Draft, not yet reviewed. This document still contains unfilled placeholders and has not been reviewed by a lawyer. Do not rely on it, and do not accept paying customers against it.
Privacy policy
Last updated 6 October 2026
This policy explains what [LEGAL ENTITY NAME] ("BugShot", "we") does with personal data. It covers two different relationships, and the distinction matters.
When you hold a BugShot account, we are the controller of your data and this policy applies to you directly.
When someone submits a bug report through a widget on our customer's website, we are only a processor. That customer decides what is collected and why, and their own privacy notice governs it. Our obligations to them are in the Data Processing Agreement. If you submitted a report and want it removed, contact the site you submitted it on; they can erase it themselves without involving us.
1. Data we hold about account holders
- Email address. Used to sign you in and to contact you about the service.
- Account and project settings. Workspace name, project names, allowed origins.
- Destination credentials. Slack webhook URLs and forwarding secrets, encrypted at rest with AES-GCM and never displayed back to you.
- Session records. To keep you signed in.
- Billing data. Plan, subscription status, and a Stripe customer identifier. We never see or store card numbers; Stripe handles those directly.
- Usage counts. Reports received per month, for quota and billing.
- Audit records. Actions that delete data, export it in bulk, or change access, together with who performed them.
2. Data we process on behalf of customers
Reports submitted through the widget may contain a screenshot, a written description, page address and title, browser and device details, console errors, failed request addresses, a record of recent clicks and navigation, an optional reporter email, and any data the customer chooses to attach through our API.
We also record the submitting IP address for abuse control and delete it automatically after 30 days. The report itself is kept for the customer's plan retention period.
Screenshots can contain anything that was on screen. By default the widget blurs the contents of every input, textarea and select before capture, always blurs password fields, and strips query strings from recorded addresses. Customers can mark further regions for masking or exclusion. We do not inspect screenshot contents.
Every uploaded image is checked to be a real PNG, JPEG or WebP file, and the details a camera or phone hides inside it (GPS position, device model, timestamps, comments) are removed before it is stored. If a customer blocks a sender, we keep a keyed fingerprint of that sender's IP address or email, never the address itself, until the customer unblocks them.
3. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Providing the service to account holders | Performance of a contract |
| Sending sign in links and service notices | Performance of a contract |
| Billing and collecting payment | Performance of a contract |
| Rate limiting and preventing abuse | Legitimate interests |
| Keeping an audit trail | Legitimate interests, and legal obligation |
| Processing submitted bug reports | On the customer's instructions, as processor |
4. Cookies
This dashboard sets a single cookie, bs_session, which keeps you signed in. It is
strictly necessary, so no consent banner is required. We use no analytics, advertising or
tracking cookies.
The sign in form may use Cloudflare Turnstile to check that a person, not a script, is asking for a sign in email. It looks at your browser and connection for that check only, sets no tracking cookies, and is run by Cloudflare, already listed as our sub-processor.
The widget sets no cookies at all and writes nothing to browser storage. It sends reports with credentials omitted. Installing it does not create a cookie consent obligation on our customers' websites.
5. Who else touches the data
We use a small number of sub-processors, listed with their locations and purposes on the sub-processors page. We do not sell personal data, and we do not share it for advertising. If a customer connects an AI agent or another tool, with an API key or by signing in from it, report data goes to that tool on the customer's instruction; that tool is the customer's choice and not our sub-processor. We do not send report data to any AI provider ourselves.
6. International transfers
Our infrastructure is currently hosted in North America. Where personal data is transferred out of the UK or EEA, that transfer relies on Standard Contractual Clauses together with the UK Addendum where applicable.
7. How long we keep things
- Bug reports and screenshots: the customer's plan retention period, from 7 days on the free plan up to unlimited on Business, deleted automatically by a nightly job.
- Submitting IP addresses: 30 days.
- Sign in tokens: 15 minutes, and single use.
- Sessions: 30 days.
- Blocked sender fingerprints: until the customer unblocks the sender or deletes the project.
- Images reported as illegal: removed from the customer's inbox at once and kept sealed only for as long as the law requires.
- Account records: until you close the account, which deletes everything immediately, apart from images reported as illegal.
8. Your rights
If you are in the UK or EEA you have the right to access, correct, erase, restrict, port and object to processing of your personal data. You can export everything and close your account yourself from the Data page in the dashboard. For anything else, write to [CONTACT EMAIL]. You also have the right to complain to your local supervisory authority.
If you are a California resident, you have rights of access, deletion, correction and portability, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under the CCPA.
9. Security
Our technical and organisational measures are described on the security page.
10. Changes
We will post any changes here and update the date above. Material changes affecting account holders will be notified by email at least 30 days in advance.
11. Contact
[LEGAL ENTITY NAME]
[REGISTERED ADDRESS]
[CONTACT EMAIL]