TurnSignal

Privacy

How TurnSignal handles your data. Last updated 2026-09-27.

In short

  • We store test results and the minimum account details needed to sign you in. We never receive your source code.
  • Common secret formats in test errors and traces (tokens, passwords, keys) are redacted in your CI before anything is sent, and again on our servers. Redaction matches known patterns, so it can miss an unusual secret; commit messages, test titles, screenshots and videos are not redacted.
  • We don't sell your data, show ads, or use your data to train AI models.
  • You can ask us to delete your data at any time.

What we collect

  • Your account. Signing in with GitHub: your GitHub user id, username and display name. Signing in with Google: your Google account id, verified email address and name. Signing in with an email link: your email address, and for about a day a record of each link we sent (only a fingerprint of the link itself). If you use Google and an email link with the same address, it is one account. We don't store passwords or GitHub/Google access tokens.
  • Organizations. Which organizations you belong to, your role, and pending invitations (a GitHub username or email address).
  • Test results sent by our reporter from your CI. Test names and file paths, outcomes, durations and attempts, error messages, stack traces and code snippets (after secret redaction), branch, commit id and message, the commit author's name (turn off with TURNSIGNAL_SEND_AUTHOR=0), the CI job link, the runner's hostname and memory use.
  • Security records. An audit log of security-relevant actions (for example sign-ins, token and member changes) with who did what and when.
  • Request logs. The page or endpoint, status, response time and a request id. They don't contain IP addresses, query strings, request bodies or tokens.
  • Screenshots, videos and Playwright traces, if your Playwright config records them and your project keeps them (by default only for failed and flaky tests). They show the application you test and can contain personal data from it. Traces are redacted in your CI before upload (authorization headers, cookies, secrets) and don't include your test source code. Project owners can turn this off.

What we don't collect

Your source code (including test source in traces), IP addresses in our database, payment details, and analytics or advertising trackers.

Cookies

Only cookies needed to run the service: your sign-in session (ends after 7 days without use, stored on our side only as a hash), a 10-minute cookie that protects the sign-in step, a 10-minute cookie that remembers which page to open after you sign in, and a two-minute cookie that shows a newly created token once. No analytics or advertising cookies.

Where your data is stored and who processes it

All data travels over encrypted connections (TLS). We use these providers:

  • Fly.io: runs the application (United States, Virginia).
  • Tigris (via Fly.io): stores screenshots, videos and traces, encrypted at rest, unless your organization connects its own bucket; then they are stored there.
  • Neon: our Postgres database on Amazon Web Services us-east-1 (United States), encrypted at rest.
  • GitHub and Google: sign-in, only if you choose them.
  • Brevo: sends sign-in emails, only if you sign in with an email link. It receives your email address and the email.
  • npm: distributes the turnsignal reporter package; it receives none of your data.

How long we keep it

  • Test runs: deleted automatically after 90 days, or the retention period set for your project.
  • Screenshots, videos and traces: 30 days for failed and flaky tests, 7 days for passed tests, and always with their run.
  • Account and organization data: until you ask us to delete it.
  • Sessions: removed after they expire.
  • Audit log: kept as security evidence.

Your choices and rights

You can revoke tokens and remove members at any time in the dashboard, and delete projects, whole organizations and your account yourself (Account, in the sidebar). Deleting removes the data, including screenshots, videos and traces, right away. To get a copy of your data, or for anything else, contact us and we will do it and confirm. Email hello@turnsignal.ai.

Changes

If this notice changes, we update this page and the date at the top.