zantiq.
FeaturesPricingDocs
LoginTry Demo
zantiq.

AI-powered testers with real online identities. Test like your users do.

Product

  • Features
  • Pricing
  • API Reference
  • Changelog

Company

  • About
  • Blog
  • Careers
  • Contact

Legal

  • Privacy
  • Terms
  • Security
© 2026 Zantiq. All rights reserved.

Privacy Policy

Last updated: March 26, 2026

Table of Contents

  1. 1. Introduction
  2. 2. Information We Collect
  3. 3. How We Use Information
  4. 4. AI & Data Processing
  5. 5. Tester Identity Data
  6. 6. Who We Share Data With
  7. 7. Data Security
  8. 8. Data Retention
  9. 9. Your Rights
  10. 10. International Transfers
  11. 11. Children
  12. 12. Cookies
  13. 13. Changes to This Policy
  14. 14. Contact & DPO

1. Introduction

Zantiq, Inc. ("Zantiq," "we," "us," or "our") operates the Zantiq platform, including our website at zantiq.io, our dashboard, our API, and all related services (collectively, the "Service"). Zantiq is an AI-powered testing platform that provisions real online identities to automate end-to-end testing of web applications.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, create an account, use our dashboard, access our API, or otherwise interact with the Service. It applies to all users of the Service, including free and paid subscribers, and to anyone who visits our website.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

2. Information We Collect

We collect several categories of information to provide and improve the Service. The specific data we collect depends on how you interact with our platform.

Account Data

When you create an account, we collect your name, email address, and profile picture. We support authentication via GitHub OAuth and Google OAuth, through which we receive your profile information and email address from those providers. We do not collect or store your GitHub or Google passwords.

Payment Data

Payment processing is handled entirely by Stripe. When you subscribe to a paid plan, your payment information (credit card numbers, bank account details) is collected and processed directly by Stripe. We never see, receive, or store your full card numbers. We receive only a summary from Stripe, including the last four digits of your card, the card brand, expiration date, and billing address for invoice and tax purposes.

Test Data

When you use the Service, we collect and process the test instructions you provide, the target URLs and domains you specify, your test configurations and parameters, the test reports and results generated by the platform, and any screenshots or recordings captured during test execution. This data is necessary to operate the Service and deliver test results to you.

Identity Data

As part of the Service, we provision real online identities for automated testing. This includes email accounts, phone numbers, social media profiles, browser profiles, and virtual payment cards created on your behalf and solely for testing purposes. This identity data is generated and managed by the platform and is not derived from real individuals. See Section 5 (Tester Identity Data) for detailed information about how this data is handled.

Usage Data

We automatically collect information about how you use the Service. This includes the pages and features you access, the number of tests you run, the number of API calls you make, timestamps of your interactions, and general usage patterns. This data helps us understand how the Service is used and how we can improve it.

Device Data

When you access the Service, we automatically collect information about your device, including your browser type and version, operating system, IP address, and approximate geographic location derived from your IP address. This information helps us provide a secure and optimized experience.

Cookies

We use essential cookies only. Specifically, we use a session cookie to maintain your authenticated session when you are logged in. We do not use advertising cookies, marketing cookies, or third-party tracking cookies. See Section 12 (Cookies) for full details.

Analytics

We use PostHog for product analytics with privacy-preserving defaults enabled. PostHog is configured to anonymize IP addresses and operates in a cookie-free mode by default. We use analytics data in aggregate to understand product usage and improve the Service.

3. How We Use Information

We use the information we collect for the following purposes:

  • Provide and operate the Service: to create and manage your account, authenticate your sessions, and deliver the core functionality of the platform.
  • Process payments: to manage your subscription, process invoices, and handle billing-related communications through Stripe.
  • Provision tester identities: to create, manage, and maintain the online identities (email, phone, browser profiles, virtual cards) used for automated testing.
  • Execute AI-powered tests: to process your test instructions through our AI engine, interact with target applications, and complete test scenarios.
  • Generate reports: to compile test results, capture screenshots, and produce detailed reports of test execution outcomes.
  • Send transactional emails: to notify you of test completions, billing events, account changes, security alerts, and other service-related communications. We do not send marketing emails without your explicit consent.
  • Improve the product: to analyze aggregated, anonymized usage data to identify trends, fix bugs, optimize performance, and develop new features. We do not use individual user data for product improvement without anonymization.
  • Prevent abuse and enforce terms: to detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Service.
  • Comply with legal obligations: to meet our legal, regulatory, and tax obligations, including responding to lawful requests from public authorities.

4. AI & Data Processing

Zantiq uses artificial intelligence to power its automated testing capabilities. We believe in transparency about how AI is used in our Service and how your data interacts with AI systems.

AI Provider:Test instructions and related context are processed by Anthropic's Claude API to generate and execute test plans. Anthropic acts as a data processor on our behalf and processes your data solely to provide the service to us.

No model training: Anthropic does not use customer data submitted through our Service for training or improving their AI models. Your test instructions, results, and data are not used as training data by Anthropic or by Zantiq.

AI-generated content: Test results, reports, and analysis generated by the Service are produced by AI. While we strive for accuracy, AI-generated outputs may contain inaccuracies, errors, or incomplete information. You should review and verify test results before making decisions based on them.

AI-generated personas: The tester identities (names, biographical details, preferences) created by the platform are entirely AI-generated. They are synthetic personas and are not based on, derived from, or modeled after any real individuals.

Our own models: We do not use your data to train our own AI models. Any data analysis we perform for product improvement uses only aggregated and anonymized data that cannot be linked back to individual users or their test data.

5. Tester Identity Data

This section provides detailed information about how we handle the online identities provisioned for automated testing. Given the sensitive nature of this data, we apply heightened security and isolation measures.

Purpose & Creation

Tester identities are created solely for the purpose of automated testing. Each identity consists of components such as email accounts, phone numbers, browser profiles, social media accounts, and virtual payment cards. These identities are synthetic and AI-generated — they do not represent or impersonate real people.

Isolation

All tester identity data is strictly isolated per customer. There is no cross-customer data access. Your tester identities, credentials, and associated data are accessible only to your account and cannot be viewed, accessed, or used by any other customer of the Service.

Encryption

Tester identity credentials are encrypted at rest using AES-256 encryption with per-tester derived keys. This means that even in the unlikely event of a data breach, credentials for one tester cannot be used to decrypt credentials for another. Encryption keys are managed through a secure key derivation process and are never stored alongside the encrypted data.

Third-Party Providers

Tester identity components are provisioned through the following third-party providers, each of which is subject to their own privacy policy:

  • Phone numbers via Telnyx: Phone numbers used for SMS verification during testing are provisioned through Telnyx. Phone number usage is subject to the Telnyx Privacy Policy.
  • Email accounts via Fastmail: Email accounts used for tester identities are provisioned through Fastmail. Email usage is subject to the Fastmail Privacy Policy.
  • Browser profiles and sessions: Browser fingerprints and profiles used for testing are managed through GoLogin. Interactive browser sessions are powered by Browserbase. Browser usage is subject to the GoLogin Privacy Policy and Browserbase Privacy Policy.
  • Virtual cards via Lithic: Virtual payment cards used for testing purchase flows are provisioned through Lithic. Card usage is subject to the Lithic Privacy Policy.

Deprovisioning

When a tester is terminated (either by you or automatically), all associated identity components are deprovisioned within 24 hours. This includes releasing phone numbers, closing email accounts, deleting browser profiles, and closing virtual cards. After deprovisioning, the identity data cannot be recovered.

SMS & Email Content

SMS messages received on tester phone numbers and emails received in tester inboxes are used exclusively for the purpose of test execution (for example, to retrieve verification codes or confirm email addresses). This content is never shared with third parties, never used for marketing purposes, and is deleted in accordance with our data retention schedule.

6. Who We Share Data With

We do not sell your data. Period. We have never sold personal data, and we will never sell personal data. We do not share your data with data brokers or advertisers.

Service Providers

We share information with the following third-party service providers who help us operate the Service. Each provider processes data solely on our behalf and is bound by their own privacy commitments and, where applicable, data processing agreements (DPAs):

  • Stripe— payment processing and subscription management
  • Telnyx— phone number provisioning and SMS delivery
  • Fastmail— email account provisioning and management
  • GoLogin— browser profile management
  • Lithic— virtual payment card provisioning
  • Vercel— website and application hosting
  • Neon— database hosting and management
  • Anthropic— AI model provider for test execution
  • PostHog— privacy-preserving product analytics
  • Sentry— error monitoring and application performance

Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process, including court orders, subpoenas, and requests from law enforcement or other government authorities. We will make reasonable efforts to notify you of such requests unless prohibited by law or court order.

Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

7. Data Security

We take the security of your data seriously and implement industry-standard technical and organizational measures to protect it. Our security practices include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3, the latest transport layer security protocol.
  • Encryption at rest: All stored data is encrypted using AES-256, the Advanced Encryption Standard with 256-bit keys.
  • API key security: API keys are stored as bcrypt hashes. We never store your API keys in plaintext. Once issued, an API key can only be verified, not retrieved.
  • Per-tester credential encryption: Tester credentials are encrypted with per-tester derived keys, ensuring that a compromise of one tester's data does not expose another's.
  • Infrastructure security: Our infrastructure providers (Vercel, Neon) maintain SOC 2 Type II compliance, ensuring continuous monitoring and verification of security controls.
  • Security audits: We conduct regular security audits and vulnerability assessments to identify and address potential vulnerabilities.
  • Incident response: We maintain documented incident response procedures to quickly detect, contain, and remediate security incidents. In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law.

Despite our efforts, no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.

8. Data Retention

We retain your data only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by law. Our specific retention periods are as follows:

  • Account data: Retained while your account is active. Upon account closure, your personal information is deleted or anonymized within 30 days, except where retention is required for legal, tax, or audit purposes.
  • Test data: Retained for 90 days after tester termination. This includes test instructions, configurations, reports, and screenshots. After this period, all test data is permanently deleted.
  • Identity components: Deprovisioned immediately upon tester termination. Phone numbers are released, email accounts are closed, browser profiles are deleted, and virtual cards are canceled within 24 hours.
  • Usage logs: Retained for 12 months from the date of collection. Usage logs are used for security monitoring, abuse prevention, and aggregated product analytics.
  • Payment records: Retained as required by applicable tax and accounting laws, typically for 7 years. This is necessary for compliance with financial reporting obligations.
  • Backups: Database backups are maintained on a 30-day rolling basis. Older backups are automatically purged.

9. Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal information. We are committed to honoring these rights regardless of where you are located, to the extent practicable.

Rights Under GDPR (EU) and UK GDPR

If you are located in the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:

  • Right to access: You have the right to request a copy of the personal data we hold about you.
  • Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
  • Right to erasure: You have the right to request that we delete your personal data (the "right to be forgotten"), subject to certain legal exceptions.
  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
  • Right to restrict processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.
  • Right to object: You have the right to object to the processing of your personal data, including processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Where we process your data based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Right not to be subject to automated decision-making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

Rights Under CCPA (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know: You have the right to know what personal information we collect, use, disclose, and sell about you.
  • Right to delete: You have the right to request that we delete the personal information we have collected about you, subject to certain exceptions.
  • Right to opt-out: You have the right to opt out of the sale of your personal information. As stated above, we do not sell personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, or provide a different quality of service because you exercised your rights.

How to Exercise Your Rights

To exercise any of the rights described above, please contact us at privacy@zantiq.io. Please include sufficient information for us to verify your identity and specify which right you wish to exercise.

We will respond to your request within 30 days of receipt. If we need additional time (up to 60 days total), we will notify you of the extension and the reason for it. There is no charge for submitting a request, unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or decline the request.

10. International Transfers

Zantiq is based in the United States. If you access the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate. These countries may have data protection laws that are different from the laws of your country.

For transfers of personal data from the European Economic Area (EEA) and the United Kingdom to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office, as applicable. These clauses provide appropriate safeguards to ensure that your data is protected to the standard required by GDPR Article 46.

We ensure that all our service providers who process personal data on our behalf implement adequate safeguards for international data transfers. A Data Processing Agreement (DPA) is available upon request by contacting privacy@zantiq.io.

11. Children

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. We do not target the Service to minors and do not knowingly allow anyone under 18 to create an account.

If we become aware that we have inadvertently collected personal information from a person under 18, we will take immediate steps to delete that information from our systems. If you believe that we may have collected information from a child under 18, please contact us immediately at privacy@zantiq.io so that we can take appropriate action.

12. Cookies

We take a minimal approach to cookies. Our cookie usage is limited to what is strictly necessary to operate the Service.

Essential Cookies

We use a single essential cookie to maintain your authenticated session when you are logged in to the Service. This cookie is necessary for the Service to function and cannot be disabled without losing the ability to use the authenticated portions of the platform.

No Advertising or Tracking Cookies

We do not use advertising cookies. We do not use marketing cookies. We do not use third-party tracking cookies. We do not participate in any advertising networks or retargeting programs.

Analytics

Our analytics provider, PostHog, is configured to operate in privacy mode. This means PostHog does not set cookies and anonymizes IP addresses before processing. Analytics data is collected solely to understand aggregate product usage and improve the Service.

Managing Cookies

You can configure your browser to reject cookies or to alert you when cookies are being set. However, if you disable essential cookies, you will not be able to log in to or use the authenticated features of the Service. Since we do not use non-essential cookies, there is no cookie preference banner or opt-out mechanism needed.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last updated" date at the top of this page.

For material changes that significantly affect how we collect, use, or share your personal information, we will provide at least 30 days' advance notice. This notice will be provided via email to the address associated with your account and through a prominent notice on the Service.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using the Service and close your account before the changes take effect.

Previous versions of this Privacy Policy are available upon request by contacting privacy@zantiq.io.

14. Contact & Data Protection Officer

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us using the appropriate channel below:

  • Privacy questions: privacy@zantiq.io
  • Complaints: complaints@zantiq.io
  • Data Protection Officer (EU/UK inquiries): dpo@zantiq.io
  • EU representative: To be appointed. This section will be updated once an EU representative has been designated in accordance with GDPR Article 27.

If you are located in the European Economic Area or the United Kingdom and believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with your local supervisory authority (data protection authority). You can find your local authority at edpb.europa.eu for EU authorities or contact the Information Commissioner's Office (ICO) for the United Kingdom.

We encourage you to contact us first so that we can try to resolve your concern directly.