Legal
Privacy Policy
Effective 26 August 2026
TryCase tests pull requests in isolated environments and returns verdicts, screenshots, and demo videos. This policy explains what we collect, why we use it, and the choices available to you. “TryCase,” “we,” and “us” refer to the service at trycase.dev. Contact us at ben@trycase.dev.
Information we collect
- Account information such as your name, email address, sign-in identity, workspace membership, and authentication events.
- GitHub installation, repository, pull-request, commit, and review information needed to start tests and publish results.
- Test data such as commands, logs, browser output, screenshots, videos, traces, scenarios, verdicts, artifacts, and resource usage.
- Encrypted repository secrets and test credentials that you choose to provide. Product interfaces expose their names, not their stored values.
- Billing plan, allowance, transaction, invoice, and subscription status. Payment card details are handled by Stripe and are not stored by TryCase.
- Operational information such as IP address, user agent, timestamps, error reports, security events, and service logs.
How we use information
We use information to authenticate users; connect repositories; plan, run, and review tests; create proof; publish GitHub checks and comments; manage subscriptions and allowances; prevent abuse; improve reliability; and provide support.
TryCase does not sell your personal information or use your private repository code to train general-purpose AI models.
Code, environments, and proof
Repository code and selected files are copied into isolated test environments. Runtime disks and processes are designed to be removed after a run stops or expires. Control-plane records and proof—such as logs, screenshots, videos, scenarios, verdicts, and audit history—may remain so you can review results and so we can operate the service.
Proof can contain information displayed by the application under test. Use non-production data and dedicated test accounts where possible, and treat downloaded or shared proof according to its contents.
Secrets
Repository secrets are encrypted before storage and made available only to authorized test environments. They are not committed to your repository or intentionally shown to testing agents. Known values are redacted from managed logs where possible, but redaction cannot prevent your own application or scripts from displaying a secret. Use scoped, revocable test credentials and rotate anything you suspect was exposed.
Service providers and sharing
We use service providers including WorkOS for authentication, GitHub for repository integration, Convex for application data, Stripe for payments, cloud infrastructure for isolated test execution, and AI providers selected by TryCase or connected by you. They process data only as needed to provide their services. A connected AI subscription or API key is also governed by that provider’s terms and privacy policy.
We may also disclose information when required by law, to protect users or TryCase, during a business transaction, or when you direct us to share it—for example by publishing a result to GitHub.
Retention, security, and your choices
We retain account, billing, proof, and operational records for as long as needed to provide the service, resolve disputes, meet legal obligations, and protect the platform. You can disconnect GitHub, remove repository access, and request access, export, correction, or deletion of personal data by emailing ben@trycase.dev.
We use access controls, encrypted secrets, isolated test environments, and audit records, but no system is perfectly secure. Report security concerns to ben@trycase.dev.
Changes
We may update this policy as TryCase changes. We will change the effective date and provide additional notice when required.