Privacy Policy
Last updated: 30 July 2026
1. Who we are
MockingbirdAI (an Australian partnership, ABN 83 173 118 376) provides AI-powered end-to-end testing for web applications at mockingbirdai.com.au and app.mockingbirdai.com.au (the “Service”). This policy explains what personal information we collect, why, and how we handle it. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
2. What we collect
Account information
Your name, email address, password (stored as a hash by our authentication provider), and optionally a phone number and profile photo. For company workspaces, the company name and any workspace logo you upload.
Product data
The tests you write (plain-English prompts and target URLs), test run results, and quality metrics.
We also capture a record of what happened during each run: session recordings of the browser session, screenshotsof each step, run logs, and per-step telemetry (the page address and title, content the agent read from the page, and the agent’s own reasoning about what it was doing). All of this shows your application as the test agent saw it, so it may include Customer Content and personal information displayed by your application during a run. You are responsible for ensuring you have authority to test, upload, and record any personal information contained in the applications you test.
Test credentials
If you attach credential modules (logins, payment card details for test environments, MFA secrets), we store them encrypted and use them only to execute the tests you configure. You control what is stored and can delete modules at any time. You must not store credentials for accounts or systems you are not authorised to use.
Billing information
Payments are processed by Stripe. We never see or store your full card details - we hold your Stripe customer reference, subscription status, and usage counts (test runs per month) used to calculate billing.
Communications
Messages you send via the contact form (name, email, message, and optionally company and phone) and feedback you submit in the app.
Technical information
Error and performance telemetry (via Sentry) and IP addresses used transiently for security controls such as rate limiting. We do not run advertising or cross-site tracking.
3. How we use it
- To provide and operate the Service, including executing your tests.
- To bill subscriptions and metered usage.
- To respond to support requests and feedback.
- To secure the Service (fraud and abuse prevention, debugging, monitoring).
We do not sell personal information, and we do not use your data to train AI models.
4. Who we share it with
We use a small set of service providers to run the Service. Each receives only what its function requires:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, and file storage |
| Stripe | Payments and subscription billing |
| Browser Use | Cloud browser sessions, session recordings, and the live view of a running test |
| Resend | Transactional email |
| Sentry | Error and performance monitoring |
| Vercel | Application hosting |
| Anthropic | AI models (Claude) that execute plain-English test instructions during runs; not used by Anthropic to train models |
We may also disclose information where required by law. Beyond that, we do not share personal information with third parties.
5. Overseas disclosure
Some of the providers above store or process data outside Australia(primarily in the United States). We may disclose personal information to these overseas providers where necessary to provide the Service. We choose providers with strong security practices and contractual safeguards where available, but overseas recipients are not bound by the Australian Privacy Principles.
6. Security
All traffic is encrypted in transit. Test credentials are encrypted at rest. Test runs execute in isolated, ephemeral cloud browser sessions. Access to production systems is limited to the people who operate the Service. No system is perfectly secure; if we become aware of a data breach likely to cause serious harm, we will notify affected users and the OAIC as required by the Notifiable Data Breaches scheme.
7. Retention
Account and product data - including step screenshots, run logs, and per-step telemetry - is retained while your account is active. Session recordings are held by our cloud browser provider and expire after a limited period, after which the replay is no longer available. If you delete your account or ask us to, we delete your personal information within a reasonable period, except records we must keep by law (e.g. billing records).
8. Access, correction, and deletion
You can update your profile and workspace details in the app. For anything else - a copy of your data, a correction, or deletion - email admin@mockingbirdai.com.au and we will respond within 30 days.
9. Cookies and embedded content
We use only essential cookies: authentication session cookies on the app. The marketing site sets no cookies. We do not use advertising or analytics cookies, and we do not run cross-site tracking.
While a test is running, the app embeds a live view of the browser session served directly by our cloud browser provider (Browser Use). Your browser connects to that provider to display it, so the provider receives your IP address and may set its own cookies or equivalent storage for that frame. The live view appears only on a running test’s page.
10. Complaints
If you believe we have mishandled your personal information, contact us first at admin@mockingbirdai.com.au and we will investigate. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced by email or in the app. The date at the top reflects the latest revision.
12. Contact
Privacy questions: admin@mockingbirdai.com.au