QA Scribe Cloud
Legal

Privacy Policy

How QA Scribe handles account, capture, report, and Google Drive data.

Effective August 18, 2026

What this policy covers

QA Scribe is an invite-only service that turns a narrated browser QA session into a human-reviewed report. This policy explains the information QA Scribe handles when you use the hosted website, Chrome extension, private and published report tools, remote MCP access, and optional Google Drive delivery.

Information QA Scribe handles

Account and authentication data

QA Scribe stores your invited email address, optional display name and job role, notification and appearance preferences, authentication and extension-pairing records, and security/audit metadata. Authentication credentials and single-use tokens are stored as hashes or encrypted values where applicable.

If you choose Google sign-in, Google provides a verified email address, display name, profile image, and stable Google account identifier. QA Scribe uses the fresh verified email to enforce the invitation policy. For a new account, the name and image are imported once; when linking an existing verified QA Scribe account, only blank local name or image fields are filled. Later Google sign-ins do not overwrite local profile edits.

The durable Google sign-in link contains only the provider name, Google's stable account identifier, your QA Scribe user identifier, and creation/update timestamps. QA Scribe discards and does not retain Google sign-in access tokens, refresh tokens, ID tokens, token expirations, or granted scopes. Google Drive is a separate, optional connection described below and uses separate credentials and storage controls.

Capture, review, and report data

A recording can contain the selected browser window, microphone narration, captured page URLs and app context, approved diagnostic evidence, transcripts, issue analysis, reviewer edits, and selected screenshots. Capture remains on your device until a verified encrypted upload is accepted. Recordings and artifacts are encrypted at rest with per-session keys.

Operational data

QA Scribe records content-free operational details such as request and job identifiers, timestamps, lifecycle state, byte counts, retry and error classes, and security events. Application logs and metrics exclude report text, transcripts, screenshots, recordings, provider payloads, authentication secrets, storage object keys that bypass authorization, and Google Drive file identifiers or links.

How information is used

  • Authenticate invited users, pair authorized extensions, and enforce owner-only access.
  • Accept encrypted uploads and perform the transcription, analysis, review, report, ZIP, and MCP actions you request.
  • Send transactional sign-in, invitation, security, processing, and retention messages according to your settings.
  • Operate, secure, troubleshoot, and improve the service using redacted operational records.
  • Create a Google Doc only after you explicitly confirm a Google Drive delivery.

Service providers and disclosures

QA Scribe uses Railway for application hosting, PostgreSQL, and encrypted object storage; OpenAI for transcription and, when selected by the administrator, issue analysis; OpenRouter for issue analysis when selected; and Resend for transactional email. These providers receive only the information needed to perform the requested service.

QA Scribe does not sell personal information or captured content, and does not use it for advertising. Information may also be disclosed when required by law or when necessary to investigate abuse or protect the service. Administrators can access account and operational metadata but do not receive access to another user's recordings, transcripts, screenshots, reports, or files.

An owner may separately authorize read-only MCP access to submitted reports and approved evidence. That grant can be revoked at any time. Raw recordings, provider payloads, noncanonical generations, and unselected evidence are not available through MCP.

Published reports

Reports are private by default. If you choose Make public & copy link, anyone who has that report's existing QA Scribe URL can read the exact current canonical report without signing in.

A published report contains the submitted report text, captured URLs included in that text, reviewer-attached evidence, and only the screenshots selected in the canonical revision. It does not expose recordings, audio, transcripts, raw artifacts, ZIP or Word downloads, Google Drive files, storage addresses, provider payloads, or owner account metadata.

Making a report private stops anonymous access at the same stable URL. Publishing it again restores anonymous access at that URL. Revocation cannot withdraw copies that another person already viewed or saved. Returning a report to review automatically makes the existing publication private, and a replacement generation starts private.

Publishing does not extend artifact retention. Anonymous access also ends when the report expires, is replaced or deleted, the owning account is revoked or deleted, or the session is no longer an active ready report. QA Scribe does not add viewer analytics, access history, or identity tracking to public reports.

An OAuth-authorized MCP client can fetch a currently published report only when given its complete QA Scribe report URL. Public MCP access provides the canonical Markdown, issue order, and selected screenshots; it does not list public reports or expose richer artifacts.

Google Drive

QA Scribe can connect one Google Drive account so you can explicitly create a new Google Doc from a submitted QA report. Connecting does not send any report automatically.

QA Scribe requests only the Google Drive drive.file permission. This lets the app create and manage files that it creates or that you explicitly open with the app; it does not grant broad access to browse your Drive. A requested delivery contains the exact submitted report revision and the screenshots you selected during review. The new document is private in My Drive unless you later change its sharing settings in Google Drive.

QA Scribe uses Google Drive account identity and import-capability information to identify the connected account and confirm that it can create the requested native Google Doc. OAuth access and refresh tokens are encrypted at rest. QA Scribe stores the connected account identity, the exact granted scope, connection status, and delivery receipts needed to resume or reconcile an upload. The source document is encrypted with the same per-session controls and retention policy as other QA Scribe artifacts.

Tokens, authorization data, upload-session addresses, Google file identifiers and links, report content, and screenshots are excluded from application logs and metrics. QA Scribe does not sell Google user data, use it for advertising, or permit humans to read it except when necessary for security, with your affirmative permission, or as required by law.

Disconnecting first prevents new deliveries, makes a bounded attempt to revoke Google access, and then erases QA Scribe's saved credentials even if Google is unavailable. Existing Google Docs are not changed or deleted. Delivered Docs are never synchronized, overwritten, or deleted by QA Scribe. Updated report revisions always create a separate document.

QA Scribe's use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Retention and deletion

  • Incomplete encrypted uploads expire after 24 hours.
  • Sessions awaiting human review are retained for up to seven days.
  • Completed canonical reports, approved evidence, ZIP files, and Drive source artifacts are retained for up to 30 days.
  • The recording remains reviewable for 24 hours after the latest submission and is then deleted.
  • Content-free audit events are retained for up to 90 days.

You can delete a session or request account deletion from QA Scribe. Account deletion revokes browser, extension, MCP, and connected-service access, cancels active work, and schedules owner-scoped stored data for verified deletion. Google Docs already delivered to your Drive remain under your control and are not deleted by QA Scribe.

Security and your choices

QA Scribe encrypts recordings and artifacts at rest, uses HTTPS in transit, scopes content access to the authenticated owner, and uses resumable, idempotent worker jobs for long-running processing. No security measure can eliminate every risk.

You can change profile, notification, and appearance settings; make a published report private; revoke extension and MCP access; disconnect Google Drive; delete individual sessions; or request account deletion from the Settings page.

Contact and policy changes

Questions or privacy requests can be sent to hello@qascribe.dev. If QA Scribe materially changes how Google user data is used, the policy will be updated and affected users will be asked to consent before the new use begins.

Privacy·Terms