Legal
Privacy Policy
Last updated 13 August 2026
This explains what we do with personal data on TestFi. It covers testers, developers, and visitors to the site.
The controller is CDrop LLC, a limited liability company registered in the State of Wyoming, United States ("TestFi", "we", "us"), [registered agent address, Wyoming, USA]. For anything in this policy, including exercising your rights, email privacy@testfi.app.
01Who decides what, and when
For tester accounts, payouts, session scoring, and the running of the platform, we are the controller: we decide why and how the data is used.
For the content of a campaign a developer runs, including any personal data they choose to put into their app or scenario, the developer is the controller and we act as their processor. The Data Processing Addendum governs that part.
02What we collect
Account and profile. Name or display name, email address, role, country, language, the devices you say you own, and any bio you write.
Screen recordings, and this is the important one. If you take a test that asks for a recording, we collect a video of your screen and your voice while you use the app. A recording captures whatever was visible at that moment, which can include notifications, other apps, your own personal information, and information about other people. We also generate a transcript of what you said and, where the session was not in English, a translation. Please read clause 9 of the Tester Agreement before you record, and tell us if something private was captured by accident so we can delete it.
Written feedback and answers you submit, and the scores and summaries our automated system produces from your session.
Payment and payout data. For developers, the fact and amount of a payment; card details go directly to Stripe and we never see or store them. For testers, the payout method and destination you enter, such as a crypto wallet address, which is encrypted at rest with AES-256-GCM.
Campaign content from developers, including app builds, scenarios, and any test credentials supplied.
Usage and technical data. IP address, browser and device information, pages viewed, and the referrer or campaign parameters that brought you to the site.
Support correspondence when you email us.
We do not deliberately collect special category data. A recording could contain some incidentally, which is exactly why recordings are retained on a schedule, restricted to the developer who paid for the session, and never sold or shared with anyone else to train their models. Clause 6 explains how we use sessions to improve our own scoring, and how to object.
03Where it comes from
Almost all of it comes from you. We also receive confirmation of payment status from Stripe, delivery and bounce information from our email provider, and, where you signed up through a link, the referral or campaign identifier that link carried.
04Why we use it, and our legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Run your account and the platform | Account, profile, usage | Performance of a contract |
| Deliver a campaign: match testers, collect sessions, deliver results | Sessions, recordings, feedback, campaign content | Performance of a contract |
| Score sessions and decide acceptance and payment | Sessions, recordings, transcripts, scores | Performance of a contract |
| Pay testers and take developer payments | Payout and payment data | Performance of a contract |
| Prevent fraud, duplicate accounts, and abuse | Account, device and usage signals, session metadata | Legitimate interests: protecting the platform and honest users |
| Sanctions screening before a payout | Name, country, payout destination | Legal obligation |
| Service emails you cannot opt out of, such as payment and session notices | Account, email | Performance of a contract |
| Product and marketing emails to existing users | Account, email, campaign history | Legitimate interests, and consent where the law requires it. Unsubscribe any time |
| Analytics and measuring where signups come from | Usage, referrer, campaign parameters | Consent where cookies or similar technologies are used |
| Improving our scoring models | Sessions, recordings, transcripts, scores | Legitimate interests: accuracy of the system that decides whether work is paid for. You can object |
| Accounting, tax, and defending legal claims | Transaction records | Legal obligation and legitimate interests |
Where we rely on legitimate interests, we have weighed them against your rights and you can object at any time using the contact details above.
05Automated decision making
An automated system scores every test session, and that score contributes to whether a submission is accepted, which is what triggers payment. Because that has a real effect on you, we explain the logic, what the system weighs, and how to get a person to review any decision in the AI Scoring and Appeals Policy.
In short: you can always ask for human review, by someone who was not part of the original decision and who can reverse it. You can give your side, and you can contest the outcome. Appeals are free.
06Using sessions to improve our models
We use completed sessions, and the transcripts and scores derived from them, to train, test, and improve TestFi's own scoring and analysis models. This is part of running the service: better scoring is what lets us accept good sessions automatically and pay for them faster. It is set out in clause 8 of the Tester Agreement.
Our legal basis is legitimate interests: improving the accuracy of the system that decides whether work is accepted and paid for. We have weighed that against your rights, and the safeguards are that the data stays inside TestFi, is never sold or given to a third party to train their models, and that where a transcript or a score is enough we use those rather than the raw video.
You can object. Email privacy@testfi.app and we will stop using your sessions for this. Objecting will not affect your pay, your rating, or the work you are offered. It does not undo training already carried out, which cannot be reversed.
A recording can incidentally capture information you did not intend to share. Clause 9 of the Tester Agreement asks you to close private apps and turn off notification previews before recording, and if something private is captured by accident, tell us and we will delete it.
08International transfers
We are a United States company, our infrastructure providers are largely in the United States and the European Union, and the person who operates the business is in Türkiye. Your data will therefore cross borders.
For transfers out of the European Economic Area or the United Kingdom we rely on the European Commission Standard Contractual Clauses, and the UK Addendum or International Data Transfer Agreement, together with additional safeguards where needed. For transfers out of Türkiye we use the standard contract required by the KVKK and notify the Board as required. You can request a copy of the relevant safeguards from privacy@testfi.app.
09How long we keep it
| What | How long |
|---|---|
| Screen recordings | 180 days from the session, then deleted from storage. Low quality sessions flagged during review are deleted sooner |
| Transcripts, written feedback, scores | Kept while the developer's account is open, as they are the deliverable |
| Account and profile | Until you close your account, then deleted within 30 days |
| Payment and payout records | Up to 7 years, because tax and accounting law requires it |
| Fraud and ban records | Kept as long as needed to stop a banned account returning, reviewed periodically |
| Support emails | 2 years |
10Security
Access to production data is restricted and authenticated. Payout details such as wallet addresses are encrypted at rest with AES-256-GCM. Database access is governed by row level security so one user cannot read another's records. Recordings are served through time limited links rather than public URLs.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant supervisory authority as the law requires.
11Your rights
Depending on where you live, you can ask us to:
- give you a copy of your data, and tell you what we do with it
- correct anything inaccurate
- delete it, where we do not need to keep it
- restrict or object to how we use it, including profiling and direct marketing
- receive it in a portable format, or send it to someone else
- withdraw consent, for anything based on consent
- obtain human review of an automated decision, as described in clause 5
Email privacy@testfi.app. We answer within one month and will tell you if we need longer. We do not charge for this, and we will not treat you differently for asking.
You can also complain to a regulator. In the EU, the data protection authority where you live or work. In the UK, the Information Commissioner's Office. In Türkiye, the Kişisel Verileri Koruma Kurumu. We would rather you came to us first, but you do not have to.
12Representatives and registrations
We are appointing a representative in the European Union and in the United Kingdom under Article 27 of the EU and UK GDPR, and completing registration with VERBİS together with a representative in Türkiye. Their contact details will be published here once appointed. Until then, all requests should go to privacy@testfi.app, and we will handle them on the same timescales.
14Children
TestFi is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a child has an account, email contact@testfi.app and we will delete it.
15Changes to this policy
We will post any change here and update the date at the top. If a change materially affects your rights we will tell you by email or in the product before it takes effect.