Key featuresFeaturesPricingSecurityDocsChangelog
Log inStart for free

The issue tracker you use with your AI agent. Your agent fixes; QA Note keeps the record.

Made in Seoul · © 2026 QA Note
ProductKey featuresFeaturesPricingSecurityChangelog
ResourcesDocsMCP guideChrome Extension
CompanyBrandTerms of ServicePrivacy Policy

ffgg|CEO: Songwook Han

Business Registration No.: 746-54-00870[Verify]|E-Commerce License No.: 2024-Seoul Mapo-2178

Address: 5F, 26 World Cup buk-ro 6-gil, Mapo-gu, Seoul, Republic of Korea

Email: support@qanote.app|Hosting Provider: Vercel Inc.

© 2026 QA Note. All rights reserved.

Terms of ServicePrivacy PolicyCookie Policy

Privacy Policy

Effective: July 24, 2026

Table of Contents

  1. 1. Purpose of Processing Personal Information
  2. 2. Personal Information Collected
  3. 3. Retention and Use Period of Personal Information
  4. 4. Provision of Personal Information to Third Parties
  5. 5. Outsourcing of Personal Information Processing
  6. 6. Overseas Transfer of Personal Information
  7. 7. Rights and Obligations of Data Subjects
  8. 8. Procedures and Methods for Destroying Personal Information
  9. 9. Measures to Ensure Security of Personal Information
  10. 10. Installation, Operation, and Rejection of Cookies and Automatic Data Collection
  11. 11. Collection, Use, and Provision of Behavioral Information
  12. 12. Data Collection by Chrome Extension
  13. 13. Automated Decision-Making
  14. 14. Personal Information of Children Under 14
  15. 15. Privacy Officer
  16. 16. Chrome Web Store User Data Policy Compliance
  17. 17. Changes to This Privacy Policy

1. Purpose of Processing Personal Information

ffgg (에프에프지지, hereinafter "Company") processes personal information for the following purposes to provide QA Note. If a purpose changes, the Company will take any measures required by applicable law, including obtaining separate consent where required.

  • User registration and identification
  • Service provision and maintenance (QA annotation, issue tracking, screenshot capture, session replay)
  • AI-assisted issue drafting and analysis, report narrative drafting, and project code chat
  • Payment and settlement when paid billing is enabled, and cancellation or refund processing for existing payments
  • Customer support and complaint resolution
  • Statistical analysis for service improvement and new service development
  • Compliance with legal obligations

2. Personal Information Collected

The Company collects the following personal information for service provision:

Required Items:

  • Email address, name (nickname), password (not collected for social login)

Social Login:

  • Social account unique ID, email address, profile name

Automatically Collected During Service Use:

  • IP address, browser information (User-Agent), access time, device information, viewport size
  • Screenshot images (screens captured directly by the user, may contain personal information)
  • Session replay data (when the user activates this feature, DOM change records)
  • Console logs and network request logs, including limited request/response body text up to 2KB where available (automatic sensitive information filtering applied)
  • CSS selectors, selected element text, computed element styles, and React component tree information
  • JavaScript errors and stack traces (error messages, file locations, call stacks)
  • SPA route change records (in-page URL change history)
  • Framework/library detection information (React, Vue, Angular, etc. usage and version)
  • Performance metrics (Web Vitals: LCP, FCP, CLS, INP, TTFB, Navigation Timing, Resource Timing)
  • Environment information (accessibility settings, language/timezone, network connection status, GPU info, zoom level)
  • Optional storage and DOM snapshots (localStorage, sessionStorage, browser-accessible cookies, and rendered DOM outerHTML) only when enabled by the project and separately confirmed by the user

Payment:

  • Payment method information (when paid billing is enabled, processed through PortOne; the Company does not directly store full card numbers)
Note: Screenshots and session replay data may contain personal information displayed on the user's screen. The Company provides automatic sensitive information filtering for such data but does not pre-screen the content of materials directly captured by users.

3. Retention and Use Period of Personal Information

After an account deletion request, the Company provides a 30-day grace period for recovery and data transfer, then destroys account identifiers. The user may cancel the deletion request during the grace period.

Organization work records, including issues and reports, follow the organization's contract and plan retention policy. After account deletion, records may remain in de-identified form where necessary for other authorized organization members.

However, if retention is required by applicable laws, the information is retained for the legally mandated period:

  • Records of contracts or subscription withdrawal: 5 years (Electronic Commerce Act)
  • Records of payment and supply of goods: 5 years (Electronic Commerce Act)
  • Records of consumer complaints or dispute resolution: 3 years (Electronic Commerce Act)
  • Login records: 3 months (Protection of Communications Secrets Act)
  • Security audit records: 1 year (internal security and dispute-response policy; email addresses are not retained after account deletion)
Note: Work-record retention by plan: Solo 30 days, Pro 365 days, and Flex for the contract term followed by a 30-day download period after termination. Data past its retention period is automatically deleted and cannot be recovered.

4. Provision of Personal Information to Third Parties

The Company does not provide personal information to third parties without user consent, except as required by law.

If the user has configured integrations, data may be transmitted to the following external services:

  • GitHub — Issue synchronization (only when the user has configured the integration)
  • Slack — Notification delivery (only when the user has configured the integration)

5. Outsourcing of Personal Information Processing

The Company outsources personal information processing as follows for service provision:

Service ProviderOutsourced TasksRetention Period
PortOne Co., Ltd.Payment processing when paid billing is enabled; cancellation and refunds for existing paymentsStatutory e-commerce retention period or until the processing agreement ends
Cloudflare, Inc.R2 file storage and CDN deliveryApplicable plan or contract work-record retention period
Plus Five Five, Inc. (Resend)Account and notification email deliveryEmail data for 30 days
Anthropic, PBCIssue analysis and drafting from screenshots and annotationsUp to 30 days under the default API retention policy
OpenAI, LLCText analysis and drafting for issues, reports, and project code chatUp to 30 days under the default API retention policy
Supabase, Inc.PostgreSQL database hostingApplicable plan or contract period and the account-deletion grace period
Vercel, Inc.Web application hosting and request-log processingService period and provider log or backup policy
Functional Software, Inc. (Sentry)Error and performance monitoringConfigured project event-retention period, up to 90 days
Upstash, Inc.Rate limiting, abuse prevention, and short-lived cachingPer-key TTL, no longer than 24 hours

6. Overseas Transfer of Personal Information

Under Article 28-8(1)(3) of the Korean Personal Information Protection Act, the Company transfers personal information overseas as processing or storage necessary to perform the service contract. Transfers occur over TLS when the relevant feature or service request is used:

RecipientCountry / RegionItems TransferredPurposeTiming / MethodRetention Period
Anthropic, PBCUnited StatesIssue content, screenshots and annotations, and required technical metadataIssue analysis and draftingTLS transfer when an AI feature runsUp to 30 days under the default API retention policy
OpenAI, LLCUnited StatesIssue and report text, summarized technical metadata, and user-requested project code contextText analysis, narrative drafting, and code chatTLS transfer when an AI feature runsUp to 30 days under the default API retention policy
Cloudflare, Inc.United States and global network (R2 location hint: APAC)Screenshots, session records, and attachmentsFile storage and CDN deliveryTLS transfer on upload or retrievalApplicable plan or contract work-record retention period
Supabase, Inc.Seoul, South Korea (AWS ap-northeast-2; provider headquartered in the United States)Account, organization, issue, report, and other service dataPostgreSQL database hostingTLS transfer during service useApplicable plan or contract period and the account-deletion grace period
Vercel, Inc.United States and global CDNIP address, User-Agent, request path, and error or performance metadataWeb application hostingTLS transfer on service requestProvider log and backup policy
Plus Five Five, Inc. (Resend)United StatesEmail address, name, and outbound message contentAccount and notification email deliveryTLS transfer when an email is sentEmail data for 30 days
Functional Software, Inc. (Sentry)United StatesError message, stack trace, query-free request path, and performance metadataError and performance monitoringTLS transfer when an error or performance event occursConfigured project period, up to 90 days
Upstash, Inc.Seoul, South Korea (icn1; provider headquartered in the United States)Hashed or other identifiers derived from IP, account, or email values for rate-limit keys, and short-lived cache entriesRate limiting, abuse prevention, and cachingTLS transfer on service requestPer-key TTL, no longer than 24 hours
Note: Under the default commercial API policies of Anthropic and OpenAI, API data is not used for model training. A user may request suspension of overseas processing at privacy@qanote.app or avoid optional features. Refusing processing essential to hosting or authentication may limit use of the Service.

7. Rights and Obligations of Data Subjects

Users (data subjects) may exercise the following rights:

  • Request to access personal information
  • Request correction of errors
  • Request deletion
  • Request to suspend processing
Note: Rights may be exercised through account settings within the service or via email at privacy@qanote.app. The Company will take necessary measures within 10 days of receiving the request.

8. Procedures and Methods for Destroying Personal Information

The Company destroys personal information without delay when the retention period has expired, or when the processing purpose has been achieved and the information is no longer needed.

Destruction Procedures:

  • Information that must be retained under applicable law is access-restricted, retained for the required period, and then destroyed
  • After the 30-day account-deletion grace period, account identifiers and files attributable to the user are deleted; organization work records are de-identified or separately destroyed under the contract and plan policy

Destruction Methods:

  • Electronic files: Permanently deleted using methods that prevent recovery
  • Paper documents: Shredded or incinerated
  • Cloud storage (R2): Complete object deletion

9. Measures to Ensure Security of Personal Information

The Company takes the following measures to ensure the security of personal information:

  • Encrypted password storage (argon2id hashing algorithm)
  • Transport encryption (HTTPS/TLS 1.2 or higher)
  • Encryption at rest (AES-256-GCM)
  • Access control management and minimization (RBAC: Owner, Admin, Member, Viewer)
  • Personal information access logging and audit trails
  • Automatic masking of sensitive information (passwords, API keys, tokens, card numbers) in console logs and network requests
  • Regular security vulnerability assessments

10. Installation, Operation, and Rejection of Cookies and Automatic Data Collection

The Company uses httpOnly cookies for authentication and session management. Cookies for marketing or personal behavior tracking purposes are not used.

Cookies Used:

  • access_token — JWT access token (expires in 24 hours), for authentication
  • refresh_token — Refresh token (expires in 90 days), for session maintenance
  • NEXT_LOCALE, sidebar state, and recent organization — language and interface preferences (7 days to 1 year)

How to Reject Cookies:

  • You can block cookies through your browser settings.
  • However, blocking authentication cookies will prevent you from logging in to the service.

11. Collection, Use, and Provision of Behavioral Information

The Company may collect behavioral information through the session replay feature for QA purposes. This is collected only when the user has explicitly activated the feature.

Behavioral Information Collected:

  • Session replay: DOM changes, mouse movements, clicks, scroll event records
  • Console logs: JavaScript console output content
  • Network requests: API request/response metadata and limited request/response body text up to 2KB where available
  • User action logs: Click, input, navigation events

Purpose of Collection:

  • Support for QA issue reproduction and debugging
  • Understanding the context of bug occurrences

How to Opt Out:

  • You can disable the session replay feature in project settings.
  • You can toggle individual data collection on/off in Chrome Extension settings.
Note: Session replay data is accessible only to members of the relevant QA project and is not used for advertising or marketing purposes.

12. Data Collection by Chrome Extension

The QA Note Chrome Extension collects technical metadata solely for the purpose of creating QA reports. All data collection begins only after the user's explicit consent.

Prerequisites for Data Collection:

  • The user must be logged in to the Extension.
  • A project must be selected.
  • The user must explicitly consent on the data collection consent screen.
  • If all three conditions are not met, the Extension does not collect any data.

Technical Metadata Collected:

  • Console logs: console.log/warn/error output from the page (max 200 entries, most recent 100 upon issue submission)
  • Network requests: fetch/XMLHttpRequest request/response metadata and limited body text up to 2KB (max 50 entries, sensitive headers like Authorization/Cookie automatically masked)
  • JavaScript errors: Error messages, file locations, stack traces (max 50 entries)
  • SPA route changes: pushState/replaceState/popstate events (max 30 entries)
  • Framework detection: Presence of React, Vue, Angular, etc.
  • React component tree: Component names, props, state (depth 10, max 20 keys)
  • Performance metrics: Web Vitals (LCP, FCP, CLS, INP, TTFB), Navigation/Resource Timing
  • Environment information: Accessibility settings, language/timezone, network status, GPU, zoom level
  • Selected element metadata: CSS selectors, visible text snippets, layout, size, and computed style information
  • Optional storage/DOM snapshots: localStorage, sessionStorage, browser-accessible cookies, and rendered DOM outerHTML only when the project allows it and the user confirms a separate prompt

Data Storage and Transmission:

  • Collected data is temporarily stored in browser memory and is transmitted to the server only when the user submits an issue.
  • If no issue is submitted, the data is automatically deleted from memory when the page is navigated away from.
  • All server transmissions are encrypted via HTTPS.
  • The Extension does not sell collected data to third parties or use it for advertising purposes.

Sensitive Information Protection Measures:

  • Automatic masking of 13 types of sensitive headers in network requests including Authorization, Cookie, and API Key
  • Masking of 14 types of sensitive URL query parameters including token, password, and api_key
  • Masking of 13 types of sensitive fields in request/response bodies including password, credit_card, and ssn
  • Automatic masking of input fields during session replay
  • Automatic masking of sensitive input values during user action tracking
  • Sensitive-key and sensitive-value masking for optional storage and DOM snapshots
Note: To stop the Extension's data collection, log out from the Extension popup or disable/remove the Extension.

13. Automated Decision-Making

The Company uses AI technology to perform the following automated processing:

Automated Processing:

  • Issue annotation analysis: Automatically drafts and refines issue titles and descriptions based on screenshots, annotations, and technical metadata
  • Report narrative and project code chat: Generates drafts or responses from records and code context selected by the user

User Rights:

  • AI results are for reference only; final judgment is made by the user.
  • AI features can be disabled in project settings.
  • Data used for AI features is not used for Anthropic or OpenAI model training.
  • The Company does not finalize decisions that materially affect a user's rights or obligations solely from AI output.

14. Personal Information of Children Under 14

Due to the nature of the B2B SaaS service, the Company restricts service use by children under 14 years of age.

If a user is confirmed to be under 14, service registration is denied without the consent of a legal guardian, and any collected personal information is immediately destroyed.

15. Privacy Officer

The Company has designated a Privacy Officer to oversee personal information processing operations and to handle complaints and remedies related to personal information:

  • Service Operator: ffgg (에프에프지지), represented by Han Songwook
  • Business Address: 26, World Cup buk-ro 6-gil, Mapo-gu, Seoul, Republic of Korea (203-56 Donggyo-dong)
  • Business Registration Number: 746-54-00870
  • Mail-Order Business Registration Number: 2024-서울마포-2178
  • Privacy Officer: Han Songwook
  • Position: Representative
  • Privacy Contact: Seong Moonhee
  • Contact: privacy@qanote.app
Note: For personal information reports and consultations: Personal Information Infringement Report Center (privacy.kisa.or.kr / 118), Personal Information Dispute Mediation Committee (kopico.go.kr / 1833-6972), Supreme Prosecutors' Office Cyber Crime Division (spo.go.kr / 1301), National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)

16. Chrome Web Store User Data Policy Compliance

The QA Note Chrome Extension is distributed through the Google Chrome Web Store and complies with Google's Chrome Web Store User Data Policy.

QA Note's use and transfer to any other app of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Limited Use Compliance:

  • Collected data is used only for the Extension's single purpose (QA bug reporting).
  • Collected data is not used for advertising purposes.
  • Collected data is not sold or transferred to unrelated third parties.
  • Data is not used for creditworthiness assessment or loan qualification screening.
  • Data collection does not begin without the user's explicit consent.

17. Changes to This Privacy Policy

This Privacy Policy may be amended due to changes in laws, policies, or services. Any changes will be announced through in-service notices at least 7 days in advance.

Significant changes (addition of collected items, changes to third-party provision, etc.) will be announced at least 30 days in advance.