Last updated: 2026-09-09
Req2QA ("we", "us") operates req2qa.com, a requirements-to-test-coverage tool for software QA teams. Req2QA is a registered business name of Kalyan Nagelli, ABN 56 181 932 896. This policy explains what we do with the files and information you submit when you use the service.
When you run an analysis, we temporarily process the requirements document, project brief, and process-flow diagram(s) you upload, along with the application name and any optional notes you provide, in order to generate your report. We also record your access code, the client name associated with it, and basic run metadata (date, application name, filename) in a lightweight internal log for account administration.
We do not sell your data. We do not use your uploaded documents to train any AI model. Your files are not retained after processing — only the resulting report and workbook are kept, and only for a limited time (currently 7 days from generation, via a private, time-limited link).
To generate your report, the content of your uploaded documents is sent to Anthropic's Claude API for analysis. Anthropic acts as a data processor for this purpose under its own API terms and data-handling commitments, which are published at anthropic.com. No other third party receives your document content.
Uploaded source documents are used only for the duration of processing and are not stored afterward. Generated reports and workbooks — including any screenshots captured during a live-execution run — are retained for up to 7 days to allow you to download them, then automatically deleted.
To let you find a past run again (for example, if you closed the browser before saving your report link), we keep a lightweight run history for each access code — the date, application name, run type, and an optional name/initials you choose to enter — for up to 30 days, after which it is automatically deleted. This history is reachable only by entering the access code it belongs to, via Run History; it does not contain your uploaded documents, requirements, or report content, and any optional initials you enter are used solely to let you filter the list to your own runs and are never verified as an identity.
Separately, we keep an internal operational log of each run (what happened, step by step, and the outcome) for up to 90 days, used only for troubleshooting an issue you report to us. This log never contains your login credentials, any text entered into a form field during execution, or the content of your uploaded documents. For a live-execution run, this log also retains a cryptographic fingerprint (a SHA-256 hash) of each screenshot — not the image itself — for the same 90 days; this lets us verify that a screenshot you later send us is authentic and unmodified, without our needing to hold the image itself beyond the 7-day window above. This troubleshooting log is accessible only to us, never to any client, and is not linked from or reachable through the application itself.
We use a cookieless, privacy-respecting analytics service (Plausible) to see aggregate traffic to req2qa.com — page views and referring sources only. It does not use cookies, does not track you across other websites, and does not collect any personally identifiable information.
Access to the service requires a private access code issued to your organization. All traffic is encrypted in transit (HTTPS). Download links to your reports are cryptographically signed and expire automatically. See our Security Overview for more detail.
You can request deletion of your run history or ask questions about how your data is handled by contacting us at kalyan@req2qa.com.
We will note material changes to this policy here, with an updated "last updated" date above. Continued use of the service after a material change constitutes acceptance of the revised policy.