UniTesters — Privacy Policy

Last updated 29 August 2026

UniTesters is a work application for people who test mobile apps for our clients. It is not a consumer product: you use it because you have been recruited as a tester, a supervisor, or an owner of a testing organisation.

This policy explains what we hold about you, why, and what you can do about it. It is written against what the application actually stores, not a template.

Who is responsible

UniTesters, operated by Jas Salazar, Philippines.

Contact for any privacy question or request: micarinderia@gmail.com

We process personal data under the Philippine Data Privacy Act of 2012 (Republic Act No. 10173). If you are unhappy with how we have handled your data you may complain to the National Privacy Commission.

You must be 18 or over

Testing work is paid, so the application refuses to create a tester profile for anyone who does not confirm they are 18 or older. This is enforced in the database, not only in the interface. We do not knowingly hold data about children. If you believe we do, write to us and we will delete it.

What we collect

Everyone with an account

DataWhy
NameSo your supervisor and your client report know whose work is whose
Email address and passwordSigning in. Passwords are stored only as a cryptographic hash — we cannot read yours
Google account addressGoogle Play closed testing works by adding this address to the client's tester group. Without it you cannot be staffed on Play Store work
Phone number (optional)So your supervisor can reach you
Time zone and languageWorking out when your testing day opens and closes

If you are a tester

DataWhy
Date of birth (optional)Confirming eligibility for paid work
Phone brand, model and OS version; whether you have a computer; internet qualityMatching you to projects. A client testing on Android 15 needs testers who have it
School, course, occupation, languages, availability (optional)Matching you to projects that suit you
Prior experience and motivation (optional)Reviewing your application
Facebook profile link (optional)Confirming you are a real person during recruitment
E-wallet provider, account name and numberPaying you. The number and account name are encrypted in our database; only the last four digits are stored in readable form so you can recognise your own account
Screenshots you submit (up to five a day)Proof of your daily testing. These are shown to your supervisor and may be provided to the client as evidence
Screen recordings you choose to attach to a bug report (optional, up to 30 seconds)Showing a fault that a still picture cannot — a crash, a freeze, something that only happens while the screen is moving. Shown to your supervisor and may be provided to the client as evidence. See the warning below
Your checklist answers, notes and bug reportsThis is the work product. It is what the client is paying for
A device fingerprint (make, model, OS — not a hardware serial) and app versionDetecting one person submitting for several accounts. This is fraud prevention, and it protects honest testers from being undercut
Push notification tokenTelling you when a testing day opens or your work was reviewed
Reliability score and historyDeciding who to invite to future work
A screen recording captures everything on your screen, not only the app you are testing. That can include notifications, messages, and anything else visible while you record — including from other apps. We never ask you to record one, and you never have to: a bug report without a recording is a perfectly good bug report.

If you do record one, turn on Do Not Disturb and close other apps first. You can see the clip and remove it before the report is sent, and once sent you can ask your supervisor to delete it. The application itself does not record your screen and cannot: you record with your phone’s own recorder and choose the file.

What we do not collect

We do not collect your location, contacts, calendar, messages, browsing history, health data, or a list of the other apps on your phone. We do not use advertising identifiers. The application contains no advertising SDK, no analytics SDK, and no third-party tracking of any kind.

Who sees it

Inside your organisation

Your supervisor and the organisation's owner can see your profile, your submissions and your record. Other testers cannot: the database restricts every query by row, so a tester can read their own work and nobody else's.

Our clients

Clients never receive your identity. In the reports we deliver, testers are labelled “Tester 1”, “Tester 2” and so on. Your name, email, school, contact details and payment details are never included. A client receives your device make and model, your findings, and which days you covered.

Service providers

WhoWhat for
SupabaseDatabase, authentication and file storage. Data is held on their infrastructure on our behalf
ExpoDelivering push notifications to your device
Google Play / AppleDistributing the application itself

These are processors acting on our instructions. We do not sell your data, and we do not share it with anyone for their own purposes.

How long we keep it

Your profile is kept while you are on our roster. Submissions, screenshots and bug reports are kept for as long as the client may reasonably need to rely on them, and in any case for the duration of the engagement plus a reasonable period for disputes about work delivered and payments made.

Screen recordings are kept only while the defect they belong to is open, and are deleted once it is closed or the engagement ends, whichever comes first. They are the most revealing thing we hold and the least often needed twice.

Records of payments made to you are kept for as long as tax and accounting rules require, even after your account is deleted. These are retained in a minimised form that does not include your e-wallet number.

Your rights, and how to use them

Under the Data Privacy Act you may ask for a copy of your data, ask us to correct it, object to how we use it, or ask us to delete it. Two of these are built into the application and do not require you to ask anyone:

You can also simply write to micarinderia@gmail.com and we will action it. We aim to respond within fifteen days.

Deleting your account does not withdraw work already delivered to a client, as that evidence was pseudonymous when it was delivered and cannot be traced back to you from the client's copy.

How we protect it

Changes

If we change this policy we will update the date at the top. If a change materially affects what we do with your data, we will tell you in the application.