Privacy Policy
Last updated: June 2026
This Privacy Policy explains how Release Assurance Inc. ("Release Assurance," "we," "us") collects, uses, and protects information when you use our Salesforce verification platform and this website (together, the "Service"). It aims to be clear rather than exhaustive; if anything is unclear, contact us using the details below.
1. Information we collect
- Account information — the names, work email addresses, and company details of the people you authorize to use the Service.
- Connection information — the Salesforce sandbox endpoint and the credentials or keys you provide so we can run verification using the account you designate.
- Verification artifacts — screenshots, video recordings, and run logs produced while a test runs. Because tests exercise your real screens, these artifacts may incidentally include data shown on those screens.
- Usage and log data — standard operational and security logs, such as request metadata and error information, generated as you use the Service.
- Website analytics — aggregate usage analytics for our website, collected through Google Analytics, to understand how the site is used.
2. How we use information
We use information to provide, operate, secure, support, and improve the Service — including configuring and running verification, reporting results, communicating with you about your account, and meeting legal obligations. We do not sell your personal information, and we do not use your Salesforce data to train machine-learning models for others.
3. How we share information
We share information only with service providers who help us operate the Service, and only to the extent needed for that purpose. Our current providers include Google Cloud (hosting and infrastructure), Resend (transactional email), Cal.com (scheduling), and Sentry (error monitoring). We may also disclose information where required by law or to protect our rights and the safety of others. We do not otherwise share your information.
4. AI processing and model providers
Release Assurance uses large language models to author verification plans from your descriptions, to classify why a run failed, and to answer questions about your testing environment. Where a feature needs it, the content sent to a model can include the description you wrote, the structure of the workflow, and context drawn from a failed run — for example the failing step, captured error text, and a summary of the evidence collected.
Where inference happens. Model inference is performed by Google Cloud Vertex AI within our own Google Cloud project. We do not send customer content to consumer AI products or free-tier AI services.
Training. Content sent for inference is not used to train foundation models. Google Cloud contractually commits that customer prompts and responses submitted through Vertex AI are not used to train its models, and we do not train models on customer content ourselves.
Minimisation. Captured field values and record identifiers are redacted before a captured step is sent to a model, because the model needs the shape of an action rather than its contents.
Direction. For customers with stricter requirements we are evaluating privately deployed models on dedicated infrastructure, so that inference for those workloads can remain inside a controlled network boundary. That capability is not available today, and this policy will be updated before it is.
5. Data retention
We keep account information for as long as your account is active. Verification artifacts are retained for a limited period and then deleted automatically; the default window is short (7 days) and can be configured for your account. Salesforce access tokens are used only in memory while a test runs and are not stored on disk. When your account ends, we delete or return your data as described in Section 7.
6. Security
We use commercially reasonable technical and organizational measures to protect information, including encryption in transit, access controls, separation of each customer's data, and least-privilege access to the environment you connect. No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect in the first place.
7. International transfers
We operate on Google Cloud and may process information in the United States and in other countries where our providers operate. Where required, we rely on appropriate safeguards for cross-border transfers of personal information.
8. Your rights and the DPA
You retain all rights to your Salesforce data and business information. Depending on your location, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. On request we will provide a Data Processing Agreement aligned with the GDPR. When your account ends, we revoke our access and delete or, on request, return your data and artifacts.
9. Children's privacy
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above; we will communicate material changes through the Service or by email.
11. Contact
Questions about this policy, a privacy request, or a Data Processing Agreement: privacy@releaseassurance.com.