Privacy Policy
Effective Date: April 9, 2026
Last Updated: April 9, 2026
BurnTest.io ("BurnTest," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at burntest.io and use our platform and services (collectively, the "Service"). Please read this policy carefully. By accessing or using the Service, you consent to the practices described in this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
We collect information that you voluntarily provide to us when you register for an account, make a purchase, submit a review, complete your profile, or communicate with us. This includes:
- Account Information: Name, email address, and authentication credentials provided through our OAuth login provider
- Profile Information: Display name, biography, expertise/skills, and profile preferences
- Demographic Information: Age group, household income range, and geographic region/country (provided voluntarily by Burners for matching purposes)
- Payment Information: Payment card details and billing information are collected and processed directly by Stripe, Inc. We store only Stripe customer IDs and transaction references — we never store your full credit card number, CVV, or expiration date
- User-Generated Content: Video recordings (screen recordings with audio), transcripts, text feedback, and any other content you submit through the Service
- Communications: Messages, feedback submissions, support requests, and any other communications you send to us
- Payout Information: Payout method preferences and associated email addresses for Burner compensation
1.2 Information Collected Automatically
When you access or use the Service, we automatically collect certain information about your device and usage, including:
- Device Information: Browser type and version, operating system, device type (mobile/desktop), screen resolution, and device identifiers
- Usage Data: Pages visited, features used, click patterns, time spent on pages, referring URLs, and navigation paths
- Log Data: IP address, access times, server logs, and error reports
- Analytics Data: We use privacy-focused analytics tools to understand how users interact with the Service, including page views, session duration, and feature engagement
1.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to operate and improve the Service. For detailed information about the cookies we use and your choices regarding cookies, please see our Data Collection & Cookie Policy.
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled without breaking core functionality
- Functional Cookies: Remember your preferences, such as theme settings and dismissed UI elements (stored in localStorage)
- Analytics Cookies: Help us understand how users interact with the Service to improve user experience
2. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and Operate the Service: Create and manage your account, process transactions, match Burners with review requests, deliver Burns to Clients, and process Burner payouts
- Demographic Matching: Use your voluntarily provided demographic information (age, income, location) to match Burners with Client review requests that target specific audience segments
- AI-Powered Analysis: Process review transcripts and feedback through artificial intelligence and machine learning systems to generate aggregated insights, sentiment analysis, and summary reports for Clients
- Communications: Send you transactional emails (account confirmations, payment receipts, review notifications), service updates, and, if you opt in, marketing communications
- Improve the Service: Analyze usage patterns and feedback to improve features, fix bugs, and enhance user experience
- Security and Fraud Prevention: Detect, investigate, and prevent fraudulent transactions, abuse, and other harmful activities
- Legal Compliance: Comply with applicable laws, regulations, legal processes, and governmental requests
- Enforce Our Terms: Enforce our Terms of Service and other agreements
3. How We Share Your Information
We do not sell your personal information to third parties. We may share your information in the following circumstances:
| Recipient | What We Share & Why |
|---|---|
| Clients | Burner video recordings, transcripts, display name, bio, expertise, and location for completed Burns. Clients need this to evaluate the feedback they purchased. |
| Burners | Client website URLs, review questions, and target demographic criteria for available review requests. Burners need this to complete their Burns. |
| Stripe, Inc. | Payment and billing information for processing credit purchases, subscription payments, and Burner payouts. Governed by Stripe's own Privacy Policy. |
| Cloud Storage Providers | Video recordings and associated files for secure storage and delivery. Files are stored with access controls. |
| AI/LLM Providers | Review transcripts and feedback text for generating AI-powered insights and sentiment analysis. Data is processed per provider terms and not used for model training. |
| Email Service Providers | Email addresses and names for sending transactional and notification emails (e.g., Resend). |
| Analytics Providers | Anonymized usage data and interaction patterns for understanding Service performance and user behavior. |
| Law Enforcement | Any information required by law, subpoena, court order, or governmental request, or to protect the rights, property, or safety of BurnTest, our users, or the public. |
| Business Transfers | In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your information may be transferred as a business asset. |
4. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. We may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, enforce our agreements, and for legitimate business purposes. Specifically:
- Account Data: Retained for the duration of your account and for a reasonable period after account deletion to comply with legal obligations
- Video Recordings and Transcripts: Retained for as long as the associated Client account is active, or as required for dispute resolution
- Transaction Records: Retained for a minimum of seven (7) years for tax and financial reporting purposes
- Analytics Data: Aggregated and anonymized data may be retained indefinitely for statistical purposes
5. Data Security
We implement commercially reasonable technical and organizational security measures designed to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols
- Secure authentication via OAuth 2.0 with session-based tokens
- Payment data handled exclusively by PCI-DSS compliant Stripe infrastructure
- Access controls and role-based permissions for internal systems
- Regular security reviews and monitoring
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. You acknowledge that you provide your personal information at your own risk.
6. Your Rights and Choices
6.1 Account Information
You may access, update, or correct your account information at any time through your Profile & Settings page. You may update your email address, display name, demographic information, and notification preferences directly within the Service.
6.2 Account Deletion
You may request deletion of your account and associated personal data by contacting us at [email protected]. Upon receiving a verified deletion request, we will delete or anonymize your personal information within thirty (30) days, except for data we are required to retain for legal, tax, or compliance purposes.
6.3 Communication Preferences
You may opt out of non-essential email communications by adjusting your notification preferences in your Profile & Settings page. You may also unsubscribe from marketing emails by clicking the "unsubscribe" link in any marketing email. Please note that you cannot opt out of transactional emails related to your account and purchases.
6.4 Cookie Preferences
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may prevent you from using certain features of the Service. See our Data Collection & Cookie Policy for more details.
7. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your information was collected, the business or commercial purpose for collecting your information, and the categories of third parties with whom we share your information
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
- Right to Correct: You have the right to request correction of inaccurate personal information
- Right to Opt-Out of Sale: We do not sell your personal information. If this practice changes, we will provide a "Do Not Sell My Personal Information" link
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to purposes necessary to provide the Service
To exercise these rights, contact us at [email protected]. We will verify your identity before processing your request. You may also designate an authorized agent to make a request on your behalf.
8. International Users and GDPR
If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located. By using the Service, you consent to the transfer of your information to the United States.
If you are a resident of the European Economic Area (EEA), United Kingdom, or Switzerland, you may have additional rights under the General Data Protection Regulation (GDPR), including the right to access, rectification, erasure, restriction of processing, data portability, and the right to object to processing. To exercise these rights, contact us at [email protected]. Our legal basis for processing your personal data includes: performance of a contract, legitimate interests, consent, and compliance with legal obligations.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe we have inadvertently collected information from a child under 18, please contact us immediately at [email protected].
10. Third-Party Services
Our Service integrates with and relies on the following third-party services, each of which has its own privacy policy governing how they handle your data:
- Stripe: Payment processing — Stripe Privacy Policy
- Manus OAuth: Authentication and identity verification
- Cloud Storage (AWS S3): Secure file and video storage
- Resend: Transactional email delivery — Resend Privacy Policy
- AI/LLM Services: Transcript analysis and insight generation
We are not responsible for the privacy practices of these third-party services. We encourage you to review their respective privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a revised "Last Updated" date. For significant changes, we may also provide additional notice, such as an email notification or an in-app alert. Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
We will respond to all privacy-related inquiries within thirty (30) days of receipt.
Notice: This Privacy Policy is provided for informational purposes and is designed to comply with applicable privacy laws. While we have made every effort to ensure accuracy and completeness, this document does not constitute legal advice. For specific legal questions regarding your privacy rights, we recommend consulting with a qualified attorney.