Privacy Policy
This policy explains how TestDuo processes information to operate reciprocal app-testing features, protect the service, and manage marketplace entitlements. It is written for the current TestDuo service and should be read together with the in-app notices and Terms of Use.
1. Scope, operator, and contact
TestDuo is a coordination service for Android developers and testers who choose to participate in reciprocal testing relationships. The service may allow accounts, developer profiles, app listings, test requests, active test sessions, evidence uploads, private messages, reputation signals, notifications, support communication, and optional one-time marketplace purchases.
Service operator / publisher: Codivo, as identified in the applicable app-store listing.
Privacy contact: codivo@yaani.com
For a request about a TestDuo account, use the email associated with the account where possible and include enough information for us to verify that the request is genuine.
2. Information we process
We process only the categories of information reasonably needed to provide, secure, support, and improve the current TestDuo service. Depending on what you choose to do, this may include:
- Account and profile information: an authentication identifier, account email supplied by the sign-in provider, anonymous/public username, selected avatar, language, settings, and profile statistics.
- App publishing information: app name, package identifier, store or testing link, icon, descriptive text, test notes, and information you choose to publish for other TestDuo users.
- Testing activity: test requests, matches, session dates, progress state, approvals, rejections, comments, reputation-related events, and technical records needed to enforce the testing workflow.
- Evidence and user content: screenshots, captions, messages, and other content you deliberately upload or send within a test relationship. This material can contain personal data or confidential information if you choose to include it.
- Device and service information: for signed-in users, we maintain one current diagnostic profile containing device manufacturer and model; Android version and API level; TestDuo version name and version code; screen resolution, density, and orientation; selected app language, device language, and time zone; notification-permission status; Firebase Cloud Messaging registration status; current connection type (for example, Wi-Fi, mobile, Ethernet, or VPN); and the most recent service-seen time. We use this profile to diagnose compatibility or notification-delivery issues, provide support, protect the service, and administer accounts. It is not visible to other TestDuo users.
- Country-only service signal: Cloudflare may provide an ISO country code with a request. We retain only the most recently observed country code and its timestamp in the diagnostic profile; we do not store a city, a location history, or precise location there.
- Data we intentionally do not collect in the diagnostic profile: IMEI, IMSI, telephone number, SIM serial number, contacts, precise location, Wi-Fi SSID or MAC address, installed-app inventory, or another stable hardware identifier. TestDuo does not store an IP address in this profile. Infrastructure providers may still process standard network information such as IP address and user-agent data in their security and request logs under their own policies.
- Marketplace and transaction information: selected product, entitlement state, Google Play purchase status, purchase-token hash, order-reference hash, refund or chargeback status, and a limited pseudonymous safety record needed to prevent duplicate delivery, refund abuse, or circumvention of marketplace restrictions. We do not receive or store your full payment-card number.
- Support communications: information you send when contacting us, including the contents of your message and any attachments you provide.
Do not upload secrets. Do not include passwords, private keys, API tokens, payment data, government identifiers, intimate content, medical information, or another person’s personal information in evidence or messages unless you have a lawful right to share it and it is genuinely necessary. In most cases, redact it instead.
3. Why we process information
We use the information above to:
- create and secure accounts and make TestDuo features work;
- show profiles and app listings to the people who need them to evaluate, request, or conduct a test;
- create, run, close, and administer reciprocal test sessions;
- store and present evidence, messages, and review decisions to the relevant participants;
- send requested or service-related notifications, including test, evidence, message, and account events;
- operate marketplace rights, verify Google Play purchases, prevent duplicate delivery, and handle refunds, chargebacks, or related restrictions;
- detect, investigate, prevent, and respond to fraud, abuse, unsafe content, service manipulation, security incidents, and violations of our rules;
- respond to support requests, enforce our agreements, and comply with legal obligations.
Where a legal basis is required, we generally rely on performance of our agreement with you, our legitimate interests in running and protecting TestDuo, your consent where required, and compliance with legal obligations. The appropriate basis can vary by jurisdiction and by the specific processing activity.
5. Cross-border processing
TestDuo uses cloud and platform providers whose infrastructure or support operations may be located in, or process information from, more than one country. As a result, information may be processed outside your country of residence. Where applicable, we use the safeguards and transfer mechanisms required or permitted by relevant law.
6. Retention, deletion, and account closure
We retain information for no longer than reasonably necessary for the purposes described in this policy, including operating an active test, maintaining security, resolving disputes, enforcing the rules, and meeting legal obligations.
- Profile, app, message, test, and diagnostic content: remains available for as long as needed to provide the relevant TestDuo feature. The diagnostic profile is a current record rather than a device or location timeline. Test-related messages and evidence may be removed from ordinary service access when a test ends, is deleted, or an account is closed, subject to the exceptions below.
- Account deletion: TestDuo provides an account-deletion flow. When completed, we remove or deidentify the account’s ordinary profile and operational content from active service records as designed by the deletion flow. Some content already shared with another participant may have been independently copied by that participant and cannot be recalled from their device or records.
- Limited safety, financial, and legal records: even after account deletion, we may retain a minimal, pseudonymous record where reasonably necessary to prevent fraud, detect repeated refund/chargeback abuse, preserve purchase integrity, enforce restrictions, resolve disputes, or comply with law. This can include hashed purchase or order references, a non-reversible account-security key, entitlement or restriction state, and event dates. It is not maintained as a public profile.
- Backups and logs: residual copies can remain in protected backups or security logs for a limited period before rotation or deletion.
7. Request account deletion outside the app
You can use the account-deletion flow available in the TestDuo app. If you cannot access the app, you may request deletion of your TestDuo account and associated data by emailing codivo@yaani.com with the subject “TestDuo Account Deletion Request”.
Please send the request from the email address associated with your TestDuo account where possible and include your TestDuo username if you know it. Do not send your Google password, payment details, private keys, or other sensitive credentials. We may request information reasonably necessary to verify that the request is genuine and to avoid deleting the wrong account.
After a verified request, we will process deletion or deidentification of ordinary account and operational content as described in Section 6. Limited pseudonymous security, fraud-prevention, transaction-integrity, dispute, backup, or legal-compliance records may be retained where reasonably necessary and permitted by law. Content independently copied by another participant cannot be recalled from that participant’s device or records.
8. Security
We use reasonable administrative, technical, and organisational measures designed to protect information in transit and at rest, limit access, and reduce misuse. No online system can guarantee absolute security. You are responsible for choosing a strong device lock, protecting your Google account, and avoiding the upload of unnecessary confidential information.
9. Your choices and rights
Depending on where you live and subject to applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing. You may also control some data directly in the app by editing profile details, managing published apps, deleting content where available, adjusting notification settings, or using account deletion.
To make a request, contact codivo@yaani.com. We may ask for information needed to verify your identity and authority. We may limit or decline a request where permitted by law, including where it would compromise another person’s privacy, security, legal rights, or the integrity of fraud-prevention and transaction records.
10. Children
TestDuo is designed for developers and testers, not for children. Do not use TestDuo if you are below the minimum age at which you can lawfully use this type of service in your country. We do not knowingly seek to collect personal information from children. If you believe a child has provided information to TestDuo, contact us so we can review the situation.
11. Changes to this policy
We may update this policy when TestDuo changes, when providers or laws change, or when a clarification is needed. We will update the effective date and, where appropriate, provide an in-app notice or other reasonable notice for material changes. Continued use after an updated policy takes effect is subject to applicable law and does not remove rights that cannot be waived.