Privacy Statement
Effective Date: 20/05/2026
Introduction
Beryl is a platform for automated testing and reliability, designed to help engineering teams ship software with confidence. By simply providing a target URL, teams can instantly generate deterministic test projects and project production environments daily. Beryl integrates with developer tooling such as GitHub, Slack, and your existing CI/CD pipelines to deliver test results and surface regressions where your team already works.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Notice describes Beryl's policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Notice as we undertake new personal data practices or adopt new privacy policies.
Privacy Contact
Beryl has designated a privacy contact for questions about personal data handling. If you would like to exercise your privacy rights or have questions about this Privacy Notice, please contact us at:
Vibemonitor, Inc.
2261 Market Street STE 46185, San Francisco, CA 94114, US
[email protected]
+1 (415) 874-0101
How we collect and use (process) your personal information
Beryl collects personal information about its website visitors and customers. With a few exceptions, this information is generally limited to:
- name
- work email
- integration credentials
- conversation & usage data
- code & repository data
- billing data
- test artifacts & crawl data
We use this information to provide prospects and customers with services.
We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services.
From time to time, Beryl receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry. We may also collect your personal data from third party services you connect to Beryl, such as GitHub or Google, when you authenticate or integrate those services.
Use of the Beryl Website
As is true of most other websites, Beryl's website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of Beryl's website, including a history of the pages you view. We use this information to help us design our site to better suit our users' needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, track visitor movements, and gather broad demographic information that assists us in identifying visitor preferences.
Beryl has a legitimate interest in understanding how members, customers and potential customers use its website. This assists Beryl with providing more relevant products and services, with communicating value to our partners and customers, and with providing appropriate staffing to meet member and customer needs.
Cookies and tracking technologies
Beryl makes available a comprehensive Cookie Notice that describes the cookies and tracking technologies used on Beryl website and provides information on how users can accept or reject them. To view the notice, please visit our https://beryl.so/cookies.
Sharing information with third parties
The personal information Beryl collects from you is stored in one or more databases hosted by third parties located in the United States. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval. On occasion, Beryl engages third parties to send information to you, including information about our products, services, and events.
A list of our third party sub processors can be found here: https://trust.beryl.so/subprocessors
We do not otherwise reveal your personal data to non-Beryl persons or businesses for their independent use unless: (1) you request or authorize it; (2) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (3) the information is provided to our agents, vendors or service providers who perform functions on our behalf; (4) to address emergencies or acts of God; or (5) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.
The Beryl website connects with third party services such as Amazon Web Services, Stripe, GitHub and others. If you choose to share information from the Beryl website through these services, you should review the privacy policy of that service. If you are a member of a third party service, the aforementioned connections may allow that service to connect your visit to our site to your personal data.
AI and automated processing
Beryl is an AI product: to explore your application and author tests, our agent reasons over the content of the pages it visits — the page's HTML/DOM, accessibility snapshots, and screenshots. To do this, and to operate the service reliably, we send that content and the related test inputs and outputs to a small set of AI and analytics providers acting as our sub-processors. We name each of them here so you know exactly which AI vendors process your data and for what purpose:
- Google (Gemini API)— the primary model our agent uses to reason about your application. Data received: page content the agent is examining (DOM, accessibility snapshots, screenshots) together with its own instructions, to decide the next test step and generate test code.
- OpenAI— a cross-provider fallback used only when the primary model is unavailable during an outage. It receives the same class of reasoning input as Google (Gemini API), and only for the transient calls that fail over to it; there is no steady-state traffic to OpenAI.
- PostHog(US cloud) — product and LLM analytics. Data received: the inputs and outputs of the model calls above, used to analyse and improve how the agent performs.
Your data is not used to train third-party AI models. We access these models through their paid, business APIs. Under the applicable terms — the Google Cloud / Gemini API terms and the OpenAI API data-usage policy — content submitted via the API is not used to train or improve the provider's models, and Beryl does not consent to any such use. PostHog receives this data only to operate observability and analytics for us, as our sub-processor, and not to train its own models.
The full, current list of Beryl's sub-processors — including these AI and analytics providers alongside our infrastructure and operational vendors — is maintained at https://trust.beryl.so/subprocessors.
Transferring personal data to the U.S.
Beryl has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Beryl's services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of "adequacy" from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Beryl is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved.
Depending on the circumstance, Beryl also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Beryl in a manner that does not outweigh your rights and freedoms. Beryl endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Beryl and the practices described in this Privacy Statement. Beryl also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Beryl has received zero government requests for information.
For more information or if you have any questions, please contact us at [email protected]
Data Subject rights
The European Union's General Data Protection Regulation (GDPR) and other countries' privacy laws provide certain rights for data subjects. Data Subject rights under GDPR include the following:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right of data portability
- Right to object
- Rights related to automated decision making including profiling
This Privacy Notice is intended to provide you with information about what personal data Beryl collects about you and how it is used.
If you wish to confirm that Beryl is processing your personal data, or to have access to the personal data Beryl may have about you, please contact us.
You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Beryl might have received the data from Beryl; what the source of the information was (if you didn't provide it directly to Beryl); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Beryl if it is inaccurate. You may request that Beryl erase that data or cease processing it, subject to certain exceptions. You may also request that Beryl cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Beryl processes your personal data. When technically feasible, Beryl will—at your request—provide your personal data to you.
Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Beryl will provide you with a date when the information will be provided. If for some reason access is denied, Beryl will provide an explanation as to why access has been denied.
For questions or complaints concerning the processing of your personal data, you can email us at [email protected]. Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation's data protection authority.
Security of your information
We adopt industry-standard technical and organisational measures to protect Personal Data from unauthorised access, disclosure or destruction. However, no method of transmission or storage is 100% secure; you acknowledge residual risk.
Data storage and retention
Your personal data is stored by Beryl on its servers, and on the servers of the cloud-based database management services Beryl engages, located in the United States. Beryl retains service data for the duration of the customer's business relationship with Beryl and for a period of time thereafter, to analyze the data for Beryl's own operations, and for historical and archiving purposes associated with Beryl's services. Beryl retains prospect data until such time as it no longer has business value and is purged from Beryl systems.
All personal data that Beryl controls may be deleted upon a verified request from Data Subjects or their authorized agents. To submit a formal Data Deletion Request, please use our Data Deletion Request page, which includes a request template and full details on the process. Once we receive your request, our privacy team will reach out to verify your identity, and upon successful verification, will proceed with deletion and send you a confirmation. We aim to fulfill all verified deletion requests within 30 calendar days.
For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at: [email protected]
Children's data
We do not knowingly attempt to solicit or receive information from children.
Questions, concerns or complaints
If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:
Vibemonitor, Inc.
2261 Market Street STE 46185
San Francisco, CA 94114 US