Privacy policy

Need 12 Testers is a credit-based platform for reciprocal Google Play closed testing. Developers earn credits by testing others' pre-release Android apps, then spend credits to run their own closed-testing campaigns. This policy explains what we collect to operate that service and how we use it.

What the product does

You create an account, set up a tester profile (country, languages, time zone, devices), and either accept matched test invitations or activate campaigns for apps you own. Assignments cover closed-test opt-in, install, first use, timed checkpoints, and private structured feedback with optional evidence. Credits and reputation track completed work. There is no public tester directory, no user-to-user messaging search, and no paid plans or card payments on the platform.

Account and profile data

Sign-in is primarily through Google (openid, profile, and email scopes only). We store your email, Google subject ID, and display name from that sign-in. We also store profile fields you provide for matching: company, country, time zone, languages, biography, and device details (manufacturer, model, Android version).

Emails and Google subject IDs are not shown publicly to other users. Display names and campaign-related identity needed for testing are visible to the other party in an assignment and to moderators.

Campaign, assignment, and feedback data

For campaigns we store app metadata you submit (name, package, opt-in and support links, icons, instructions, requirements, questionnaires). For assignments we store progress timestamps, checkpoints, dropout reasons, the device used, and credits reserved or earned. Structured feedback, scores, questionnaire answers, and checkpoint evidence (screenshots) are private to the campaign owner and platform moderators. Evidence is stored in object storage and shared only through temporary signed URLs when needed.

Credits, reputation, and safety

We keep an append-only credit ledger and reputation events so matching stays fair and abuse can be reviewed. Reports, disputes, moderation actions, and an audit log (including hashed IP and user agent where recorded) support trust and safety. Mobile sessions may store refresh-token hashes and creation IP for signed-in devices.

Notifications and email

We send in-app notifications about invitations, assignments, and campaigns. Optional email (checkpoint reminders and campaign updates) can be turned off in Settings. Transactional email is delivered through our email provider when email is enabled.

Third parties we rely on

  • Google: account sign-in (and Google Play closed testing you run yourself outside this product)
  • Our email provider: transactional notifications you opt into
  • Cloud infrastructure: hosting, bot protection, and evidence object storage
  • Operational logging and metrics for reliability and security (not a consumer advertising product)

Need 12 Testers is not affiliated with Google. We do not sell personal data or run paid advertising based on your account.

Cookies

The website uses a small set of cookies that are required to sign you in and keep the service secure. We do not use advertising cookies, social plugins that track you across sites, or third-party marketing pixels on need12testers.com.

Cookies we set (or that appear during sign-in):

  • Authentication (.AspNetCore.Identity.Application): keeps you signed in on the web after Google sign-in. HttpOnly session cookie for the application.
  • Anti-forgery (.AspNetCore.Antiforgery.*): protects forms and authenticated requests from cross-site request forgery.
  • Sign-in correlation (short-lived .AspNetCore.Correlation.* cookies during Google OAuth): completes the redirect back from Google and is not used for advertising.

Interactive pages (Blazor Server) keep a live connection to our servers while you use the dashboard. That connection relies on your authentication cookie; we do not set a separate advertising or analytics cookie for it.

The Flutter mobile app does not use these website cookies. It stores access and refresh tokens in the device secure storage instead.

If traffic passes through Cloudflare (DNS/proxy or Turnstile bot checks), Cloudflare may set its own security cookies (for example challenge or bot-management cookies). Those are controlled by Cloudflare’s policies, not by us for advertising. You can clear site cookies in your browser or sign out; clearing the authentication cookie ends your web session.

Retention, export, and deletion

We keep account, campaign, assignment, credit, and moderation records as needed to operate the platform, resolve disputes, and prevent abuse. Signed-in users can download a personal data export from Settings. Account deletion is also self-serve from Settings: after you confirm, you are signed out, open campaigns and assignments are cancelled, matched testers or campaign owners are notified, and open tester slots may be refilled. Your account then enters a 14-day cancel window. If you do not cancel, we anonymize personal data and mark the account deleted. Requests are audited. An open report against your account, or an open dispute you filed, blocks deletion until it is resolved; you can also contact support for help. Some records may be retained in anonymized or aggregated form, or where we must keep them for legal or safety reasons.

Contact

Privacy questions: support@need12testers.com. See also the testing policy, terms of service, and FAQ.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.