Privacy Policy
Last updated: April 8, 2026
1. Introduction
DeFlaky ("we", "our", "us") operates the deflaky.com website and the DeFlaky CLI tool. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
2. Information We Collect
Account Information: When you sign in via GitHub or Google OAuth, we receive your name, email address, and profile picture. We do not receive or store your password.
Test Results Data: When you use the DeFlaky CLI with the --push flag, we receive test names, file paths, pass/fail statuses, durations, and run metadata. We do not receive your source code.
AI Analysis (BYOK): When you use the AI root cause analysis feature, your AI API keys are stored locally in your browser only. We proxy analysis requests but do not store your API keys on our servers.
Usage Data: We collect standard web analytics (page views, referrer, device type) to improve our service. We do not use third-party tracking scripts.
3. How We Use Your Information
- To provide and maintain the DeFlaky dashboard and API
- To authenticate your identity and secure your account
- To display test results and flakiness metrics in your dashboard
- To send service-related notifications (if enabled)
- To improve and optimize our services
4. Data Storage and Security
Your data is stored on secure cloud infrastructure (Neon PostgreSQL on AWS). All data is encrypted in transit via TLS/HTTPS. API tokens are generated per-project and can be revoked at any time. We implement industry-standard security practices including parameterized database queries and input validation.
5. Data Sharing
We do not sell, trade, or rent your personal information. We do not share your test results data with third parties. We may share anonymized, aggregated statistics (e.g., "average FlakeScore across all users") for marketing or research purposes.
6. Data Retention
Test results data is retained for 90 days on the free plan. You may request deletion of your account and all associated data at any time by contacting us. Upon account deletion, all data is permanently removed within 30 days.
7. Your Rights
- Access: You can access all your test data via the dashboard or API
- Deletion: You can request complete deletion of your account and data
- Export: You can export your test results via the API
- Correction: You can update your profile information through your OAuth provider
8. Cookies
We use essential cookies for authentication session management only. We do not use advertising or tracking cookies.
9. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy, contact us at pramod@thetestingacademy.com.