REST&TEST
Back to home

Privacy Policy

Effective date: 1 May 2025  ·  Last updated: 1 May 2025

This Privacy Policy explains how REST&TEST ("we", "our", "us") collects, uses, and protects information about you when you use the REST&TEST desktop application ("App") and the restandtest.xyz website ("Website"). By using our services you agree to the practices described here.

1. Who we are

REST&TEST is operated as an independent software product. For privacy inquiries contact us at admin@restandtest.app.

2. Data we collect

Account data: When you create an account we collect a username and, optionally, an email address. Passwords are stored as salted PBKDF2-SHA256 hashes — we never store plaintext passwords.

Usage data: We log the number of test-generation and auto-repair operations performed under your account for billing and quota enforcement. We do not log the content of your API specifications or generated tests.

Payment data: Payments are processed by Stripe, Inc. We never receive or store your card number, CVV, or full payment details. Stripe may share limited billing identifiers (customer ID, subscription ID, last-4 digits) with us for account management.

Technical data: Our server logs may temporarily record your IP address, browser/app version, and request timestamps for security and abuse prevention purposes. These logs are retained for up to 30 days.

API specifications: When you use the AI generation or repair feature, your OpenAPI/Swagger specification is transmitted to our backend and forwarded to the AI model provider for processing. Specifications are not stored on our servers after the response is returned.

3. How we use your data

  • To provide, operate, and maintain the REST&TEST service
  • To authenticate your account and enforce subscription limits
  • To process payments and send billing-related communications
  • To detect and prevent fraud, abuse, and security incidents
  • To respond to support requests
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising.

4. Third-party services

Stripe — payment processing. Stripe's privacy policy applies to data you provide during checkout: stripe.com/privacy.

OpenAI — AI model provider used for test generation and repair. Your API specification is sent to OpenAI's API. OpenAI's usage policies and privacy practices apply: openai.com/policies/privacy-policy. By using our service you acknowledge that your API specification content is transmitted to OpenAI.

5. Data retention

Account data is retained for as long as your account is active. If you delete your account, your username, hashed password, and email are deleted within 30 days. Usage counters may be retained in anonymised form for up to 12 months for aggregate analytics.

Server logs are retained for 30 days and then automatically deleted.

6. Your rights (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your account and associated data
  • Restriction — request that we restrict processing in certain circumstances
  • Portability — request your data in a machine-readable format
  • Objection — object to processing based on our legitimate interests

To exercise any of these rights, email admin@restandtest.app. We will respond within 30 days.

7. Security

We implement reasonable technical and organisational measures to protect your data including HTTPS/TLS transport encryption, hashed password storage, rate limiting, and access controls. No system is perfectly secure — we cannot guarantee absolute security and we accept no liability for breaches beyond our reasonable control.

8. Cookies and local storage

The Website uses local storage (not traditional cookies) to persist your authentication token on your browser. No third-party tracking cookies are placed by us. The App stores an authentication token on your device in application data storage.

9. Children

REST&TEST is not directed at individuals under 16 years of age. We do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new effective date. Continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

For any privacy questions or requests: admin@restandtest.app

© 2025 REST&TEST. All rights reserved. Terms of Service  ·  Privacy Policy