Privacy Policy
Last updated 1 October 2026
This policy explains what Burhan, operated by [Operator legal name], stores about you and the people in your workspace, why, and for how long. It is written to be read, not skimmed; if anything is unclear, write to hello@useburhan.com.
1. Account data
- What: your name, email address, password (hashed by our sign-in provider; we never see it), workspace name, and who invited whom.
- Why: to sign you in, run your workspace and contact you about the service or your bill.
- How long: until you delete your account. Billing records are kept as long as tax law requires.
2. What you upload and configure
- Documents (specs, stories, PDFs): stored as extracted text so Burhan can read them and draft journeys. Kept until you remove the document or delete the project.
- Journeys and their edit history (who changed what, when).
- Environments: the URLs you ask us to test.
- Test accounts: the username and password of each test account. Passwords are encrypted at rest with a key held only on our servers, are never shown back in the app, and are typed into the application under test only by the runner, never shown to the AI. Deleted when you delete the account, project or workspace.
- Your Anthropic API key, if you add one: encrypted at rest the same way, shown only by its last four characters, used only to make AI calls for your workspace, removable at any time.
3. What a run records
When Burhan walks a journey it keeps evidence so a person can check the result:
- a screenshot at the end of each step and a video of the whole run;
- the application's API calls during the run (URL, status, timing, and response bodies, with fields that look like tokens, passwords or keys replaced by “[hidden]” before storage);
- the page outline the AI saw, the AI's notes, console errors, and timing and cost.
This evidence can include whatever your application shows to the test account, such as test customers' names. Use test data in test environments. Evidence is kept with the run until the run, journey, project or workspace is deleted. Videos and screenshots are stored in a private bucket and served only through short-lived signed links to members of your workspace.
4. AI processing
To draft journeys and judge results, we send relevant parts of your documents, journeys and the page the runner sees to Anthropic's API. Anthropic processes it under its API terms and, by its stated policy at the time of writing, does not train models on API inputs and outputs. If you use your own Anthropic key, those calls happen under your own agreement with Anthropic. We log each call's purpose, model, token counts and cost, but not its content.
5. Payments
Payments are handled by Stripe. We never see or store your card number; we keep Stripe's customer and subscription identifiers, your plan, and invoice records.
6. Who else processes your data
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Database, file storage (videos, screenshots) and sign-in | EU / US (per project settings) |
| Vercel | Hosting the web app | Global edge, US origin |
| Railway | Running the test browser (runner worker) | US |
| Anthropic | AI that reads documents, drafts journeys and judges results | US |
| Stripe | Payments and invoices | US / EU |
We do not sell your data and do not use it for advertising. We share it only with these providers, to run the service, or when the law requires.
7. Cookies
We use only the cookies needed to keep you signed in and to remember which workspace you are in. No advertising or cross-site tracking cookies.
8. Where data is stored
Your data is stored by the providers above in the regions listed. If you need your data kept in a specific region, tell us before you start; we will say whether we can do it.
9. Your rights
- Access and export: everything in your workspace is visible in the app; ask us for an export and we will provide one.
- Correction: edit your profile, documents and journeys in the app.
- Deletion: deleting a project removes its documents, journeys, runs and evidence; deleting your account removes your personal data. Backups are overwritten within 30 days.
- Complaint: if you are in the EU/EEA or UK you can complain to your data protection authority; we would rather you wrote to us first.
10. Security
Encrypted transport everywhere, credentials and keys encrypted at rest, access limited to members of your workspace, private storage with signed links, and secrets redacted from recorded API responses. If we learn of a breach affecting your data we will tell the workspace owner without undue delay.
11. Children
Burhan is for businesses and is not directed at children under 16.
12. Changes
We will email the workspace owner about material changes to this policy before they take effect.
Contact
[Operator legal name] · hello@useburhan.com · established in [Country]