Privacy Policy
A MarSci product · Effective 21 September 2026
Local-first responsive QA
Mobile Lab stores core settings, recent/test URLs, saved test setups, QA state, recorded QA-flow evidence and user-triggered captures on the user's computer. Core Free testing does not require an account. Routine previews, screenshot editing/redaction, QA-flow assembly and saved local work are not uploaded to a cloud workspace by the current v2 implementation.
Optional extension product analytics
The Chrome extension does not send product-usage analytics before consent. After a first successful test, Mobile Lab may offer an optional, non-blocking choice to share first-party aggregate product events. Declining does not reduce Free or Pro functionality.
If accepted, the extension may send a pseudonymous app-generated installation identifier, extension version, event name, Free/Pro state and a generic feature/scope label to the Mobile Lab service. Example event names include a completed test, screenshot, QA Flow, Results view, trial start or checkout start.
The extension product-analytics endpoint is not designed to receive URLs or hostnames, browsing/search history, page/DOM content, screenshots, form values, typed QA-flow values, credentials, cookies or session recordings. The server rejects telemetry fields outside its allowlist.
Public website analytics
The public website at ml.marsci.cc uses Google Analytics 4 and PostHog only after a separate website analytics consent. Advertising storage, ad-user data and ad personalization remain disabled. PostHog is used for explicit website events without interaction autocapture or session recording. Website consent does not enable extension telemetry.
QA Flow Recorder and interaction signals
When you explicitly start Record Flow, Mobile Lab records website interaction metadata needed to build reproducible QA steps, such as action type, accessible element name, element role/geometry, selected viewport and screenshot evidence. Typed field values are not stored by the recorder. Password, payment-card, security-code and obvious authentication-secret values are specifically suppressed. Recorded flow evidence remains local unless you explicitly copy or export it.
For simulator features, Mobile Lab may use temporary scroll, pointer/touch and focused-editable signals to synchronize or emulate interactions across the testing workspace. These signals are used for the requested lab behavior and are not advertising telemetry.
Mobile Lab Pro diagnostic processing
When an activated Pro user requests protected review details, professional export or a fix/handoff prompt, Mobile Lab sends a structured diagnostic payload to the Pro service over HTTPS. It may include the reviewed URL, device/viewport measurements, accessibility, frontend/UX/runtime signals, selected page metadata or derived content signals, manual QA states and optional QA notes.
The Pro service is not designed to receive cookies, authentication credentials, password/form values, full page HTML, screenshots/captures or saved workspace files as part of routine diagnostic requests. Current server code processes these diagnostic requests to produce the requested result and does not intentionally persist the full diagnostic request payload in the license database.
Trial, billing and device authorization
A 14-day Pro trial can be requested after a successful test. Starting a trial requires a verified email and a device-bound entitlement; no payment method is collected for the trial and no automatic paid subscription is created when it ends. Trial status and expiration are held by the Mobile Lab entitlement service.
Stripe handles card entry and payment collection for paid subscriptions. Mobile Lab may process checkout email, subscription/payment status, Stripe customer/subscription identifiers, app-generated installation ID, device public key, signed challenge/request proofs and entitlement state. The extension does not receive card numbers or Stripe secret keys. The device private key is kept as a non-extractable browser CryptoKey.
Security records
The Pro service may use request IP addresses transiently to derive hashed rate-limit/security buckets. It is not used for location profiling or advertising. License, device, webhook/idempotency, revocation, trial and limited security-audit records are retained as needed to operate access and prevent abuse.
Permissions
Mobile Lab uses storage, tabs, downloads, debugger, declarativeNetRequest and HTTP/HTTPS host permissions for responsive preview, browser-level Interactive Test, blocked-site recovery, screenshots/downloads, QA Flow capture and diagnostic evidence. These permissions are not used to sell user data or build advertising profiles.
Limited Use
Mobile Lab uses Chrome API and user data only to provide or improve its disclosed responsive-testing/frontend-QA purpose and related security/operational functions. We do not sell user data or use it for personalized advertising.
Deletion and control
Users can delete saved test setups/flows, clear extension storage, delete exports, decline telemetry, or uninstall the extension. Subscription/device/trial record access or deletion requests can be sent to ml.support@marsci.cc; records required for payment, fraud prevention, security or legal obligations may be retained where applicable.