Effective 2026-10-01. Covers version 0.2.1 and later — both the copy from the Chrome Web Store and the copy from GitHub.
The Testomat.io extension, published by Testomat.io, runs Testomat.io manual tests beside the site you are testing. This policy says what data it handles, where that data goes, how long it is kept, and how to switch it off or erase it.
https://app.testomat.io, or your own self-hosted address.app.testomat.io, that instance is run by Testomat.io (Optimum Solutions Sp. z o.o.), and
what you upload is covered by the Testomat.io Privacy Policy.
A self-hosted instance is run by your own organization.app.testomat.io, Testomat.io passes them to its AI provider, Groq (USA).Your Testomat.io account. Your access token, stored in your browser and sent only to the instance you save it for. To show the people on runs and tests and to set assignees, the extension reads your project members’ names, emails, avatars and time zones from your instance, and your own user ID from your session; these stay in the panel’s memory and are gone when it closes.
Test results. The statuses, comments and step results you mark, and the tests, suites and attachments you create, edit or delete — sent to your instance when you click.
Environment info. With each status you mark: the browser and its major version, the operating system, the size of the tested tab, and its address. By default the address is cut to scheme, host and path — no query string, no fragment. Settings → Record environment info turns this off; Include the query string keeps the full address, here and in a recorded Open step.
Screenshots and screen recordings of the tab you are testing — only when you take one. You mark up a screenshot before it is saved, and review (and can trim) a recording before you attach it. Recordings are picture only, with no sound.
The console & network log of the tab you are testing — only while you record it (the Rec button), or when you have turned on Auto-start (off by default). It holds the page’s console errors and warnings, and for each network request its method, address, status and timing, plus the first 16 KB of the response body of a failed request (Include response bodies turns bodies off). Request bodies and cookies are never read. Outside those response bodies, every web (http and https) address in the log file is cut to scheme, host and path. It keeps a rolling window of the last minute (configurable), and is attached to a result when you mark it Failed (Attach log to failures, on by default). The Attach button next to one log entry copies that entry, response body included, into your comment.
Recorded steps. When you record steps, the extension writes down your clicks, what you type,
the options you pick and the pages you open, as readable sentences such as
Type "Kyiv" into the City field. Typed values are kept up to 40 characters.
Polish with AI (off by default). When you stop a recording with the editor’s Polish with AI switch on, or press Polish recorded steps, the extension sends your instance, once: the test’s title, the steps already written, the recorded steps, the texts and attributes of the controls you used and of their surroundings, what changed on the page after each action, and the page’s title and address (query cut). Nothing is sent while you record.
Payment details. When you test a payment page, card or bank details can end up in a screenshot, a recording, the log or a recorded step: card fields are masked, but only as best effort, and a card you pick by clicking (“Visa •••• 4242”) is recorded by its text.
Page addresses and titles. The address of the page you are testing travels with results; its address and title travel with logs and recorded steps, as described above. Chrome’s browsing history is never read.
app.testomat.io that is Testomat.io, under its
Privacy Policy and Terms.
Everyone with access to the project there can see what you upload to it.app.testomat.io, passed on by
Testomat.io. Testomat.io’s Terms say AI features must first be switched on by the company owner
in the company settings. On a self-hosted instance, where that text goes is up to its
administrator. The extension itself never contacts an AI provider.chrome.storage.local): your access token per instance,
the instance and project, your settings, a short list of instances you used, where you left
the panel, and results waiting to be sent while your instance cannot be reached.chrome.storage.session): the log you recorded, recorded
steps, unsaved drafts and comments, a screenshot being marked up, and the record of a screen
recording waiting for review (the video itself stays in the extension’s memory).chrome.storage.sync is never used, so none of this is copied to your Google account.Once something reaches your instance, it lives there under that instance’s rules — on
app.testomat.io, the Testomat.io Privacy Policy.
app.testomat.io and of the self-hosted instance you are
connected to, which tells the web app that the extension (and its version) is installed, so it
can offer Run in Extension. It never runs on the site you test.The mark-up tool, the file preview, the recording bar and review, and the step recorder’s pill are drawn inside the page you are testing, so that page’s own scripts can see them — including the screenshot being marked up and the address of a file being previewed.
Chrome shows two warnings for these: “Read and change all your data on all websites” and “Access the page debugger backend”.
handoff.json, the file a desktop test tool can place in that folder to
connect the panel.The use of information received by this extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. It is used only to run your tests, attach evidence to their results and write test cases, and it is never sold, never used or transferred for advertising, and never used to determine creditworthiness or for lending.
The extension is a professional testing tool and is not directed at children.
This page is published from the repository’s main branch and changes when a change is merged
there, which can be a few days before that version reaches the Chrome Web Store. The date at the
top says when it last changed.
Questions about the extension, or a claim here that does not match the code: open an issue at https://github.com/testomatio/browser-extension/issues.
A request about your data on app.testomat.io: legal@testomat.io.