Privacy policy
Last updated 30 Sept, 2026.
1. Overview
This Privacy Policy explains how QualityLabs Inc., a Delaware corporation ("Quality", "we", "us", or "our"), collects, uses, shares, and protects personal information when you visit qualities.work and its subdomains (the "Site"), or use the Quality browser extension and web dashboard (together with the Site, the "Service").
Quality is a website feedback and QA tool: it lets teams leave comments anchored to elements on a web page, capture screenshots, and record and replay browsing sessions. By using the Service, you acknowledge the practices described in this policy.
2. Our role: controller and processor
Quality is the controller of the personal information we collect to run our business — account details, billing records, and communications with you.
When our customers use the Service, the comments, screenshots, session recordings, and other material they capture ("Customer Content") is processed on their behalf and under their instructions. For Customer Content, the customer that owns the workspace is the controller and Quality is its processor. If you have questions about how an organization uses Quality, or want to exercise your rights over Customer Content, please contact that organization directly; we will assist them in responding. Our Data Processing Agreement sets out the terms of that processing.
3. Information we collect
Information you provide to us:
- Account information: Your name, email address, and profile photo, collected when you sign up with an email code or with Google sign-in.
- Workspace information: The workspaces and projects you create or join, your role in them, and the teammates you invite by email.
- Billing information: For paid plans, billing contact details and plan history. Card payments are handled by our payment processor; we do not store full card numbers.
- Communications: What you send us when you contact support, request a demo, or respond to a survey.
Information created when you use the Service:
- Feedback content: Comments, threads, replies, attachments, and screenshots you choose to create, along with the page URL and the element you anchored them to.
- Session recordings: A replay of the page you are on: its structure and changes, your interactions, and the page's network and console activity. While you have a project active, the extension keeps a short rolling buffer of this activity in your browser's memory on that project's website only. The buffer is uploaded when you create feedback or save a screen recording, and is discarded otherwise.
- Technical and usage data: IP address, browser and extension version, device type, and logs of requests to our servers, used to operate, secure, and debug the Service.
Information from third parties: if you sign in with Google, we receive your name, email address, and profile photo from Google. If you connect Jira, Linear, or Slack, we receive the account and workspace identifiers needed to send feedback there, and an access token that we store encrypted.
4. What we do not collect
- We do not collect your general browsing history. The extension only runs on the website of the project you have activated, and nothing leaves your browser until you create feedback or save a recording.
- Password fields are masked in session recordings before they leave your browser, and the values of email and hidden fields are left out of recorded actions.
- We do not sell or rent personal information, share it for cross-context behavioral advertising, or use Customer Content to train generalized AI models.
5. How we use information
- To provide the Service: authenticating you, storing and syncing feedback, replaying recordings, and sharing them with the members of your workspace.
- To send feedback to the integrations you connect, and to send the notifications and invitations you or your teammates trigger.
- To process payments and manage subscriptions.
- To send service messages such as sign-in codes, security alerts, and changes to our terms.
- To maintain, secure, and improve the Service, including detecting abuse and fixing errors.
- To comply with legal obligations and enforce our Terms of Service.
6. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we process personal information as a controller on these bases: performance of our contract with you; our legitimate interests in operating, securing, and improving the Service; compliance with legal obligations; and your consent, where we ask for it. You may withdraw consent at any time without affecting processing that took place before.
7. Browser extension permissions
The extension requests only the permissions it needs, and uses them only to provide its user-facing features:
- activeTab and host access: To show the feedback toolbar on the website of the project you have activated, whichever site you are testing.
- storage: To keep your session and active project on your device so you stay signed in across pages and tabs.
- tabs: To connect each tab to the right project and coordinate the toolbar with the extension's background worker.
Data collected through the extension is used only to provide the Service. It is not transferred to third parties except as described in this policy, and is never used for advertising or to determine creditworthiness.
8. How we share information
- Within your workspace: Feedback and recordings are visible to the workspace and project members, and guests, that the workspace owner permits.
- Service providers: Vendors that host our infrastructure, store media such as screenshots and recordings, deliver email, and process payments, bound by contract to use the data only to provide their services to us.
- Integrations you connect: Jira, Linear, Slack, and any integration added later, which receive the feedback you choose to send and handle it under their own privacy policies.
- Business transfers: A successor entity, as part of a merger, acquisition, financing, or sale of assets, subject to this policy's commitments.
- Legal requirements: Where required by law or valid legal process, or to protect the rights, property, or safety of Quality, our users, or the public.
9. International transfers
Quality is based in the United States, and we and our service providers may process information in the United States and other countries. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
10. Data retention
We keep account information while your account is active. Customer Content stays until it is deleted by a workspace member or the workspace is closed. After an account or workspace is deleted, we remove or de-identify the related data within 30 days, apart from residual copies in backups, which expire on their normal cycle, and records we must keep for legal, tax, or security reasons.
11. Security
We protect information with safeguards appropriate to its sensitivity: encryption in transit, encryption of integration credentials at rest, revocable sign-in sessions, and access limited to the workspace and project each person belongs to. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you as required by law.
12. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your profile and delete feedback directly in the Service. For other requests, email us; we will verify your identity and respond within the time the law requires. We will not discriminate against you for exercising these rights. If you are in the EEA or UK, you may also complain to your local data protection authority.
13. U.S. state privacy rights
Residents of California and other states with comprehensive privacy laws have the right to know what personal information we collect, use, and disclose; to request deletion or correction; and to opt out of its sale or sharing. We do not sell or share personal information as those laws define it, and we do not use or disclose sensitive personal information for purposes that would require a right to limit. You may make a request yourself or through an authorized agent by emailing us.
14. Cookies and local storage
We use only the cookies and browser storage needed to keep you signed in and remember your preferences. We do not use advertising or cross-site tracking cookies. Blocking storage in your browser may stop you from signing in.
15. Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect their personal information; if you believe a child has provided some to us, contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or in the Service before they take effect, and update the "Last updated" date above.
17. Contact us
QualityLabs Inc. is a Delaware corporation. For questions about this policy or to exercise your rights, contact us at [email protected]. Our Terms of Service describe the rules for using the Service.