Security & privacy
Careful with your site, your data and your users.
What we store, where, for how long, and what our agents are never allowed to do.
EU hosting in Madrid
- Recordings, screenshots, reports and account data are stored in the EU, in a Madrid data centre.
- Traffic is encrypted in transit (TLS) and data is encrypted at rest.
Test credentials
- Passwords for test accounts are encrypted as soon as you save them.
- They are used only by the login step. The AI model never receives them, and they never appear in reports, videos or logs.
- Delete them from the project at any time. Use accounts created for testing, never real customer accounts.
What agents may and may not do
- Public sites: read and navigate only. No sign-ups, messages, reviews or orders.
- Apps: only on domains you have verified, only with the test accounts you provide.
- Payments: never. Agents stop before any payment step and never type card details.
- Human pace: sessions browse like a person would, never as a load test.
Retention and deletion
- Studies, recordings and reports are kept for 90 days, then deleted.
- Ask us to delete a study or your whole account sooner and we will.
- Download your PDF report and fix prompt if you need to keep them longer.
AI processing
- Screenshots and page text from test sessions are sent to our AI model provider to run the synthetic users and write the report.
- Test credentials are never sent. We do not use your data to build profiles of your visitors.
- The list of subprocessors and their locations: [to be completed by legal]
DPA and compliance
- A Data Processing Agreement is available for customers who need one.
- GDPR roles, legal basis and international transfers: [to be completed by legal]
Security questions or a DPA request: hello@uxsurgery.com