Testomat.io Chrome extension

Privacy Policy for the Testomat.io Chrome extension

Effective 2026-10-01. Covers version 0.2.1 and later — both the copy from the Chrome Web Store and the copy from GitHub.

The Testomat.io extension, published by Testomat.io, runs Testomat.io manual tests beside the site you are testing. This policy says what data it handles, where that data goes, how long it is kept, and how to switch it off or erase it.

Summary

What the extension handles

Your Testomat.io account. Your access token, stored in your browser and sent only to the instance you save it for. To show the people on runs and tests and to set assignees, the extension reads your project members’ names, emails, avatars and time zones from your instance, and your own user ID from your session; these stay in the panel’s memory and are gone when it closes.

Test results. The statuses, comments and step results you mark, and the tests, suites and attachments you create, edit or delete — sent to your instance when you click.

Environment info. With each status you mark: the browser and its major version, the operating system, the size of the tested tab, and its address. By default the address is cut to scheme, host and path — no query string, no fragment. Settings → Record environment info turns this off; Include the query string keeps the full address, here and in a recorded Open step.

Screenshots and screen recordings of the tab you are testing — only when you take one. You mark up a screenshot before it is saved, and review (and can trim) a recording before you attach it. Recordings are picture only, with no sound.

The console & network log of the tab you are testing — only while you record it (the Rec button), or when you have turned on Auto-start (off by default). It holds the page’s console errors and warnings, and for each network request its method, address, status and timing, plus the first 16 KB of the response body of a failed request (Include response bodies turns bodies off). Request bodies and cookies are never read. Outside those response bodies, every web (http and https) address in the log file is cut to scheme, host and path. It keeps a rolling window of the last minute (configurable), and is attached to a result when you mark it Failed (Attach log to failures, on by default). The Attach button next to one log entry copies that entry, response body included, into your comment.

Recorded steps. When you record steps, the extension writes down your clicks, what you type, the options you pick and the pages you open, as readable sentences such as Type "Kyiv" into the City field. Typed values are kept up to 40 characters.

Polish with AI (off by default). When you stop a recording with the editor’s Polish with AI switch on, or press Polish recorded steps, the extension sends your instance, once: the test’s title, the steps already written, the recorded steps, the texts and attributes of the controls you used and of their surroundings, what changed on the page after each action, and the page’s title and address (query cut). Nothing is sent while you record.

Payment details. When you test a payment page, card or bank details can end up in a screenshot, a recording, the log or a recorded step: card fields are masked, but only as best effort, and a card you pick by clicking (“Visa •••• 4242”) is recorded by its text.

Page addresses and titles. The address of the page you are testing travels with results; its address and title travel with logs and recorded steps, as described above. Chrome’s browsing history is never read.

Where your data goes

What is kept in your browser, and for how long

Once something reaches your instance, it lives there under that instance’s rules — on app.testomat.io, the Testomat.io Privacy Policy.

What runs without a click

The mark-up tool, the file preview, the recording bar and review, and the step recorder’s pill are drawn inside the page you are testing, so that page’s own scripts can see them — including the screenshot being marked up and the address of a file being previewed.

Permissions

Chrome shows two warnings for these: “Read and change all your data on all websites” and “Access the page debugger backend”.

Your choices and how to erase

What the extension does not do

Limited Use

The use of information received by this extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. It is used only to run your tests, attach evidence to their results and write test cases, and it is never sold, never used or transferred for advertising, and never used to determine creditworthiness or for lending.

Children

The extension is a professional testing tool and is not directed at children.

Changes

This page is published from the repository’s main branch and changes when a change is merged there, which can be a few days before that version reaches the Chrome Web Store. The date at the top says when it last changed.

Contact

Questions about the extension, or a claim here that does not match the code: open an issue at https://github.com/testomatio/browser-extension/issues.

A request about your data on app.testomat.io: legal@testomat.io.