Security & Privacy

A clear, transparent breakdown of how Wizzo accesses, processes, stores, & protects your data.
Blog Banner

Last updated: February 2, 2025

Table of Contents

  1. Overview
  2. At a Glance: Wizzo & Your Data
  3. Data Access in Slack
  4. Data We Store
  5. Data We Never Store
  6. AI Model Processing
  7. Integrations (Jira & GitHub)
  8. Data Encryption & Infrastructure
  9. Data Residency
  10. Data Retention & Deletion
  11. Access Control & Internal Security
  12. Admin Controls & Auditability
  13. Threat Protection & Safe Use
  14. In-Product Feedback & Support Data
  15. Compliance & Legal
  16. Contact
  17. Updates
  18. Changelog

Overview

Wizzo is an AI-powered Slack app that helps teams generate test cases from requirements. This page provides a comprehensive view of our security and privacy practices, including what data we access, how we process it, and the measures we take to protect it.

At a Glance: Wizzo & Your Data

Data access — Only what you explicitly share in Wizzo interactions.

Data storage — Minimal, purpose-limited, encrypted at rest and in transit.

AI processing — Google Gemini API; data not retained or used for training.

Hosting region — European Union (Frankfurt, Germany).

AI processing region — United States (protected by SCCs).

Integrations — Optional Jira and GitHub connections; OAuth-based.

Retention — User-controlled deletion; automatic cleanup of temporary data.

Data Access in Slack

Wizzo only accesses data that users explicitly provide through interactions with the app:

What Wizzo Does NOT Access

Data We Store

Wizzo stores the following data to provide its core functionality:

Products & Features — Organize test cases. Retained until user deletes.

Test cases — Core functionality. Retained until user deletes.

Session context — Maintain conversation flow. Retained for 72 hours (auto-deleted).

Draft test cases — Review before saving. Retained for 24 hours (auto-deleted).

Quality Party sessions — Collaborative discussions. Configurable (24–96 hours).

Integration tokens — Jira/GitHub access. Retained until user disconnects.

User preferences — Personalization. Retained until user deletes account.

Data We Never Store

AI Model Processing

Wizzo uses Google Gemini for AI-powered test case generation.

Key Facts

AI Provider — Google (Gemini API).

Processing Location — United States.

Data Retention by AI — None — data is not retained after processing.

Training Data — Not used — your data is never used to train AI models.

Transfer Protection — Standard Contractual Clauses (SCCs) approved by the European Commission.

What Gets Sent to the AI

What Does NOT Get Sent

Processing occurs within Google Cloud's infrastructure in the United States. Data transfers to the US are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

AI Limitations & Human Oversight

Important: AI-generated content has inherent limitations:

Accuracy — AI outputs may contain errors, inaccuracies, or omissions (sometimes called "hallucinations").

Context — AI may misinterpret requirements or generate test cases that don't match your intent.

Completeness — AI may not cover all edge cases or testing scenarios.

Human oversight is required:

For complete terms regarding AI-generated content, see our Terms of Service.

Integrations (Jira & GitHub)

Jira Integration

Authentication — OAuth 2.0 (user-level).

Scope — Read issues, write comments.

Data flow — Issue data fetched on-demand, not stored permanently.

Token storage — Encrypted, per-user.

GitHub Integration

Authentication — GitHub App (workspace-level).

Scope — Read PRs and issues, write comments.

Data flow — PR/issue data fetched on-demand, not stored permanently.

Installation — Managed by workspace admins.

Both integrations are optional and can be disconnected at any time.

Data Encryption & Infrastructure

Encryption

In transit — TLS 1.2+ for all connections.

At rest — AES-256 encryption for stored data.

Infrastructure

Security Features

Data Residency

Current Hosting

Wizzo operates from a single hosting region: European Union (Frankfurt, Germany — AWS eu-central-1).

Application data — EU (Frankfurt). Primary database.

Backups — EU (Frankfurt). Same region as primary.

AI processing — United States. Protected by SCCs; no data retained.

Custom Regional Hosting

Wizzo does not currently offer custom regional data residency (e.g., hosting exclusively in the UK or a specific country). All customer data is hosted in the EU region described above.

If your organization has specific data residency requirements, please contact us at legal@epictestquest.com to discuss your needs.

Data Retention & Deletion

Automatic Cleanup

Conversation sessions — 72 hours of inactivity.

Draft test cases — 24 hours after creation.

Quality Party sessions — Based on configured duration (24–96 hours).

Expired OAuth tokens — Immediate on expiration.

User-Initiated Deletion

Workspace Removal

When Wizzo is uninstalled from a workspace, all associated data is queued for deletion within 30 days.

Access Control & Internal Security

Application Access

Internal Practices

Admin Controls & Auditability

Workspace Admins Can

Audit Capabilities

Threat Protection & Safe Use

Input Validation

Prompt Injection Protection

Recommended Practices

In-Product Feedback & Support Data

Feedback Collection

Support Requests

Framework Alignment

GDPR — Compliant (EU data hosting, user rights supported).

SOC 2 — Via sub-processors (Supabase, Google).

Data Processing — DPA available on request.

Sub-processors

Wizzo uses cloud infrastructure and AI model providers as sub-processors.

Google (Gemini API) — AI processing for test generation. United States. SOC 2, ISO 27001.

Supabase — Database and authentication. European Union (Germany). SOC 2 Type II.

Slack — Platform integration. United States. SOC 2, ISO 27001.

Atlassian (Jira) — Optional integration. US or EU (customer choice). SOC 2, ISO 27001.

GitHub — Optional integration. United States. SOC 2, ISO 27001.

Legal Basis for Processing

Contact

For inquiries related to security, privacy, or data protection:

Data Protection / Privacy — legal@epictestquest.com

Security / Vulnerability Reports — security@epictestquest.com

General Legal — legal@epictestquest.com

Response time: Within 48 hours for security and data protection matters.

Updates

This page is reviewed quarterly and updated as our practices evolve. Material changes will be communicated via the Wizzo Home tab or workspace notifications.

Changelog

February 2, 2025 — Added Data Residency section, backup location info, explicit Data Protection contact.

January 21, 2025 — Added explicit hosting region, AI processing location, and sub-processor list.

January 2025 — Initial publication of Security & Privacy overview.

Got all the info you need? If not, just send us a message.

We're here for you 24/7
Contact Us
Contact Us