Privacy Policy
Last updated: 8 July 2026 · Bugbase browser extension & dashboard
Bugbase is an internal-first bug-reporting tool: a browser extension and a dashboard that let your team and clients report bugs on the page they are looking at. This policy explains what data Bugbase processes, why, on what legal basis, who it is shared with, and the rights you have. Bugbase is privacy-first by design - it only processes what you explicitly choose to capture, it does not sell your data, does not serve ads, and does not track you across websites.
1. Who we are
The Bugbase extension and dashboard software is provided by Bugbase ("we", "us"). For privacy questions, data-subject requests, or complaints, contact support@bugbase.dev.
Controller vs processor. When you use Bugbase inside an organization, your organization is the data controller - it decides which projects, sites, and members exist and how long reports are kept - and Bugbase acts as a processor acting on its instructions. Where Bugbase operates a hosted backend on your organization's behalf, we process personal data only to provide the service and under a data-processing agreement. If you self-host the Bugbase backend, your organization is both controller and operator.
2. Data we process
The extension processes data only when you take an action (sign in, enable reporting on a tab, or capture and submit a report). We group it as:
- Account data: your email address, obtained at sign-in (single sign-on with your existing Bugbase session, or a one-time email code), your display name, chosen language, and your role and project membership. Used to authenticate you and attribute your reports.
- Report content you capture: screenshots or a selected region of the current tab; console logs; network request/response metadata (method, URL, status, timing - not full bodies unless you include them); the page URL and title; browser, operating-system and viewport details; and, if you record one, a DOM session replay of your interaction with the page.
- Discussion content: comments, @mentions, reactions, and files you attach to a report.
- Local device settings: your session token, selected project, UI language, and widget position, stored locally in your browser so you stay signed in. These stay on your device and are not shared.
- Diagnostics: minimal server logs (timestamps, error codes) needed to operate and secure the service.
We do not collect your browsing history, and we capture nothing on pages where you have not started a report. The reporting widget only appears on the site URLs configured in your organization's Bugbase project.
3. Sensitive-data masking
Before a DOM session replay leaves your browser we mask password fields, credit-card fields, and any element you mark with data-bb-mask, and we mask input values by default. This masking happens on your device. You are responsible for not deliberately capturing special-category data (health, biometric, etc.); if a screenshot could show such data, mask it before submitting.
4. How we use data and our legal bases
We process the above data to record, reproduce, triage, route, and fix the bug you reported, to notify the right people, and to keep the service secure. Under the GDPR, our (or your organization's) legal bases are:
- Contract (Art. 6(1)(b)) - to provide the bug-reporting service you or your organization signed up for.
- Legitimate interests (Art. 6(1)(f)) - to secure the service, prevent abuse, and improve reliability, balanced against your rights.
- Consent (Art. 6(1)(a)) - where required, e.g. optional features; you may withdraw it at any time.
- Legal obligation (Art. 6(1)(c)) - where we must retain or disclose data by law.
5. AI triage
To speed up triage, the text of a report (title and description) and, for the knowledge-base feature, documents your organization uploads may be sent to third-party AI providers - Anthropic (Claude) for classification and OpenAI for search embeddings - strictly to classify severity/type and to answer questions from your own project documents. These providers act as sub-processors, do not use the data to train their models on an opt-out API basis, and receive only what is needed for the task. AI features are only active when your organization has enabled them and provided its own API keys.
6. Sharing and sub-processors
Report data is transmitted over HTTPS to your organization's Bugbase backend and is visible only to members of the relevant project, according to their role. We do not sell or rent data and do not share it with advertising or data-broker services. We use a limited set of sub-processors purely to run the service:
- Object storage (self-hosted MinIO or your organization's chosen provider) - stores screenshots, replays, and attachments.
- Email delivery - sends sign-in codes and invitations.
- AI providers - as described in section 5, when enabled.
7. International transfers
Depending on where your organization hosts Bugbase and which sub-processors it enables, data may be processed outside your country. Where personal data of EEA/UK individuals is transferred, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses.
8. Data retention
Report and discussion data is retained by your organization's Bugbase backend for as long as your organization keeps it, according to its retention settings, and is deleted when a task, project, or organization is deleted. Local extension settings remain on your device until you sign out or remove the extension. Minimal security logs are kept for a limited period.
9. Security
We protect data with encryption in transit (HTTPS), signed and httpOnly session cookies, role-based access control scoped to project membership, and object storage that is not publicly reachable. No system is perfectly secure, but we apply industry-standard measures appropriate to the data.
10. Your rights
Subject to applicable law - including the EU/UK GDPR, the California CCPA/CPRA, and other applicable data-protection laws - you may request to access, correct, delete, export, or restrict/object to the processing of your personal data, and to withdraw consent. Because your organization is usually the controller, please direct requests to your organization first; we will assist it in responding. You may also contact us at support@bugbase.dev, and you have the right to complain to your local data-protection authority.
11. Cookies and local storage
Bugbase uses a small number of strictly-necessary cookies and local-storage entries - a signed session cookie to keep you logged in, a theme/language preference, and the extension's local settings. We do not use advertising or cross-site tracking cookies.
12. Browser permissions
The extension requests permissions strictly to provide bug reporting: injecting the reporting widget on the tab you choose, reading your Bugbase sign-in cookie for single sign-on, capturing a screenshot of the current tab, storing your session locally, and - for the optional device simulator - emulating devices and framing sites. It executes no remotely-hosted code; every script ships inside the extension package.
13. Children
Bugbase is a workplace developer tool, not directed to children, and we do not knowingly collect data from anyone under 16.
14. Changes to this policy
We may update this policy from time to time; material changes will be reflected here with a new "last updated" date. Continued use after a change takes effect means you accept the updated policy.
15. Contact
Questions, requests, or complaints about privacy: support@bugbase.dev. See also our Terms & Conditions.