Legal

Privacy Policy

Last updated 22 August 2026. What we collect, why we collect it, and the rights you have over it, in plain English.

1. Who we are

SuperGorilla is operated by Uzair Hussain Sheikh, trading as SuperGorilla, who is the data controller for the personal data described here. Questions, requests and complaints all go to support@supergorilla.ai.

2. This website tracks nothing

The marketing site you’re reading sets no cookies and runs no analytics or tracking scripts. If you just browse, we collect nothing about you.

3. What we collect when you use the service

  • ·Account details: your name, email address and team membership.
  • ·Billing information: handled by Stripe, our payment processor. We never see or store your card details.
  • ·Repository and application data: the code and running application needed to perform the tests you configure.
  • ·Test credentials: the accounts you provide for agents to sign in with, stored encrypted.
  • ·Run artifacts: recordings, screenshots, console and network logs produced by your test runs.
  • ·Memory: what the service learns about your application across runs, so tests improve over time.
  • ·Support correspondence: emails you send us.

4. Why we collect it

To provide the service you signed up for (performance of a contract): running tests, producing reports, remembering your app between runs, and billing. To keep the service secure and reliable, and to respond when you contact us (legitimate interests). And to meet legal obligations, such as tax records. We don’t sell personal data, and we don’t use your data for advertising.

5. AI model providers

Test runs are powered by third-party AI model providers. You choose which model your tests use, and data needed to run a test is processed by that provider under their terms. If you bring your own API key, model traffic runs through your own provider account and your own agreement with them, rather than ours.

6. Who else sees data

Service providers who help us run SuperGorilla, each processing data only as needed to provide their service to us:

  • ·GitHub: repository access, pull request events and posting reports, via the GitHub App you install.
  • ·Google Cloud: cloud infrastructure where test runs execute.
  • ·Vercel: application and website hosting.
  • ·Neon: database hosting.
  • ·Cloudflare: networking, content delivery and security.
  • ·Trigger.dev: background job orchestration for runs.
  • ·Stripe: payment processing.
  • ·The AI model provider you choose: see section 5.

We’ll keep this list current as our infrastructure changes. Beyond these, we disclose data only where the law requires it. We don’t sell personal data.

7. How long we keep it

Account data lasts while your account does. Run artifacts and memory are kept for your team’s use and are deleted on request; email us or close your account. Billing records are retained as long as tax law requires. Some providers we use may process data outside the UK; where they do, transfers rely on appropriate safeguards such as the UK’s international data transfer mechanisms.

8. Security

Test credentials are stored encrypted, repository access is scoped to what a run needs, and runs execute in isolated environments that are destroyed afterwards. Guardrails you set bound what agents may do inside your application. No system is perfectly secure; if we learn of a breach affecting your data, we’ll tell you.

9. Your rights

Under UK data protection law you can ask for access to your personal data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interests. Email support@supergorilla.ai and we’ll respond within a month. If you’re unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ico.org.uk).

10. Changes

If this policy changes materially, we’ll tell you by email or in the product before the change takes effect.