Privacy Notice
This notice explains how Affinity Labs Ltd (“Affinity Labs”, “we”, “us”) handles personal data in Watchr. It covers this website (watchr.tech), Watchr Cloud (agent.watchr.tech) and the watchr-mcp server you install on your own computer. It sits alongside our Terms of Service.
1. Who we are
Watchr is made by Affinity Labs Ltd, a company registered in England and Wales (company number 16564102), whose registered office is at 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom.
For your account, billing, this website and anything you send us, we are the controller of your personal data: we decide how and why it is used. For the content of the apps and websites our customers test with Watchr, we are usually a processor acting for that customer (see section 4).
Questions about this notice or your data go to privacy@affinitylabs.ai. That mailbox reaches the people at Affinity Labs responsible for data protection.
2. watchr-mcp on your computer
watchr-mcp is the open-source server that lets your coding assistant drive simulators, devices and browsers. It runs entirely on your computer. Screenshots, recordings, network captures, saved logins and settings stay in a folder on that computer (~/.watchr), and we never receive them.
It contacts other services in only these cases:
- Licence check. If you set a licence key, watchr-mcp checks it with RevenueCat, our subscription provider, at most once a day. The key is the email address you bought Watchr Pro with, so RevenueCat receives that address and your IP address.
- Downloads. Installing and updating watchr-mcp downloads it from PyPI. Some checks download open-source scripts from the cdnjs and unpkg code networks. As with any download, those services see your IP address, and their own privacy policies apply.
- Your assistant and the apps you test. What your coding assistant (for example Claude Code) sends to its AI provider is governed by your agreement with that provider, not by us. The apps and sites you open in a test receive what any visitor would send them.
3. What we collect
| Type of data | Examples | Where it comes from |
|---|---|---|
| Account details | Email address, name and profile picture (if you sign in with Google), password (held by our sign-in provider), when you last used Watchr | You, when you sign up or sign in; Google, if you choose Google sign-in |
| Workspace details | Workspace name, members and their roles, invitations (the invited email address), comments on runs | You and your teammates |
| What you set up for tests | The apps and sites to test, written instructions, test cases, personas, chosen countries, and the test-account logins and saved sessions you give Watchr to sign in with | You |
| Connections you turn on | Your own AI-provider API key, a Slack webhook, a Google Play sign-in for installing apps on test devices, a proxy address | You |
| Run results | Screenshots, screen recordings, the text of the pages tested, the steps the agent took, findings and reports | Created by Watchr while it runs your tests |
| Technical and security logs | IP address, browser details, the requests made to our servers, sign-in events, and the prompts and responses exchanged with AI models during a run, which can include the text and images of the screens tested | Collected automatically when you use Watchr |
| Billing details | Plan, purchase email, subscription status and payment history. Card details go straight to our payment providers; we never see them. | You, through our payment providers |
| Messages to us | What you write to us, including privacy requests, and our replies | You |
To create an account you must give us an email address, and to buy a plan you must give our payment providers your payment details; without them we can't provide those services. Everything else is up to you. We do not ask for special category data such as health information. Please don't put it in test instructions or test accounts.
4. Data in the apps you test
When Watchr Cloud tests an app or website, it sees and records what is on screen. That can include personal data: the details of the test accounts our customer gives us, and anything else that app shows. For this data the customer who set up the test is the controller, and we process it only to run their tests and keep their results, as they instruct us.
If you are a user of an app that a company tests with Watchr and you have questions about your data, please contact that company first. If you contact us instead, we will, with your agreement, pass your request to the company and help them answer you.
5. How we use it and why
Data protection law requires a lawful basis for each use of personal data. Ours are:
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and run your account and workspace, run your tests, show you the results | Account, workspace and test set-up details, connections, run results | Contract: we need it to provide the service you signed up for |
| Let the people your organisation invites use its workspace | Invitations, members' account details | Legitimate interests: providing the service your organisation chose |
| Take payment and check licences | Billing details, purchase email | Contract |
| Keep Watchr secure and working, investigate faults and misuse | Technical and security logs, run results | Legitimate interests: protecting our service and our customers |
| Answer your messages and privacy requests | Messages to us, account details | Legal obligation (for privacy requests); legitimate interests (for other messages) |
| Keep accounting records and meet other legal duties | Billing details | Legal obligation |
Where we rely on legitimate interests, you can object (see section 12). We do not send marketing email, and we do not make decisions about you by automated means that have legal or similarly significant effects.
6. AI models
Watchr Cloud uses an AI model to decide what to do next during a test and to write up what it found. To do that, it sends the model your test instructions, screenshots and the text of the screens being tested. Passwords you save for test accounts are not sent: the model types a placeholder, and Watchr fills in the real value on the device.
- By default, Watchr uses Google's Gemini models, with Anthropic's Claude models as a backup, under our own accounts with those providers.
- If you add your own API key for a provider (for example OpenAI, Anthropic, OpenRouter or Groq), your runs use your account with that provider, and that provider's terms and privacy policy apply to what is sent.
- We do not use your content or your run results to train AI models.
7. Who we share it with
We share personal data only with the service providers below, who process it on our behalf under contract, and with authorities when the law requires it. If we were involved in a sale or merger of our business, the buyer would receive it under the same protections. We never sell personal data.
| Provider | What for | Where the data is |
|---|---|---|
| Google Cloud | Servers, storage of run results, logs, Android test devices | Belgium (europe-west1) |
| Supabase | Database and sign-in | Ireland (AWS eu-west-1) |
| Google (Gemini API), Anthropic | AI models that run tests (see section 6) | May be processed in the United States |
| Oxylabs | Network routes that let a test appear from a chosen country; test traffic passes through them | Lithuania; traffic leaves through connections in the country you choose, which may be outside the UK and EEA |
| RevenueCat and Stripe | Subscriptions, checkout and payments | United States |
| Vercel | Hosting this website | United States and its global network |
| Tailscale | The private network link to the Apple computers that run iOS tests | United States (connection details only) |
| Microsoft 365 | Our email, including privacy requests | As set out in Microsoft's data residency terms |
Some data goes to services because you connect them: run summaries go to your Slack workspace if you add a Slack webhook, and your Google Play sign-in is used with Google if you connect Google Play. If you create a share link for a report, anyone with the link can see that report until the link expires (30 days unless you choose otherwise) or you revoke it.
8. Transfers outside the UK and EEA
Some of the providers above process data outside the UK and the European Economic Area, mainly in the United States. When they do, we rely on an adequacy decision (such as the UK–US data bridge for certified companies) or on standard contractual clauses approved by the UK and EU authorities, with the UK addendum. You can ask us for details at privacy@affinitylabs.ai.
9. How long we keep it
| Data | How long |
|---|---|
| Account, workspace and test set-up details | While your account is open. When you close your account or ask us to delete it, we delete it within 90 days. |
| Run results (screenshots, recordings, reports) | While your workspace exists. When the workspace is closed, or you or its owner ask us to delete them, we delete them within 90 days. |
| Application logs, including the prompts and responses exchanged with AI models | 30 days |
| Security and audit logs | Up to 2 years |
| Database backups | Up to 35 days, after which deleted data is gone from backups too |
| Billing and accounting records | 6 years, as UK tax law requires |
| Privacy requests and our replies | 3 years after we close the request |
10. Cookies and browser storage
This website sets no cookies and uses no analytics or advertising trackers. Watchr Cloud keeps a few items in your browser's local storage that it needs to work: your sign-in session, the workspace you last used and display preferences such as a collapsed sidebar. Because these are strictly necessary, they don't need your consent. If we ever add optional cookies or analytics, we will ask first.
11. How we protect it
Data is encrypted in transit and at rest. Saved test-account passwords and sessions, API keys and webhook addresses get an extra layer of encryption with our own key, and passwords are never shown again after you save them. We limit which of our staff can reach production systems. If a breach puts your data at risk, we will tell the people affected and the regulator when the law requires it. No system is perfectly secure, so please use test accounts rather than personal ones where you can.
12. Your rights
Under UK and EU data protection law you can ask us to:
- give you a copy of your personal data (access)
- correct data that is wrong or incomplete (rectification)
- delete your data (erasure)
- limit how we use it (restriction)
- stop using it where we rely on legitimate interests (objection)
- give you the data you provided in a portable format (portability)
- stop a use you consented to, at any time (withdrawing consent)
We will answer within one month of receiving your request. If a request is complex we may need up to two more months; if so, we will tell you within the first month. We may ask you to confirm your identity first, and we will only send data to an address we have verified. Requests are free unless they are clearly unfounded or excessive. Some rights have legal exceptions; if one applies, we will explain it.
You can also complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113) or, in the EEA, to your local data protection authority. We would appreciate the chance to help first.
13. Make a privacy request
Use this form to ask us to delete your data or to use any of the rights above. It writes an email to privacy@affinitylabs.ai for you to send. You can also just write to that address. Every request is logged and tracked until we have answered it.
14. Children
Watchr is a tool for businesses and professionals and is not meant for anyone under 18. We do not knowingly collect children's data. If you think we have, contact privacy@affinitylabs.ai and we will delete it.
15. Changes to this notice
When we change how we handle personal data, we update this notice within 30 days and change the date at the top. If a change matters to you, we will also tell account holders by email or in Watchr Cloud before it takes effect.