CollaudIA

CollaudIA

Privacy notice

Last updated: 25 August 2026

1. Data controller

The data controller is Gianfranco Coratella, an individual based in Italy.

For personal data and privacy requests: privacycollaudia@gmail.com. For service support: infocollaudia@gmail.com.

2. Local processing by design

CollaudIA is a desktop application designed to test web applications locally on the user’s computer.

The contents of tested applications, screenshots, reports, results and test history are not sent to or stored on servers operated by CollaudIA. The browser automation and testing engine runs on the user’s device.

To allow artificial intelligence to interpret a page and decide which actions to perform, CollaudIA sends the visible textual and structural information from the page, together with the results of performed actions, directly to the AI provider selected by the user. This communication uses the API key supplied by the user and does not pass through servers operated by CollaudIA.

Screenshots are generated locally as evidence of identified issues and remain on the user’s device unless the user exports or shares them.

3. Account and subscription data

The following information may be processed to create and manage an account:

  • email address;
  • technical account identifier;
  • profile name and image when supplied by the selected authentication service;
  • technical information required to maintain a secure session;
  • subscription status and technical identifiers connected to the payment.

This information is used only to authenticate the user, provide access to the service, verify the subscription, provide support and protect the service against unlawful or unauthorised use.

4. Authentication

Users may authenticate by email or, when available, through Google or GitHub.

Authentication and the technical management of accounts are provided through Supabase. When Google or GitHub is selected, that provider processes the information required to verify the user’s identity and authorise access under its own privacy notice.

CollaudIA requests only the basic information required for sign-in. It does not request access to files, repositories, contacts, messages or other content held in Google or GitHub accounts.

5. Payments

Payments and subscription management are provided through Stripe.

CollaudIA does not receive or store card numbers, security codes or complete payment credentials. Stripe processes this information within its own systems and may process additional information to execute payments, prevent fraud, comply with tax requirements and meet other legal obligations.

CollaudIA retains only the technical identifiers and subscription status needed to determine whether the user is entitled to access the product.

6. Artificial intelligence providers

To use the testing features, the user configures their own API key for Anthropic, OpenAI or another compatible service selected by the user.

The API key is stored in the operating system’s secure keychain and is not sent to servers operated by CollaudIA. AI requests are sent directly from the user’s device to the selected provider.

The AI provider may receive:

  • visible text and structure from the tested page;
  • descriptions of performed actions and their results;
  • questions or instructions entered by the user;
  • information required to produce the test report.

Processing by the AI provider is governed by the agreement, settings and privacy notice applicable to the user’s API account. If the user configures an alternative API endpoint, the user is responsible for selecting that provider.

7. User responsibilities for tested projects

Users must use CollaudIA only with applications and data they are authorised to test. Before starting a test, users must assess whether pages may display personal, confidential or third-party information and whether communicating that information to the selected AI provider is authorised.

Test environments and fictitious or anonymised data are recommended. Real payment information must not be entered. CollaudIA includes technical controls intended to prevent payment details from being entered or payments from being confirmed, but these controls do not replace the user’s responsibility for selecting appropriate environments and test data.

8. Information stored locally

The following information may be stored on the user’s device:

  • AI provider configuration and the selected spending limit;
  • the API key in the operating system’s secure keychain;
  • application preferences;
  • a summary of test history;
  • reports and screenshots generated or exported by the user.

This information is not automatically synchronised with servers operated by CollaudIA. Its protection, retention, export and deletion depend on the user’s device and actions.

9. External service providers

Each provider applies its own security measures and processes information according to its role, terms and privacy notice. CollaudIA selects and configures the services required for the product, limits the information transmitted and does not use these providers to sell personal information or for behavioural advertising.

  • Supabase: accounts, authentication, sessions and subscription status;
  • Stripe: payments, billing and subscription management;
  • Google and GitHub: authentication, only when selected by the user;
  • Vercel: website hosting and operation;
  • the AI provider selected by the user: processing required to perform tests.

10. Legal bases and purposes

Personal information is processed:

  • to perform the contract and provide the account, access and subscription;
  • to comply with legal, tax and accounting obligations;
  • for the legitimate interest of protecting the service and preventing abuse;
  • based on the user’s choice when an optional authentication or AI provider is used.

CollaudIA does not use personal information for advertising profiling and does not sell personal information.

11. Retention

Account and subscription information is retained for as long as necessary to provide the service and manage the contractual relationship. After an account is closed, information is deleted or anonymised unless it must be retained for legal, tax, accounting or anti-fraud obligations or for the establishment, exercise or defence of legal claims.

Retention periods applied independently by external providers are described in their respective privacy notices.

12. International transfers

Some providers may process information outside the European Economic Area. Where applicable, this processing is governed by the safeguards required by the GDPR and the mechanisms adopted by the relevant provider, such as adequacy decisions or standard contractual clauses.

13. Security

CollaudIA applies measures appropriate to the nature of the service, including local execution of the testing engine, storage of the API key in the operating system’s secure keychain, minimisation of remotely stored information and the use of specialised providers.

No system can be considered entirely free from risk. Any incident will be managed according to the respective responsibilities and obligations applicable to CollaudIA and the providers involved.

14. Cookies and necessary technologies

The website and application use only cookies or equivalent technologies required for authentication, security, session management and operation of the service. CollaudIA currently does not use behavioural advertising or behavioural analytics tools.

15. Data subject rights

Where provided by the GDPR, users may request access, rectification, erasure, restriction, portability or objection to the processing of their personal information. They may also withdraw consent where processing relies on consent, without affecting processing already carried out. Requests may be sent to privacycollaudia@gmail.com. Users may also lodge a complaint with the Italian Data Protection Authority or the competent authority in their country.

16. Changes to this notice

This notice may be updated to reflect changes to the service, providers or applicable law. The published version will always show the date of the latest update.

Back to the home page