Legal

Privacy policy

Last updated:

Ekko is a service published by Bomunto. It does two things. It lets teams receive detailed bug submissions from a widget placed on their site or an SDK built into their mobile application. And it puts those teams in touch with testers signed up on ekko, who join testing campaigns. This page describes the data we process on both sides, why, for how long, and what you can do about it.

This page is a translation, provided for convenience: the French text is the legally binding version and prevails over this English translation in the event of any discrepancy.

Who is responsible for the processing

Bomunto, the publisher of Ekko, is responsible for the processing of the data described here. For any question: hello@ekko.bomunto.com.

The data we collect

Your account. When you sign up through GitHub or Google, we keep your email address, your display name and your account identifier with that provider. We ask for no other permission and never act on your GitHub or Google account.

The testers you invite. When you invite someone from your dashboard, we keep their email address and name, attached to your project only.

Bug submissions. When a tester sends a submission from the widget, it contains what the tester wrote and, depending on what they agreed to:

  • an annotated capture of the page or screen;
  • a session video of the last few seconds before it was sent;
  • a voice comment, if the tester allowed the microphone;
  • console messages and failed network requests;
  • on the web: the page address, browser, screen size and language;
  • on mobile (iOS, Android, Flutter and React Native SDKs): the device model, system version, application version and the screen the submission was sent from.

The microphone never opens without an explicit action from the tester. The content of these submissions is under the control of the team that installed the widget: it is up to them not to place it on pages carrying data they do not want to see come through.

Integrations. If you connect Jira, we keep the OAuth access token issued by Atlassian, encrypted at rest, along with the identifier and address of your Jira site. This token is used only to create tickets from your submissions and to synchronise their status. We do not read the rest of your Jira.

The testers who sign up on ekko

A tester can open an account directly on ekko, without being invited by anyone. That account is theirs: it is attached to no project until they join a campaign.

Their account. Their name, their email address and, if they chose a password, its hash — never the password itself. If they sign up through Google or GitHub, their account identifier with that provider.

Their tester profile. What they declare they can test: their platforms, their devices (type, system, model), their city, their country and their languages. These are used to offer them the campaigns that match, and they are visible to developers looking for testers — without their email address, which is never shown until they have joined that project.

Their activity. The campaigns joined, the missions held or dropped, the bugs sent, the points and credits earned, and their rank. These are what their certificate carries.

Their certificate. A document they can download, whose verification address is public. It carries their name, rank, points, the number of validated bugs, the number of applications tested, the platforms and the device models. It never names an application or a customer. Anyone they give that address to can read the document.

Their Google account, on an Android campaign. A Google Play closed test is joined with a Google address. The tester gives it to the developer running the campaign, who needs it to enrol them in the Play Console. That address therefore leaves ekko, for that developer and for Google.

What we do not collect

  • No advertising tracker, no audience-analytics tool.
  • No data from your application's visitors: the widget and the SDK send nothing until a tester sends a submission.
  • No card number: payments go through Stripe, which processes and stores them on its side. We only receive the fact that a payment took place and the last four digits Stripe displays.

Why we process it

  • Provide the service: receive, display and pass on bug submissions.
  • Authenticate you and secure your account.
  • Match campaigns with the testers whose profile fits, and follow how a mission is going.
  • Send you the service's emails: invitations, sign-in links, notifications, campaign reminders.
  • Export your submissions to the tools you have connected.
  • Bill subscriptions and campaigns, through Stripe.

The legal basis is the performance of the contract that binds us when you use Ekko. We do not use your data for any other purpose.

For how long

Submissions and feedback are kept for as long as your plan provides, screen captures, session videos and voice comments included, then deleted automatically. This length is not adjustable: 30 days on Solo, 90 days on Freelance, 180 days on Team.

Your account, your projects and your testers are kept for as long as your account exists. Integration tokens are deleted as soon as you disconnect the integration.

A tester's account, profile, points and mission history are kept until they delete it. They can do so themselves, from "My account" in their space. The bugs they sent stay with the developer who received them, detached from their name: those are that project's data, not theirs.

Where it is stored

Account data, tester profiles and bug submissions are stored in a database operated by Bomunto on servers located in France. Screen captures, session videos and voice comments are stored with Cloudflare (R2), whose storage and network span several countries, including outside the European Union. The service's emails are sent from a mail server operated by Bomunto. Payments are processed by Stripe.

We neither sell nor rent your data. It is passed to a third party only at your request, when you connect an integration such as Jira, and only the submissions you choose to export.

Cookies

Ekko sets a signed session cookie to keep you signed in, and a temporary cookie during an OAuth sign-in to check that the provider's reply matches your request. No third-party cookie.

Your rights

You may ask for access to, correction, portability or deletion of your data, and object to a processing activity, by writing to hello@ekko.bomunto.com. We reply within thirty days.

These are the rights the General Data Protection Regulation (GDPR) grants people residing in the European Union, and Bomunto applies them to everyone. If our answer does not satisfy you: in Cameroon, the National Agency for Information and Communication Technologies (ANTIC) is the competent authority; in the European Union, the data protection authority of your country of residence, the CNIL in France.

A tester deletes their account themselves, from their space. Deleting a developer's account deletes its projects, its invited testers, its bug submissions and its integration tokens; it is requested by email, at the address above.

Changes

If this policy changes significantly, the date at the top of this page is updated and active accounts are notified by email.