Privacy Policy
What Kvalli collects, why, where it is stored, and how to have it removed. Written to describe how the product actually behaves rather than to maximise what we are permitted to do.
Effective 16 September 2026 · PR Dmitrii Bogdanov
Who we are
PR Dmitrii Bogdanov operates kvalli.ai and the Kvalli workspace. For questions about this policy or to exercise any right described below, contact admin@kvalli.ai.
Registered address: Mite Ružića 2, 21000 Novi Sad, Republic of Serbia
Information you give us directly
- Pilot enquiries: work email, company name, team size, the test management and automation tools you use, and any notes you add. We use this only to respond to you about a pilot.
- Account information: email address and a password hash if you create a workspace account. Passwords are hashed with scrypt and a per-user salt; we never store or transmit them in plain text.
- Correspondence you send to us by email.
Information from the tools you connect
When you connect an integration (Jira, Confluence, YouTrack, GitHub, GitLab, an OpenAPI source, or a CI provider), Kvalli reads the data needed to build the coverage graph: requirement and issue text, repository file contents and paths, test case definitions, and pipeline run results.
- Integration credentials are encrypted at rest with AES-256-GCM envelope encryption and are never returned to the browser after they are saved.
- Outbound requests are constrained by DNS-resolved SSRF protection, so a hostname cannot be used to reach internal network ranges.
- Secrets detected in logs and agent output are recursively masked before storage or display.
- You choose the scope of each access token. Kvalli requests no more than read access for analysis, and write access only for features you explicitly enable.
Model providers and bring-your-own-key
Generative features run against a model provider using an API key you supply. When an agent runs, the relevant requirement text, code excerpts, or stack traces are sent to that provider under your key and subject to that provider’s terms and retention policy. We do not use your content to train models, and we do not share it with any model provider you have not configured.
What we do not collect
- We do not sell or rent personal data, integration contents, or stack details to anyone.
- We do not run third-party advertising or cross-site tracking scripts on this site.
- We do not require analytics cookies to use the public pages.
Retention and deletion
Analysis artifacts, test cases, and run history persist in your workspace until you delete them or ask us to. Pilot enquiry records are kept until the enquiry is resolved and for a reasonable period afterwards for follow-up. Email admin@kvalli.ai to request export or deletion of your data and we will action it without undue delay.
Your rights
Depending on where you live, you may have the right to access, correct, export, restrict processing of, or delete your personal data, and to object to processing or withdraw consent. You can exercise any of these by emailing us; we will not charge you or degrade your service for doing so. If you are in the EEA or UK and are unsatisfied with our response, you may complain to your local data protection authority.
Sub-processors and transfers
We use infrastructure providers for hosting, database, and email delivery, and the model provider you configure. Data may be processed in countries other than your own; where that happens we rely on the safeguards offered by those providers. We will update this section when the set of providers changes materially.
Security reports
If you believe you have found a vulnerability, email admin@kvalli.ai with reproduction steps and the affected endpoint. We will acknowledge your report and will not pursue action against good-faith research that avoids privacy violations and service disruption.
Changes to this policy
We will update the effective date at the top of this page when this policy changes, and will notify workspace account holders by email for changes that materially reduce your rights.