Privacy Policy

Your code stays yours.

How TestCoverNet handles your data — in plain English first, then in full.

Effective 1 July 2026 · Last updated 1 July 2026

The short version

  • We do not store or retain your source code, and we never use it to train AI models.
  • To generate tests, your code is processed transiently — held only for as long as a job runs, then deleted.
  • To generate tests, your code is disclosed only to the sub-processors listed below, under confidentiality and no-training terms.
  • What we keep is metadata and test results — file names, test names, coverage numbers, pass/fail status — not the contents of your code.
  • We use read-only access to your repository. Generated tests are proposed as pull requests you review and merge yourself.

This summary is for convenience. The full policy below governs.

1. Who we are

TestCoverNet ("TestCoverNet", "we", "us", or "our") provides an automated test-generation service that connects to your source-code repository, plans tests, and proposes generated tests as pull requests. This policy explains what information we handle, how we use it, and the choices and rights you have. It applies to our website and to the TestCoverNet service.

2. Our commitment on your source code

Your source code is the most sensitive thing you trust us with, so we treat it separately from everything else and hold ourselves to the following commitments:

  • No persistent storage. We do not retain copies of your source code. Code is cloned into isolated, ephemeral working areas, used only to plan and generate tests, and then deleted when the job finishes — including on failure.
  • Transient processing only. During a job, portions of your source code, diffs, and existing tests are processed in memory and are sent to our third-party LLM inference provider solely to generate proposed tests.
  • No training. We do not use your source code, tests, or repository contents to train, fine-tune, or improve any AI model, and our inference provider is contractually bound not to train on your content.
  • Read-only access. We request read-only access to your repository. We do not modify your code directly; generated tests are delivered as pull requests that you review, change, and merge yourself.
  • Least-privilege credentials. Where supported, we use short-lived, repository-scoped access tokens, and we strip credentials before any code is handed to an isolated test sandbox.
  • Ownership. The tests we generate for you belong to you.

3. What we retain: metadata, not code

While we do not keep your source code, we do retain metadata and results needed to run the service, show you coverage over time, and bill you correctly. This includes:

  • Repository, branch, commit, and pull-request identifiers (for example SHAs and PR numbers).
  • File paths and file names within your repository.
  • Structural metadata about your code needed to plan tests: symbol/entry-point names, dependency relationships, and whether a file already has test coverage.
  • Metadata about the tests we generate: test names, the file they target, type (unit / integration / smoke), and pass / fail / needs-review status.
  • Coverage metrics over time (for example, covered diff lines or whole-repo baseline coverage).
  • Operational logs and job records (timestamps, job outcomes, error and repair-loop results) used to run and debug the service.

Some of this metadata — for example file paths, branch names, or commit messages — can incidentally contain text you have chosen to put there, which may include personal information. We treat all such metadata as confidential and apply the protections described in this policy to it.

4. Personal information we collect

Separately from repository metadata, we collect the personal information needed to provide the service to you and your organisation:

  • Account information: name, work email address, organisation, and the identity of the account that authorised our access to a repository.
  • Billing information: billing contact details and transaction records. Card details are handled by our payment processor, not stored by us.
  • Communications: messages you send us (for example support or sales enquiries) and our replies.
  • Technical and usage data: IP address, device and browser information, and website analytics collected when you use our website and service.

5. How we use information

We use the information described above to: provide and operate the test-generation service; plan, generate, and deliver tests as pull requests; report coverage and metrics back to you; authenticate users and secure the service; provide support; bill for covered files; comply with legal obligations; and detect, prevent, and investigate fraud, abuse, and security incidents.

Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests or contractual necessity (for example, to run a job you asked for), we limit processing to what is reasonably necessary for that purpose.

6. Disclosure and sub-processors

We do not sell your information. We disclose it only to the sub-processors we rely on to deliver the service, each engaged under contractual confidentiality and data-protection terms:

  • Source-code hosting provider (GitHub, GitLab, Gitea, or Bitbucket)

    Read-only access to clone the repository you ask us to analyse, and to open pull requests containing proposed tests that you review and merge yourself.

  • Third-party LLM inference provider (security compliant major US LLM providers)

    Transient processing of source code, diffs, and existing tests solely to generate proposed tests. Bound by contract to confidentiality and to not use your content to train models. No customer code is retained by us after the job completes.

  • Cloud hosting and infrastructure provider

    Runs our orchestration service and the isolated, network-restricted sandboxes that compile and run generated tests.

  • Payment processor

    Processes billing for covered files. Receives your billing details only — never your source code or code metadata.

We may also disclose information where required by law, to protect our legal rights, or in connection with a corporate transaction, in each case subject to appropriate safeguards. We will keep the list of sub-processors current.

7. International data transfers

Some of our sub-processors, including our LLM inference provider, may process data outside in the United States and Australia. Where information is transferred across borders, we take reasonable steps to ensure it is handled consistently with this policy and applicable law, including using recognised transfer mechanisms where required.

8. Data retention

Source code is deleted at the end of each job. Metadata, test results, account information, and billing records are retained for as long as your account is active and thereafter only as needed for legitimate business purposes and to meet legal, tax, and accounting obligations, after which they are deleted or de-identified.

9. How we protect your data

We build the service around isolation and least privilege. Untrusted customer code is compiled and run inside sandboxes with network access disabled, no ambient secrets, dropped privileges, and strict resource limits, and those environments are torn down after each job. We use encryption in transit, access controls, and logging. No system is perfectly secure, but we design to limit the blast radius of any single failure.

10. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Ask us to correct information that is inaccurate, incomplete, or out of date.
  • Ask us to delete your personal information, subject to any legal retention obligations we have.
  • Withdraw consent, or object to or restrict certain processing, where applicable law gives you that right.
  • Request a copy of the personal information you provided to us in a portable, machine-readable format, where applicable.
  • Make a complaint to us, and escalate to a data protection regulator if you are not satisfied with our response.

To exercise any of these rights, contact us using the details below. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and, where they apply, the EU/UK GDPR and the California Consumer Privacy Act.

11. Data breach notification

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the relevant regulator as required by law, including under Australia's Notifiable Data Breaches scheme.

12. Cookies and website analytics

Our website uses cookies and similar technologies for essential functionality and to understand how the site is used. You can control cookies through your browser settings; disabling some cookies may affect how the site works.

13. Children

TestCoverNet is a business tool that is not directed to children, and we do not knowingly collect personal information from children.

14. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Continued use of the service after changes take effect means you accept the updated policy.

15. Contact us

For privacy questions, requests, or complaints, contact us at:

admin@testcovernet.com

TestCoverNet — automated test coverage that terminates bugs before they ship.

© 2026 TestCoverNet · Home · Privacy