Privacy and your data
How to take a copy of your personal data, delete your account, what happens to your workspaces when you do, and how workspace content is handled under the DPA.
Last updated 2026-09-10
EvaliQA holds two kinds of data about people. Your account (who you are, how you sign in, what you did) is yours, and this page is about the controls you have over it. Workspace content (test plans, datasets, traces, recordings, results) belongs to the workspace and is handled under the Data Processing Addendum on your organisation's instructions.
Everything below lives in Settings → Privacy & data.
Download a copy of your data
Download export produces a JSON file with everything the account service holds about you:
| Section | What is in it |
|---|---|
account | Profile, sign-in provider, onboarding answers, whether two-factor is on |
workspaces | Each workspace you belong to, your role, when you joined |
sessions | Active sessions with IP address and device description |
cookieConsent | Your cookie choices |
invitesSent, invitesReceived | Workspace invitations you sent or were sent |
apiTokens | Metadata of API tokens you created (never the token itself) |
auditEvents | Your own entries in the audit log, up to 180 days back |
marketingLeads | Resources you downloaded from the website |
The file carries a format field (evaliqa.personal-data-export/1) so
tools can recognise it. The export itself is written to the audit log
as DATA_EXPORTED.
Workspace content is not in this file. A workspace owner or admin exports it from within the product: datasets, runs and reports each have their own export, and traces can be pulled through the API.
Delete your account
Delete account removes the account and everything tied to it: profile, sessions, two-factor setup, recovery codes, API tokens you created, invitations you sent, cookie choices, and website download records under your email address. Queued and logged emails in the email program are removed as well; an unsubscribe you made is kept as a bare address so you are never mailed again.
You will be asked to prove it is you:
| Account | Confirmation |
|---|---|
| Password sign-in | Current password |
| Password sign-in with two-factor on | Current password and a code from the authenticator app |
| Google or GitHub sign-in with two-factor on | A code from the authenticator app |
| Google or GitHub sign-in, no two-factor | Type your email address |
What happens to your workspaces
| Situation | Result |
|---|---|
| You are the only member | The workspace is deleted with all its content |
| Other members exist and at least one other owner | You leave; the workspace continues |
| Other members exist, you are the only owner | Deletion is refused until you make another member an owner (Settings → Members) or remove the other members |
The refusal lists the workspaces in question, so you know where to go.
What stays
Entries you made in a workspace's audit log stay for their 180-day
retention, without your email address. The deletion itself is recorded
as USER_DELETED with a hash of the address, which lets us confirm
later that a deletion happened without keeping the address. Backups
expire on a rolling 30-day schedule, so a deleted account is gone from
them within 30 days.
Billing records for a workspace are kept as long as accounting law requires; they belong to the workspace, not the account.
Requests we handle by email
Anything the product does not let you do yourself (a correction we have to make by hand, a restriction request, an objection, a question about a specific record) goes to support@qamentor.com with the subject "Privacy request". We answer within 30 days and may ask you to write from the account's email address to confirm it is you. The Privacy Policy lists your rights in full.
For workspace admins: end-user requests
If a person whose data appears in your workspace content (an end user of the product you evaluate) exercises their rights with you, the product gives you what you need:
- Search and delete: dataset items and traces can be deleted individually or in bulk; deleting a project or workspace removes everything under it.
- Export: datasets, runs and reports export from their pages.
- Retention: runtime traces expire after 6 months; everything else lives as long as the workspace does.
Where that is not enough, the DPA commits us to assist within 10 business days. Requests that reach us directly about your content are forwarded to you rather than answered on the merits.
