Privacy Policy
Last updated: July 26, 2026 · Effective date: July 26, 2026
Modrena UG (“Modrena,” “Testral,” “we,” “us,” or “our”) is committed to protecting the privacy of individuals who interact with us. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit https://testral.dev (including subdomains) and related digital platforms (the “Website”), use our desktop application and hosted Services, or otherwise communicate with us.
Controller: Modrena UG, Bismarckstraße 14A, 76275 Ettlingen, Baden-Württemberg, Germany. Contact: hello@testral.dev.
By using our Services or providing personal data, you acknowledge this Policy. Where consent is required by law, we will obtain it. Our Terms of Service also apply. This Policy is intended to meet requirements under the EU General Data Protection Regulation (GDPR) and German data protection law (including the BDSG).
Roles: controller and processor
For account data, billing metadata, Website usage, and waitlist emails, Modrena is typically the controller.
For Customer Content you upload or generate while using the product (tests, app builds, screenshots, device streams, logs, reports) that may contain personal data of your end users or other third parties, you are the controller and Modrena acts as your processor, processing that data on your documented instructions to provide the Services. You are responsible for having a lawful basis and any required notices or consents for that data. Enterprise customers may request a Data Processing Agreement (DPA).
Information We Collect
We may collect personal data that identifies you or relates to you, including:
Contact and account information
- Name
- Email address
- Organization / team details
- Authentication identifiers (e.g. from Google or GitHub sign-in)
- Waitlist or closed-beta signup information (email and signup source)
Service and product data
- Projects, tests, plans, settings, and related metadata
- App builds or identifiers you upload or configure for testing
- Device connection metadata (e.g. device type, OS, connection status)
- Screenshots, logs, step reports, and other artifacts generated during runs
- Usage metrics related to executed steps, plans, and features
Technical data
- IP address (e.g. in server or access logs)
- Browser type and operating system
- Approximate usage patterns when you use the Website or Services
- Diagnostic and crash data from the desktop app (where enabled, e.g. via error monitoring)
Payment information
Payments are processed by Stripe. We typically receive billing metadata (plan, status, limited payment method details such as last four digits and expiry) but do not store full card numbers on our servers.
Other information
- Information you voluntarily provide via email, forms, or support
- Recruitment information if you apply for a role with us
How We Collect It
Information you provide directly
- Creating an account or joining the waitlist
- Using the desktop app and Services
- Contacting us or submitting forms on the Website
- Entering into a contractual relationship with us
Information collected automatically
When you access the Website or Services, we may automatically collect IP address, browser/OS information, and operational logs needed to provide and secure the Services. The desktop app may send operational and diagnostic data (including error reports where enabled).
Information from third parties
We may receive information from identity providers (Google, GitHub), payment processors (Stripe), cloud device or infrastructure providers, AI inference providers, and error-monitoring tools, as permitted by applicable law.
How We Use Your Information
We process personal data on the following legal bases (GDPR Art. 6):
- Contract (Art. 6(1)(b)) — providing the Services you requested, including accounts and billing
- Legitimate interests (Art. 6(1)(f)) — securing and improving the Services, preventing abuse, responding to inquiries; for B2B contacts, limited product communications where allowed
- Consent (Art. 6(1)(a)) — where required (e.g. waitlist marketing beyond beta access emails, non-essential cookies if we add them)
- Legal obligations (Art. 6(1)(c)) — tax, accounting, and other mandatory retention
We use information to:
- Provide and operate the Website and Services (including AI-assisted testing features for your account)
- Create and manage accounts, organizations, and waitlist invitations
- Process subscriptions, step usage, and payments
- Generate reports and, if you enable sharing, make report links available to recipients
- Respond to inquiries and provide support
- Send transactional and beta-access emails; send promotional email only where permitted (you may unsubscribe)
- Monitor security, prevent fraud, and enforce our Terms
- Comply with law
AI processing. To run AI QA features, we may send relevant Customer Content (such as UI context, screenshots, or step text) to subprocessors that provide model inference, solely to provide those features for your account (locate UI, verify outcomes, explore apps, assist authoring). We do not sell your personal data and do not use Customer Content to train general-purpose foundation models for unrelated customers. Aggregated or anonymized operational metrics may be used to operate and improve the Services.
Shareable reports. If you publish a report link, the report and related artifacts may be viewable by anyone with the link, without signing in. Treat links as confidential and revoke them when no longer needed.
Sharing Your Information
We do not sell or rent your personal data. We may share information with:
- Service providers / subprocessors who help us operate the Website and Services under appropriate data-processing terms (see list below)
- Team members and invitees you authorize within an organization, or recipients of shareable report links you create
- Legal authorities when required by law or to protect our rights, users, or the public
- Business transfers in connection with a merger, acquisition, or asset sale, subject to appropriate protections
Current subprocessors (categories)
- Hosting & storage: Amazon Web Services (e.g. compute, object storage)
- Email delivery: Amazon SES
- Payments: Stripe
- AI inference: model providers accessed via our AI gateway (e.g. OpenRouter and underlying model hosts)
- Error monitoring: Sentry (where enabled)
- Identity: Google and GitHub when you choose those sign-in methods
The specific providers may change as we evolve the stack; material changes will be reflected in updates to this Policy.
Cookies and Local Storage
The Website currently uses browser local storage for essential preferences (for example, light/dark theme). We do not currently set non-essential advertising or analytics cookies on the marketing site. If we introduce non-essential cookies or similar trackers in the future, we will update this Policy and obtain consent where required. Server logs and the desktop app may still process technical data as described above.
Data Security
We implement reasonable technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure; we encourage care when sharing information online.
International Transfers
We are established in Germany. Some subprocessors process data in the United States or other countries outside the EEA. Where required, we use appropriate safeguards for cross-border transfers (such as EU Standard Contractual Clauses) and additional measures as appropriate.
Retention
We retain personal data only as long as necessary for the purposes described in this Policy, including:
- Account and Service data for the life of your account, plus a limited period after closure (typically up to ninety (90) days) for export, backup rotation, or dispute handling, unless longer retention is required by law
- Soft-deleted tests and related artifacts may be retained briefly (on the order of days) before permanent purge, consistent with product behavior
- Billing and tax records for statutory retention periods under German/EU law
- Waitlist emails until we invite you, you ask us to remove you, or we close the waitlist program
Your Rights
Under the GDPR and applicable German law, you may have the right to access, rectify, erase, or restrict processing of your personal data; to data portability; to object to certain processing (including direct marketing); and to withdraw consent where processing is based on consent. Withdrawal does not affect prior lawful processing. You also have the right to lodge a complaint with a supervisory authority — for Modrena UG this is typically the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), without prejudice to any other remedy.
To exercise these rights, contact hello@testral.dev. We will respond without undue delay and within one month of receipt (extendable by two further months for complex requests, as permitted by Art. 12 GDPR). We may need to verify your identity before responding.
Children
The Services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe we have, contact us and we will take appropriate steps to delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Material changes may be communicated by additional notice (for example, email or in-product) where appropriate.
Contact Us
Modrena UG (controller for Testral)
Bismarckstraße 14A
76275 Ettlingen, Baden-Württemberg, Germany
Email: hello@testral.dev
Website: https://testral.dev