
- MongoDB Atlas — the database.
- Backblaze B2 — stores files attached to issues.
- Bunny.net — streams video attachments.
- Zoho ZeptoMail — sends account emails (verification, invitations, password resets, confirmation codes).
- Cloudflare — DNS for the domain and forwarding of mail sent to our addresses.
- Google Fonts — serves the typeface the site uses.
Who can see your work
Only members of your workspace, limited by the role and apps an owner gives them. No other workspace can see it.
Deleting your data
Owners can delete apps, and everything recorded against them, from inside the app. To remove your account or a whole workspace, write to hello@qarunbook.com from the address on the account and we will delete it.
Changes
If this policy changes in a way that matters, we will update the date above and say so in the app.
Questions? Write to hello@qarunbook.com. Privacy · Terms