
Last updated: February 2, 2025
Wizzo is an AI-powered Slack app that helps teams generate test cases from requirements. This page provides a comprehensive view of our security and privacy practices, including what data we access, how we process it, and the measures we take to protect it.
Data access — Only what you explicitly share in Wizzo interactions.
Data storage — Minimal, purpose-limited, encrypted at rest and in transit.
AI processing — Google Gemini API; data not retained or used for training.
Hosting region — European Union (Frankfurt, Germany).
AI processing region — United States (protected by SCCs).
Integrations — Optional Jira and GitHub connections; OAuth-based.
Retention — User-controlled deletion; automatic cleanup of temporary data.
Wizzo only accesses data that users explicitly provide through interactions with the app:
Wizzo stores the following data to provide its core functionality:
Products & Features — Organize test cases. Retained until user deletes.
Test cases — Core functionality. Retained until user deletes.
Session context — Maintain conversation flow. Retained for 72 hours (auto-deleted).
Draft test cases — Review before saving. Retained for 24 hours (auto-deleted).
Quality Party sessions — Collaborative discussions. Configurable (24–96 hours).
Integration tokens — Jira/GitHub access. Retained until user disconnects.
User preferences — Personalization. Retained until user deletes account.
Wizzo uses Google Gemini for AI-powered test case generation.
AI Provider — Google (Gemini API).
Processing Location — United States.
Data Retention by AI — None — data is not retained after processing.
Training Data — Not used — your data is never used to train AI models.
Transfer Protection — Standard Contractual Clauses (SCCs) approved by the European Commission.
Processing occurs within Google Cloud's infrastructure in the United States. Data transfers to the US are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.
Important: AI-generated content has inherent limitations:
Accuracy — AI outputs may contain errors, inaccuracies, or omissions (sometimes called "hallucinations").
Context — AI may misinterpret requirements or generate test cases that don't match your intent.
Completeness — AI may not cover all edge cases or testing scenarios.
Human oversight is required:
For complete terms regarding AI-generated content, see our Terms of Service.
Authentication — OAuth 2.0 (user-level).
Scope — Read issues, write comments.
Data flow — Issue data fetched on-demand, not stored permanently.
Token storage — Encrypted, per-user.
Authentication — GitHub App (workspace-level).
Scope — Read PRs and issues, write comments.
Data flow — PR/issue data fetched on-demand, not stored permanently.
Installation — Managed by workspace admins.
Both integrations are optional and can be disconnected at any time.
In transit — TLS 1.2+ for all connections.
At rest — AES-256 encryption for stored data.
Wizzo operates from a single hosting region: European Union (Frankfurt, Germany — AWS eu-central-1).
Application data — EU (Frankfurt). Primary database.
Backups — EU (Frankfurt). Same region as primary.
AI processing — United States. Protected by SCCs; no data retained.
Wizzo does not currently offer custom regional data residency (e.g., hosting exclusively in the UK or a specific country). All customer data is hosted in the EU region described above.
If your organization has specific data residency requirements, please contact us at legal@epictestquest.com to discuss your needs.
Conversation sessions — 72 hours of inactivity.
Draft test cases — 24 hours after creation.
Quality Party sessions — Based on configured duration (24–96 hours).
Expired OAuth tokens — Immediate on expiration.
When Wizzo is uninstalled from a workspace, all associated data is queued for deletion within 30 days.
GDPR — Compliant (EU data hosting, user rights supported).
SOC 2 — Via sub-processors (Supabase, Google).
Data Processing — DPA available on request.
Wizzo uses cloud infrastructure and AI model providers as sub-processors.
Google (Gemini API) — AI processing for test generation. United States. SOC 2, ISO 27001.
Supabase — Database and authentication. European Union (Germany). SOC 2 Type II.
Slack — Platform integration. United States. SOC 2, ISO 27001.
Atlassian (Jira) — Optional integration. US or EU (customer choice). SOC 2, ISO 27001.
GitHub — Optional integration. United States. SOC 2, ISO 27001.
For inquiries related to security, privacy, or data protection:
Data Protection / Privacy — legal@epictestquest.com
Security / Vulnerability Reports — security@epictestquest.com
General Legal — legal@epictestquest.com
Response time: Within 48 hours for security and data protection matters.
This page is reviewed quarterly and updated as our practices evolve. Material changes will be communicated via the Wizzo Home tab or workspace notifications.
February 2, 2025 — Added Data Residency section, backup location info, explicit Data Protection contact.
January 21, 2025 — Added explicit hosting region, AI processing location, and sub-processor list.
January 2025 — Initial publication of Security & Privacy overview.