TestzoManaged Android testing

Testzo Privacy Policy

Last updated: 11 August 2026

Applies to: the Testzo Android app (com.testzo.closedtesting) and the Testzo web services.


1. Who we are

Testzo is a managed Android closed-testing and QA marketplace available at

https://aiviogen.com and operated from India.

We are the data controller for the personal data described below.

2. What we collect

We collect only what the service needs. We do not collect location, contacts,

photos, files, SMS, call logs, health data, or device identifiers for advertising.

2.1 Everyone

DataWhyLegal basis
Email addressAccount creation, sign-in, service noticesContract
Display nameShown on your own profileContract
CountryPricing, currency and available payment methodsContract
Language preferenceApp languageLegitimate interest
App version, OS versionSupport and compatibilityLegitimate interest

2.2 Testers

DataWhyLegal basis
Device model and Android versionMatching you to compatible testing projects; device-coverage reportingContract
QA activity — sessions completed, streaks, task results, ratingsCalculating your Quality Score and rewardsContract
Written feedback and bug reportsDelivering QA results to the developerContract
Quality Coin balance and ledgerRewards and payoutsContract
UPI ID / payout detailsPaying youContract, legal obligation (tax records)
Google account emailEnrolling you in the developer's Google Play closed-testing track — this is the only purposeContract, with your explicit consent per project

2.3 Developers

DataWhyLegal basis
App name, package name, category, descriptionRunning the testing projectContract
Play Console opt-in and testing URLsVerifying a genuine closed-testing track existsContract
Billing records — plan, amount, currency, tax, payment referenceFulfilling the order, invoicing, tax recordsContract, legal obligation

2.4 Notifications

If you allow notifications, we store a Firebase Cloud Messaging registration

token for your device so we can deliver testing reminders and status updates.

You can revoke this at any time in Android Settings; the token is deleted when

Firebase reports it as unregistered.

3. Tester identity and anonymity

This is central to how Testzo works:

  • Testers appear to developers only as anonymised identifiers such as TR-8291.
  • Your name and email are never shown to a developer inside Testzo.
  • Your email leaves Testzo in exactly one circumstance: to add you to the

Google Play Console closed-testing tester list for a project you have joined,

either by direct sync to the Play Developer API or through a CSV the developer

uploads. Google Play requires the tester's Google account email for enrolment;

there is no way to join a closed track without it.

  • Every such release is recorded in an internal audit log naming the

administrator who performed it.

4. Payments

We do not store your card number, UPI PIN, CVV or bank credentials. Payments

are processed by:

  • Razorpay Software Private Limited (India) — cards, UPI, net banking, wallets.

See Razorpay's privacy policy.

  • Google LLC (Google Play Billing) — where you pay through your Play account.

See Google's privacy policy.

We receive and store only a payment reference, the amount, the currency, the

method type and the status, which we need for invoicing, refunds, dispute

resolution and statutory tax records.

5. How we use your data

We use personal data to operate the service: create and secure accounts, match

testers to projects, run and monitor the 14-day QA cycle, calculate Quality

Scores and rewards, take payments and make payouts, resolve disputes, provide

support, prevent fraud and abuse, and meet legal obligations.

**We do not sell personal data. We do not share it with data brokers. We do not

use it for third-party advertising or build advertising profiles.**

6. Who we share it with

RecipientWhatWhy
The developer whose app you testAnonymised TR- id, device model, Android version, QA results, feedback, bug reportsDelivering the QA results they paid for
Google (Play Developer API)Tester Google account emailEnrolling you in the closed-testing track you joined
Google (Firebase Cloud Messaging)Device push tokenDelivering notifications
RazorpayPayment amount, currency, order referenceProcessing payment
MongoDB hosting / cloud infrastructureData at restRunning the service
Government authoritiesOnly what the law requiresLegal obligation

Processors act on our instructions under written agreements.

7. International transfers

Our service providers may process data in India and in other countries where

they operate. Where data is transferred outside your country — for example to

Google's global infrastructure — we use the safeguards required by applicable

law and limit the transfer to what the service needs.

8. How long we keep it

DataRetention
Account profileWhile your account is open
QA activity, feedback, bug reportsLife of the project + 24 months (developers rely on the QA record)
Payment and payout records8 years (Indian tax and companies law)
Push tokensUntil revoked, replaced, or reported unregistered
Audit logs24 months
Support tickets24 months

After you delete your account we remove or irreversibly anonymise your personal

data within 30 days, except records we must keep by law (payment and tax

records), which we retain for the statutory period and use for nothing else.

9. Your rights

Regardless of where you live, you can:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your account and personal data
  • Export your data in a machine-readable format
  • Withdraw consent — including turning off notifications, or leaving a

testing project so your email is removed from that project's tester list

  • Object to or restrict certain processing
  • Complain to a supervisory authority

How to delete your account:

We respond to requests within 30 days.

Under India's DPDP Act 2023 you may also nominate another person to exercise

these rights on your behalf, and you may escalate to the Data Protection Board

of India if our Grievance Officer does not resolve your complaint.

10. Security

Traffic is encrypted with HTTPS/TLS. Passwords are hashed with bcrypt. Admin

access is role-gated and every privileged action is written to an audit log.

Tester emails are excluded from API responses at the database layer, not merely

hidden in the interface. No system is perfectly secure; we will notify affected

users and the relevant authority of a qualifying breach without undue delay.

11. Children

Testzo is not directed at children and is not intended for anyone under 18.

Testers must be 18 or older to earn rewards and receive payouts. We do not

knowingly collect data from children. If you believe a child has given us data,

contact us and we will delete it.

12. Changes

We will post any change here and update the date at the top. For material

changes we will notify you in the app or by email before they take effect.

13. Contact

Testzo

Website: https://aiviogen.com

Email and grievance contact: venkatadri@androai.io