Privacy Policy

Last updated: June 2026

This Privacy Policy explains how Release Assurance Inc. ("Release Assurance," "we," "us") collects, uses, and protects information when you use our Salesforce verification platform and this website (together, the "Service"). It aims to be clear rather than exhaustive; if anything is unclear, contact us using the details below.

1. Information we collect

2. How we use information

We use information to provide, operate, secure, support, and improve the Service — including configuring and running verification, reporting results, communicating with you about your account, and meeting legal obligations. We do not sell your personal information, and we do not use your Salesforce data to train machine-learning models for others.

3. How we share information

We share information only with service providers who help us operate the Service, and only to the extent needed for that purpose. Our current providers include Google Cloud (hosting and infrastructure), Resend (transactional email), Cal.com (scheduling), and Sentry (error monitoring). We may also disclose information where required by law or to protect our rights and the safety of others. We do not otherwise share your information.

4. AI processing and model providers

Release Assurance uses large language models to author verification plans from your descriptions, to classify why a run failed, and to answer questions about your testing environment. Where a feature needs it, the content sent to a model can include the description you wrote, the structure of the workflow, and context drawn from a failed run — for example the failing step, captured error text, and a summary of the evidence collected.

Where inference happens. Model inference is performed by Google Cloud Vertex AI within our own Google Cloud project. We do not send customer content to consumer AI products or free-tier AI services.

Training. Content sent for inference is not used to train foundation models. Google Cloud contractually commits that customer prompts and responses submitted through Vertex AI are not used to train its models, and we do not train models on customer content ourselves.

Minimisation. Captured field values and record identifiers are redacted before a captured step is sent to a model, because the model needs the shape of an action rather than its contents.

Direction. For customers with stricter requirements we are evaluating privately deployed models on dedicated infrastructure, so that inference for those workloads can remain inside a controlled network boundary. That capability is not available today, and this policy will be updated before it is.

5. Data retention

We keep account information for as long as your account is active. Verification artifacts are retained for a limited period and then deleted automatically; the default window is short (7 days) and can be configured for your account. Salesforce access tokens are used only in memory while a test runs and are not stored on disk. When your account ends, we delete or return your data as described in Section 7.

6. Security

We use commercially reasonable technical and organizational measures to protect information, including encryption in transit, access controls, separation of each customer's data, and least-privilege access to the environment you connect. No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect in the first place.

7. International transfers

We operate on Google Cloud and may process information in the United States and in other countries where our providers operate. Where required, we rely on appropriate safeguards for cross-border transfers of personal information.

8. Your rights and the DPA

You retain all rights to your Salesforce data and business information. Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. On request we will provide a Data Processing Agreement aligned with the GDPR. When your account ends, we revoke our access and delete or, on request, return your data and artifacts.

9. Children's privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

10. Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date above; we will communicate material changes through the Service or by email.

11. Contact

Questions about this policy, a privacy request, or a Data Processing Agreement: privacy@releaseassurance.com.