AssertAssert

Privacy Policy

Last updated: 4 April 2026

1. Who we are

Assert is a product of Pixel Funnel Ltd, a private limited company incorporated in England and Wales (company number 8497619). Our registered address is available on request. You can contact us at support@assert.click.

2. What data we collect

Account data

When you create an account we collect your name, email address, and password (stored as a one-way hash). If your organisation is on a paid plan we also collect billing address and telephone number for invoicing purposes.

Usage data

We store the test scenarios, run results, and uploaded Markdown files you create within the platform. This data is used to provide the service and display results in your dashboard.

Analytics data

On our marketing site (assert.click) we always use a privacy-minimised PostHog setup to measure aggregate page usage and capture client-side fault events so we can improve the site. If you accept our enhanced analytics banner, we also enable richer PostHog analytics features such as cookies, broader interaction capture, session replay, heatmaps, and browser diagnostics. We do not use analytics data for advertising. On our dashboard we use PostHog product analytics after sign-in to understand feature usage, navigation, and reliability so we can improve the service.

3. How we use your data

  • To provide, operate, and improve the Assert service
  • To send transactional emails (account confirmation, password reset, run notifications)
  • To process payments via Stripe
  • To monitor platform health and diagnose errors via Sentry
  • To comply with legal obligations

We do not sell your data to third parties. We do not use your data for advertising.

4. Third-party services

We use the following third-party processors:

  • Stripe — payment processing. Stripe Privacy Policy
  • Resend — transactional email delivery
  • Sentry — error monitoring (no personal data in error reports)
  • DigitalOcean — cloud infrastructure, hosted in the EU (London region)
  • PostHog — privacy-minimised marketing analytics, optional enhanced marketing analytics on consent, and product analytics

5. Cookies

Our marketing site always uses a privacy-minimised analytics mode without persistent PostHog cookies or local storage. If you accept enhanced analytics, we enable PostHog cookies and related browser storage so we can run richer analytics features. If you disable site analytics entirely, we store only the local preference needed to remember that objection. Our dashboard uses a session cookie (httpOnly, secure) strictly necessary for authentication and PostHog analytics in memory for the active browser session without persistent browser storage.

6. Marketing site analytics controls

You can accept or decline enhanced analytics through the banner shown on the marketing site, and you can disable or re-enable all marketing-site analytics at any time using the control below or the footer link shown on every page.

Site analytics controls

Marketing-site analytics are currently enabled. Enhanced analytics are disabled. We use local preferences to remember these choices.

7. Data retention

We retain your account data for as long as your account is active. Run results and test files are retained for as long as they are needed to provide the service, unless they are deleted sooner by your organisation. When a workspace owner or super admin deletes a user or organisation in-app, the related active-system data is removed as part of that deletion workflow.

Some information may be retained for longer where required for legal obligations, accounting, fraud prevention, security, the establishment or defence of legal claims, or until backup media rotates out in the normal course of operations.

8. Your rights (UK GDPR)

As a UK resident you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Object to or restrict processing
  • Data portability

Workspace owners and super admins can delete users or entire organisations from within the Assert app. Deleting a user removes their account data from active systems and unlinks their ownership from shared workspace records. Deleting an organisation removes the organisation's projects, test files, runs, API keys, AI logs, and locally stored run artifacts from active systems.

To exercise any of these rights, or if you need help with a request that cannot be completed in-app, email us at support@assert.click. We will respond in line with applicable data protection law.

9. Security

All data is transmitted over TLS. Passwords are hashed using bcrypt. API keys are stored as hashed values and are never retrievable after creation. We use industry-standard security practices and monitor for vulnerabilities.

10. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of the service after changes constitutes acceptance.

11. Contact

For privacy-related queries contact us at support@assert.click.