Data retention and deletion policy
TesterAgent keeps your reports while your account exists, deletes screenshots 90 days after an audit, deletes uploaded APKs right after the analysis and logged-in sessions when the audit ends. Deleting your account removes everything at once, except backups, which expire on their own schedule.
Retention schedule
| Data | Kept |
|---|---|
| Account: email, name, password hash (scrypt — never the password), report language, accepted Terms version and date, how you first found us | Until you delete your account |
| Websites you add: address, test settings, optional login-page addresses, the login steps a checkpoint learned (step names and page paths — never what you typed), your “I own this website” confirmation | Until you remove the site or delete your account |
| Audit reports: scores, findings, HTML / Markdown / JSON report, test cases | In your history until you remove the site or delete your account (app reports: until you delete your account) |
| Screenshots of tested pages and app screens, including logged-in areas (stored on Cloudinary under random addresses) | Deleted automatically 90 days after the audit started (free check: 7 days) |
| Raw check files on our server (per-check results, audit log) | Deleted 90 days after the audit ended |
| Screenshot upload records (which image, size, upload status — not the image) | 365 days after the upload; deleted with your account |
| Uploaded APK file | Deleted right after the analysis (or when the audit is cancelled) |
| The app installed on our test phone, with its data | Deleted when the audit ends |
| Logged-in browser session of your site (cookies and storage after you log in) | Deleted when the audit ends — we never see or store your password or one-time codes |
| Free check without an account: the report | 7 days |
| Free check: one-way keyed hash of your IP address | 30 days |
| Sign-in session (random token, stored only as a hash) | 30 days, or until you sign out |
| Email links (confirm email, reset password) | Until used, or 48 hours / 2 hours |
| Monthly usage counters | Until you delete your account |
| Billing status: plan, status, renewal dates, provider customer and subscription ids, card brand and last 4 digits | Until you delete your account. Invoices and payment records are kept by Lemon Squeezy (or PayPal) under their own policies |
| Payment notifications (webhooks) from Lemon Squeezy / PayPal — contain your billing name and email | 90 days |
| Misuse reports and opt-out requests sent with our form (your email, the domain, your message) | 365 days |
| Blocked-domain list (domain, reason) | Until the block is removed |
| Sign-ups and free checks counted per traffic channel (no personal data) | 400 days |
Automatic deletion jobs
- Every few minutes the worker deletes screenshots on Cloudinary whose time is up (90 days after the audit started; free checks 7 days), or whose audit, report or site was deleted.
- Every hour the worker deletes raw check files older than 90 days, leftover folders and abandoned APK uploads.
- Database expiry (MongoDB TTL indexes) removes free-check reports, IP hashes, sign-in sessions, email links, payment notifications, misuse reports and upload records when their time is up.
- Logged-in sessions and the app on our test phone are deleted in the same step that ends the audit — including failed or cancelled audits — and leftovers of a crashed worker are swept every minute.
- Removing a site deletes its audits and reports at once and its screenshots within minutes.
When you delete your account
Account → Delete my account (after cancelling a running subscription) immediately deletes your account, sites, audits, reports, usage counters, billing status, sessions and email links; deletes your screenshots on Cloudinary (if Cloudinary cannot be reached, the worker retries and deletes them within its next runs); deletes your upload history; and removes local files of your audits. Invoices stay with Lemon Squeezy as the seller, as tax law requires.
Backups and logs
- Database backups: [[OWNER: Atlas backup retention, e.g. daily snapshots kept 7 days (BACKUP_RETENTION)]]. Deleted data disappears from backups when they expire.
- Server logs: [[OWNER: server log retention, e.g. 14 days with Docker log rotation (LOG_RETENTION)]].
Exceptions
We may keep specific data longer when the law requires it or to handle a legal claim or an abuse investigation, and only for that purpose.