Privacy Policy

Last updated: July 2026

1. Introduction

The Service is operated by M00N Report LLC, 2108 N St, Ste N, Sacramento, CA 95816, USA ("M00N Report", "we", "us"). M00N Report LLC is the data controller for the personal data described in this policy, except where stated otherwise in the Our Roles section.
We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use M00N Report ("Service").

2. Our Roles (Controller vs. Processor)

For account, billing, authentication, and usage data of registered users, M00N Report acts as the data controller.
For test results, test cases, and uploaded artifacts submitted by your organization ("Customer Data"), M00N Report acts as a data processor on behalf of your organization, which remains the controller of that data. We process Customer Data only on your organization's instructions, as set out in our Data Processing Agreement (DPA), available on request from privacy@m00nreport.com.

3. Information We Collect

We collect the following categories of information to provide and improve the Service:
Account Information: When you create an account, we collect your email address, name, organization details, and a securely hashed version of your password.
Social Login Data: If you sign in using a social login provider (e.g., Google), we collect your provider user ID, email address, display name, and avatar URL. This data is stored in association with your account to facilitate seamless authentication.
SSO Data: If your organization uses Single Sign-On (SSO), we collect your SSO provider ID and subject identifier. Supported SSO providers include Okta, Azure AD, Google Workspace, Auth0, and custom OIDC-compliant identity providers configured by your organization.
Test Data & Artifacts: We store test results, test cases, launches, runs, steps, errors, and related metadata that you submit through the Service. Artifacts - including screenshots (PNG/JPEG), videos (WebM/MP4), Playwright trace files, logs, and any other uploaded files - are stored in encrypted object storage (AWS S3 for the cloud service; S3-compatible storage such as MinIO for self-hosted deployments).
Jira Integration Data: If your organization enables the Jira integration, we collect and store your Atlassian account ID, Jira cloud ID, site URL, site name, and OAuth tokens (encrypted at rest). We also cache issue metadata such as summaries, statuses, project keys, and issue types to provide a seamless integration experience.
Audit Log Data: We record IP addresses and user agents for SSO authentication events, as well as user actions on test cases, to maintain a complete audit trail for security and compliance purposes.
Usage Data: We automatically collect information about how you interact with the Service, including access times, pages viewed, and features used.
Device Information: We collect information about the device and browser you use to access the Service, including IP address, browser type, and operating system.
Notification Configuration: If your organization configures notifications, we store SMTP credentials (encrypted at rest), webhook URLs for Slack, Microsoft Teams, Discord, and Telegram, as well as recipient email lists used to deliver test run notifications.

4. How We Use Your Information

We use the information we collect to:
  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments, questions, and requests
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent security incidents
  • Comply with legal obligations
Legal bases: Where the GDPR applies, we process personal data on the following legal bases: performance of a contract - providing the Service, processing transactions, and responding to support requests (Art. 6(1)(b)); our legitimate interests - service security, fraud and abuse prevention, audit logging, and product improvement based on aggregated usage (Art. 6(1)(f)); legal obligation - keeping tax and accounting records (Art. 6(1)(c)); and consent where we ask for it, which you can withdraw at any time (Art. 6(1)(a)).

5. Data Sharing

We do not sell or "share" personal information as defined by the California Consumer Privacy Act, and have not done so in the preceding 12 months. California residents may exercise the rights described in the Your Rights section at privacy@m00nreport.com; we do not discriminate against you for exercising them.
We may share your information with:
  • Atlassian/Jira: When the Jira integration is enabled by your organization, test details, error messages, and links are sent to Atlassian's servers to create and link Jira issues. This data sharing is governed by Atlassian's Privacy Policy.
  • Social Login Providers: OAuth authentication flows are conducted with Google (and future providers such as GitHub and Microsoft). These flows are governed by the respective provider's privacy policies.
  • SSO Identity Providers: OIDC/SAML authentication flows are conducted with identity providers such as Okta, Azure AD, Google Workspace, Auth0, or custom providers configured by your organization.
  • Notification Services: Test run summaries and notification data are sent to Slack, Microsoft Teams, Discord, Telegram, or custom webhook endpoints configured by your organization.
  • Email Services: Notification emails are sent via SMTP servers configured by your organization.
  • Service Providers: Third parties that help us operate the Service, including hosting and payment processing providers.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets.
  • Legal Requirements: When required by law or to protect our rights.
  • With Your Consent: For any other purpose with your explicit consent.

6. Third-Party Integrations

The Service supports optional third-party integrations. Each integration is governed by the applicable third party's own privacy policy and terms of service.
Jira/Atlassian: When enabled by your organization administrator, test result data (including error details and links) flows to Atlassian's servers to create and manage Jira issues. OAuth tokens used for this integration are encrypted at rest using AES-256-GCM and are revoked and deleted when you disconnect the integration. Cached issue links and site metadata are retained to support reconnection, unless you choose full removal, which permanently deletes all cached Jira data. See Atlassian's Privacy Policy.
Social Login: When you sign in via a social login provider (e.g., Google), we receive your email, display name, and avatar URL from the provider. You can unlink a social login from your account settings at any time. See Google's Privacy Policy.
Single Sign-On (SSO): SSO is organization-managed. When your organization configures SSO, authentication flows pass through your identity provider (Okta, Azure AD, Google Workspace, Auth0, or a custom OIDC provider). We receive only the claims necessary for authentication and profile information from your IdP.
Notifications: When your organization configures notifications, test run summaries are sent to the configured webhook endpoints (Slack, Teams, Discord, Telegram) or via SMTP email. The data sent includes test run names, pass/fail counts, and links back to M00N Report.
AI Assistants (MCP): Organizations may connect third-party AI assistants to the Service via MCP API keys; data queried through such a connection is transmitted to whatever AI provider the connecting user has chosen, under that provider's terms - this connection is initiated and controlled by the user.
Users can revoke integration access at any time through their account or organization settings.

7. Data Retention

We retain data for the following periods, by category:
  • Account and organization data: retained for the life of the account. When you delete your account, it is removed from active systems within 30 days; residual copies in encrypted backups expire on our standard backup rotation schedule.
  • Test data and artifacts: retained per your plan's retention limit (Free plan: 30 days; paid plans: up to 365 days as stated on the pricing page) or until deleted by you.
  • Canceled or lapsed subscriptions: data is retained for 90 days after cancellation, with warning emails sent around day 60 and day 75, and is then permanently deleted.
  • Audit logs (including IP addresses): retained for up to 12 months.
  • Billing and invoice records: retained as long as required by tax and accounting law.
Organization owners can delete their organization and all associated data directly in the app (Settings), in addition to contacting privacy@m00nreport.com.

8. Data Security

We implement appropriate technical and organizational measures to protect your data, including:
  • Encryption of data in transit (TLS) and at rest
  • AES-256-GCM encryption for stored integration credentials (such as Jira OAuth tokens and SMTP passwords)
  • Bcrypt hashing for user passwords
  • Presigned URLs with 24-hour expiry for secure artifact access
  • Ongoing dependency review and security patching
  • Access controls and authentication requirements
  • Row-level security (RLS) for multi-tenant data isolation
In the event of a personal data breach affecting your data, we will notify affected organizations without undue delay, and where we act as processor we will support controllers in meeting their own notification obligations, consistent with the GDPR's 72-hour standard.

9. Your Rights

Depending on your location, you may have the right to:
  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Request data portability
  • Withdraw consent at any time
To exercise these rights, please contact us at privacy@m00nreport.com.
We respond to requests within one month, as required by the GDPR. If you are in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.

10. Local Storage and Tracking Technologies

M00N Report uses browser local storage and session storage - not cookies - to provide core functionality. The following storage keys are used:
Strictly Necessary (Authentication):
  • m00n_auth_token - JWT authentication token to keep you signed in
  • m00n_auth_user - Cached user profile for the current session
Functional (UI Preferences):
  • m00n_selected_project - Last selected project
  • Other UI preference keys for layout and display settings
Session Storage (Temporary):
  • m00n_oauth_pending - Temporary state during OAuth login flows
No third-party tracking cookies or analytics are currently used by M00N Report. We do not use Google Analytics, Mixpanel, or any similar tracking services.
If analytics or tracking technologies are added in the future, we will update this policy and obtain your consent before activating any non-essential tracking.
For more details, see our Cookie Policy.

11. Data Processing and Sub-Processors

To deliver the cloud Service, we use the following sub-processors:
  • Amazon Web Services, Inc.: Cloud infrastructure, database, and artifact storage (United States, us-east-1 region). Artifact storage for the cloud service runs on AWS S3; self-hosted deployments use S3-compatible storage (such as MinIO) on the customer's own infrastructure.
  • Stripe, Inc.: Payment processing (United States).
  • Google LLC: Transactional email delivery via Google Workspace SMTP, and OAuth sign-in (United States).
System and transactional email for the cloud service is delivered via our email provider (Google Workspace SMTP). Organizations may optionally configure their own SMTP server or Gmail integration, in which case email is delivered through the organization's own provider.
We will provide at least 30 days notice before adding or replacing a subprocessor (via email or in-app notice), during which your organization may object on reasonable data-protection grounds.
For self-hosted deployments, all data processing occurs on your own infrastructure. Licensed self-hosted instances periodically contact our license server to validate the subscription, transmitting the license token, an instance identifier, hostname, application version, and active user count. No test data leaves the customer's infrastructure.

12. Sensitive Content in Artifacts

Screenshots, videos, Playwright trace files, and other artifacts uploaded to the Service may contain personally identifiable information (PII) or other sensitive data from the applications under test. Please be aware of the following:
  • M00N Report does not scan, analyze, or inspect the content of uploaded artifacts
  • Users and organizations are responsible for ensuring that uploaded artifacts comply with their own data protection policies and applicable regulations
  • Artifacts are isolated per organization using row-level security (RLS) and accessed exclusively via presigned URLs with limited expiry
  • We recommend reviewing artifacts before upload to ensure no unauthorized sensitive data is included

13. Self-Hosted Deployments

For self-hosted deployments, your test data remains on your infrastructure. Licensed self-hosted instances periodically contact our license server to validate the subscription, transmitting the license token, an instance identifier, hostname, application version, and active user count. No test data leaves your infrastructure.

14. International Data Transfers

The Service is hosted on Amazon Web Services in the United States (us-east-1 region). If you are located in the EEA, UK, or Switzerland, your personal data is transferred to the United States. We rely on the following safeguards: Amazon Web Services is certified under the EU-US Data Privacy Framework, and we offer the European Commission's Standard Contractual Clauses (SCCs) to customers through our Data Processing Agreement. A copy of the relevant safeguards can be requested at privacy@m00nreport.com.

15. Children's Privacy

The Service is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of changes by posting the new policy on this page and updating the "Last updated" date. For material changes we will notify registered users by email or in-app notice before the changes take effect.

17. Contact Us

If you have any questions about this Privacy Policy, please contact us at:
M00N Report LLC
2108 N St, Ste N, Sacramento, CA 95816, USA
Email: privacy@m00nreport.com
We have not appointed a Data Protection Officer, as we are not required to; privacy inquiries are handled at privacy@m00nreport.com.