Testaro
FeaturesScreensSecurity
Add to Azure DevOps
← Back to home

Privacy Policy

Last updated: 2 September 2026

Testaro is an Azure DevOps extension for test management. Your test data stays inside your own Azure DevOps organisation. Testaro does not run a server that stores your content, does not sell or share your data, and AI features are opt-in and use your API key to call your AI provider directly.

What data Testaro handles

  • Test-management content you create — test cases, steps, suites, runs, results, configurations, shared steps, and exploratory sessions. This is stored in the Azure DevOps Extension Data Service within your own organisation/project. Testaro never receives a copy.
  • Work-item references — Testaro reads the Azure DevOps work items you link, using your existing Azure DevOps session, to show titles and states for traceability. Read-only.
  • AI provider key (optional, bring-your-own-key) — if you use the AI features, your key is held in browser memory for the session only. It is never persisted, never logged, and never sent to Testaro. AI requests go from your browser directly to the provider you configure.
  • Company-managed AI (optional) — if your admin configures a shared company key, it is stored server-side and never returned to the browser; requests are proxied with a per-user cap. Users never see or enter the key.

Optional usage statistics (off by default)

Testaro can send anonymous, aggregate usage statistics so we know which features are worth improving. It is off unless a project administrator turns it on in Testaro's Settings, and turning it off stops the sending immediately.

  • What is sent, if you turn it on: the Testaro version; a one-way SHA-256 hash of your Azure DevOps organisation id and project id (computed in your browser — the hash cannot be reversed back to an id or a name, and we never receive the id itself); the date the counts are for; and counters of how many times anonymous feature keys were used that day (for example “the overview screen was opened 3 times”).
  • What is never sent: organisation or project names, user names or emails, test cases, steps, results, comments or any other test content, work items, AI keys or prompts, and no free text of any kind. We do not retain your IP address or user agent with the statistics.
  • What it is used for: only to decide what to build and improve next. It is never sold, shared, or used to identify a person, a team, or a customer, and it is not accurate enough to try.
  • Retention: the raw daily counter records are kept for 13 months and then deleted.

What Testaro does not do

  • No Testaro-operated database holds your test content.
  • No analytics or telemetry is sent to third parties. The optional usage statistics above go only to Testaro, and only if an administrator switches them on.
  • No selling, renting, or sharing of customer data.

Data location, retention, and deletion

  • Location: your Azure DevOps organisation (Extension Data Service), governed by your Microsoft / Azure DevOps data-residency settings.
  • Retention: for as long as you keep it; Testaro adds no separate retention. The only exception is the optional usage statistics above (if switched on), whose daily counter records are kept for 13 months.
  • Deletion / export: you can delete any item in-app, and read or export everything via the Testaro API client or Azure DevOps' own Extension Data REST API. Uninstalling the extension leaves the data in your org — you control its removal.

Sub-processors

  • Microsoft Azure DevOps — hosts the extension and stores your data (your existing relationship).
  • Your chosen AI provider (only if you enable AI) — receives the prompts you send, under your own agreement with that provider.

Contact

Questions about this policy or your data? Email support@baytekdev.com.

Testaro© 2026 Testaro · Baytek
SecuritySupportMarketplace