Security & privacy

Careful with your site, your data and your users.

What we store, where, for how long, and what our agents are never allowed to do.

EU hosting in Madrid

  • Recordings, screenshots, reports and account data are stored in the EU, in a Madrid data centre.
  • Traffic is encrypted in transit (TLS) and data is encrypted at rest.

Test credentials

  • Passwords for test accounts are encrypted as soon as you save them.
  • They are used only by the login step. The AI model never receives them, and they never appear in reports, videos or logs.
  • Delete them from the project at any time. Use accounts created for testing, never real customer accounts.

What agents may and may not do

  • Public sites: read and navigate only. No sign-ups, messages, reviews or orders.
  • Apps: only on domains you have verified, only with the test accounts you provide.
  • Payments: never. Agents stop before any payment step and never type card details.
  • Human pace: sessions browse like a person would, never as a load test.

Retention and deletion

  • Studies, recordings and reports are kept for 90 days, then deleted.
  • Ask us to delete a study or your whole account sooner and we will.
  • Download your PDF report and fix prompt if you need to keep them longer.

AI processing

  • Screenshots and page text from test sessions are sent to our AI model provider to run the synthetic users and write the report.
  • Test credentials are never sent. We do not use your data to build profiles of your visitors.
  • The list of subprocessors and their locations: [to be completed by legal]

DPA and compliance

  • A Data Processing Agreement is available for customers who need one.
  • GDPR roles, legal basis and international transfers: [to be completed by legal]

Security questions or a DPA request: hello@uxsurgery.com

Privacy policyAcceptable use policy