Your tests stay Playwright, Selenium and pytest. We don't replace them. We make them enterprise-ready, and you own everything: code, evidence and history.

Privacy

Last updated 2026-10-08 · one policy for this website, the account portal and Nexus Studio

This site sets no cookies and stores nothing in your browser. No local storage, no third-party analytics, no tracking pixels, no embedded video, no fonts loaded from anyone else's server. What it measures is a visit count, sent to our own servers at most once per page load and carrying two things only: the path of the page, without its query string or #fragment, and the site that linked you here, cut to its origin (https://example.org, never a page on it), or nothing if you came directly. It is kept as one row of web_events in the table below, with no IP address, cookie or identifier. If a script on the page fails, it also sends that page's path and the error message, cut to 200 characters; our server removes email addresses and long identifiers from the message and writes it to our hosting provider's request log, which deletes it after at most 7 days, not to that table. If your browser has Global Privacy Control or Do Not Track turned on, nothing is sent at all. What the page sends is checked by a test in the repository that runs its script, rather than asserted here. To offer the Spanish edition, the first page you open reads your browser's language list and where you came from; it uses both on your device and keeps neither. The count is the kind of anonymous audience measurement that needs no consent; in the UK we rely on the exception for statistical purposes in regulation 6 of the Privacy and Electronic Communications Regulations. You can object at any time, without telling us, by turning on Global Privacy Control or Do Not Track: then nothing is sent.

This policy covers three places: this website, the account portal where you sign in, start a trial and pay, and Nexus Studio once it is installed. The controller of the personal data described here is Verdict System LLC, a Wyoming limited liability company ("we"), reachable at [email protected].

What the product sends us

Nexus Studio runs on your own machines, and we never receive your tests or evidence unless you send them to us yourself. They go elsewhere only to services you connect yourself, as described below. One connection, zero test data: a license check that sends a machine hash, a nonce and a token; your license key only once, at activation. Exactly this, and nothing else:

We never receive your test data. We keep your email, billing status and license records.

Jira, Slack, Telegram or an AI provider, if you configure them, talk to those services straight from your machine, never through us. They are your providers, not ours.

What the portal and the license check keep

All of it lives in one database. Each row below is one of its tables, named as it is in our code, so this list can be checked against the schema. "Purged" means a scheduled job deletes it.

DataWhyLegal basisKept
Account accounts
Email address and whether it is verified; your Google or GitHub account ID if you sign in with one of them; your Stripe customer ID once you pay; which version of the Terms you accepted and when; the checkout you have open, if any; an admin flag; when it was created and deleted.
Sign you in, run your account, tie it to your license and billing, and prove which Terms you accepted.ContractWhile the account exists. After you delete it, the email is replaced and the name and the Google and GitHub IDs erased; records of the Terms and renewal terms you accepted are kept until 3 years after you accepted them or 1 year after your subscription ended, whichever is later, because subscription law requires it; the rest is purged 24 months later.
Sessions sessions
A SHA-256 hash of your session token (the token itself lives only in your cookie), its account, and when it started, ends or was signed out.
Keep you signed in to the portal.ContractA session lasts 30 days; its record is purged 30 days after it ends. Erased when you delete the account.
Sign-in links magic_links
The email address a link was sent to, a SHA-256 hash of its token, when it expires and when it was used.
Sign you in by email, and cap how many live links one address can have.ContractA link works once, for 15 minutes; its record is purged 1 day after it expires.
License licenses
Plan, billing interval, the organization name, if you give one, machines allowed, status (active, past due, canceled, revoked or expired) and why it was revoked (refund, dispute or an administrator); Stripe subscription ID; the date it is paid until, the payment grace date, a scheduled end; the first activation; the time of the last payment event applied; when we sent the trial and renewal reminders.
Know whether your license is valid, until when, and what you pay for.Contract; legal obligation for billing recordsWhile the account exists. After you delete it, kept with nothing that names you, then purged 24 months later.
Machines activations
For each activated machine: its machine hash, a SHA-256 hash of its activation token, and when it was activated, last renewed and deactivated.
Enforce the machine limit, renew each machine's license and list your machines so you can deactivate one.ContractWhile the account exists. Erased when you delete it.
License key api_keys
The key's public prefix and a SHA-256 hash of the key, never the key itself; when it was created and replaced.
Check the key you paste into the Studio.ContractWhile the account exists. A replaced key stops working at once. Erased when you delete the account.
Trial machines trial_machines
The machine hash of each machine that started a trial, which trial, and when.
Allow one free trial per machine.Legitimate interests: preventing repeated trialsWhile the account exists, then purged 24 months after you delete it.
Payment events stripe_events
The ID and type of each notification Stripe sends us, and when it arrived and was applied.
Apply each payment event once, in order.ContractHolds no personal data; kept so an event is never applied twice.
Email queue email_outbox
Which email went out (a sign-in link, a trial or renewal reminder, a receipt of a change to your plan or license, a security notice), whether and when it was sent, the attempts, and the dates or plan the message mentions. A sign-in row holds a SHA-256 hash of the address; a queued row holds your account ID instead. Never the address itself.
Send the emails the service needs, once each, and troubleshoot delivery.Contract; legitimate interestsWhile the account exists. Erased when you delete it, except the notice of the deletion, purged 24 months later.
Audit log audit_log
Account events, append-only: the Terms you accepted, a key regenerated, a payment that could not be applied or was refunded automatically, a license revoked or restored and why, the account deleted.
Show what happened to an account and its billing if it is ever disputed.Legitimate interestsWhile the account exists. After you delete it, records of the Terms and renewal terms you accepted are kept until 3 years after you accepted them or 1 year after your subscription ended, whichever is later, to prove that consent; everything else is purged 24 months after deletion. The database refuses to edit it.
Founding applications founding_applications
What you send with the Founding Customer form: your name, work email, company, role, team size, company website and what you would test; whether it was approved or rejected and when; the Founding code we issued and the account that used it.
Review your application, check in public registers, such as the EU VIES service, that the company and its tax ID exist, issue and honor the Founding discount, and send the program's feedback rounds.Steps you asked for before a contract, then contractA pending, rejected, or approved-but-never-used application is deleted 6 months after the application or the decision, from our database and from our mailbox. An approved and used one is kept while its account exists. When you delete your account, your name, email, company, role, team size, website and use case are erased at once; the record of what you accepted is kept as long as subscription law requires, and nothing else.
Feedback feedback
The message and optional 1 to 5 rating you send from the portal, your account ID and the time.
Read your feedback and improve the product.Legitimate interestsWhile the account exists. Erased when you delete it.
Website visits web_events
A page view or a download on this website: the page path, the host name of the site that linked to it, the time. No IP address, cookie or identifier.
Count visits and downloads.Legitimate interests; it identifies no onePurged after 13 months.

Contract means we need it to give you what you signed up for (GDPR article 6(1)(b)); legitimate interests, that we need it to run the service fairly and it does not override your rights (article 6(1)(f)); legal obligation, that tax or accounting law requires it (article 6(1)(c)).

Invoices, receipts, your card and your billing address are held by Stripe, not by us, and Stripe keeps invoices and payments for as long as accounting law requires, also after you delete your account.

Cookies, and why there is no cookie banner

This website sets none. The account portal sets only what signing in needs, and nothing for analytics or advertising:

All three are strictly necessary for a service you asked for, so there is nothing to accept or reject. The portal uses no local storage.

Who processes it with us

Five providers receive this data. Cloudflare and Resend process it only on our instructions. Stripe processes it for us and also, as a controller in its own right, for fraud prevention and its legal duties. Google and GitHub are not our processors: if you sign in with them, they handle your account with them under their own terms and send us only what is listed here. The Subprocessors page says what each one receives.

We do not sell or share your personal information, in the meaning the CCPA gives those words, and we use none of it for advertising. We are a United States company, and our database is held by Cloudflare in Eastern North America, in the United States. People who work for us may access it from other countries. Our providers process it in the United States, and Cloudflare also handles requests at the point of its network nearest to you. Where a provider receives personal data from the EU, the EEA or the UK, we rely on its certification under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. Data Privacy Framework where it has one, and otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Write to [email protected] for a copy of the safeguard that applies.

Your rights, and how to use them

Depending on where you live, you can ask to access, correct, delete or take a copy of the personal data we hold about you, and object to or restrict how we use it. Most of it you can do yourself:

Your right to object. Where the table above names legitimate interests, you can object at any time, on grounds relating to your situation, by writing to [email protected]. We then stop, unless we show compelling legitimate grounds that override your interests, or need the data to establish, exercise or defend legal claims.

You must give us an email address to have an account, and we need the records the table marks Contract to provide the service; without them we cannot provide it. We make no decision about you based solely on automated processing that has legal or similarly significant effects: a person decides every Founding application and every license revocation by an administrator.

Complaints. You can complain to us at [email protected]. We acknowledge a complaint within 30 days and answer it without undue delay. In the EU and the EEA you can also complain to the data protection authority where you live, work or think the problem happened, and in the UK to the Information Commissioner's Office at ico.org.uk.

California and other US states

Several US states give their residents privacy rights. Today we do not meet the size thresholds of the California Consumer Privacy Act or of the other state privacy laws, but we honor the rights below for everyone, wherever they live.

In the last 12 months we collected these categories of personal information: identifiers (your name, email address, account ID, and your Google or GitHub account ID if you sign in with one); commercial information (your plan, billing status and license records); professional information you give us in a Founding Customer application (your company, role, team size, company website and use case); and, for a short time while a request is handled, your IP address, which Cloudflare processes to protect the service and which may appear in our hosting providers' request logs, kept for at most 7 days. We collected it from you, from Stripe, and from Google or GitHub when you sign in with them, for the purposes and periods in the table above. We do not sell or share personal information, as the CCPA defines those words, and we use none of it for advertising. The only sensitive personal information we hold is what signs you in (hashes of your session token and license key), and we use it only to sign you in and protect your account.

You can ask to know, access, correct, delete or take a copy of your personal information, yourself or through an authorized agent, and we will not treat you differently for asking. We answer within one month, the same deadline as the section above. If we decline a request, you can appeal by replying to our answer, and we answer the appeal within 45 days. Wherever you live, you can also complain to your data protection authority.

Colombia (Ley 1581 de 2012)

If you are in Colombia, this section is our política de tratamiento under Ley 1581 de 2012 and Decreto 1377 de 2013 (compiled in Decreto 1074 de 2015).

Children

Nexus Studio is a tool for businesses and professionals. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, write to us and we will delete it.

If there is a security incident

If we learn that personal data we hold has been accessed, disclosed, changed or lost without authorization, we contain it first, then assess the risk to the people it concerns. Where the law requires it, we notify the competent data protection authorities, within 72 hours of becoming aware where the GDPR or the UK GDPR applies, and within 15 business days to the Superintendencia de Industria y Comercio in Colombia. We tell affected account holders by email without undue delay: what happened, what data was involved, what we have done and what you can do. Your tests and evidence stay on your machines, so an incident on our side can expose only what you have emailed us.

If you email us

We receive what you wrote and your address, and use it to answer you; it is kept in our mailbox, held in Gmail, for up to 24 months after the conversation ends, then deleted. We do not add you to a mailing list or pass it to anyone except that mailbox provider; ask us to delete the thread and we delete it.

Changes

When this policy changes, the date at the top changes with it. If a change affects account holders, we email them before it applies.