Privacy Policy
We take privacy very seriously. These privacy policy ("Terms") govern your access to and use of the BugByBug website, application, and related services (collectively, the "Service").
Last Updated: 4 September 2026
Welcome to BugByBug ("we," "our," or "us"). We build developer tooling that helps engineering teams detect, track, and resolve application errors. This Privacy Policy explains how we collect, use, store, and share information when you use our platform, including our website, API, and SDK (collectively, the "Services").
Please read this policy carefully. By using our Services, you agree to the practices described here. If you do not agree, please discontinue use of the Services.
Who This Policy Applies To
This policy covers two distinct groups:
- Account holders ("Customers") — developers and organizations that register for a BugByBug account to monitor their applications.
- End users — individuals who use a Customer's application that has integrated the BugByBug SDK. End users interact with BugByBug indirectly.
Where this policy applies differently to each group, we say so explicitly
Lawful Bases for Processing Personal Data
Under the EU GDPR (Article 6) and UK GDPR, we are required to identify a lawful basis before processing personal data. The table below sets out each processing activity, the data involved, and the legal basis we rely on.
| Processing Activity | Data Involved | Lawful Basis |
|---|---|---|
| Creating and managing your account | Name, email address, hashed password | Contract processing is necessary to perform the contract for the Services (Art. 6(1)(b)) |
| Email/password authentication | Email address, hashed password | Contract necessary to provide access to the Services (Art. 6(1)(b)) |
| Google Sign-In | Name, email address, Google identity token | Contract necessary to create and authenticate your account (Art. 6(1)(b)) |
| Sending transactional emails (verification, password reset, invitations) | Email address, Name | Contract necessary to deliver core account functionality (Art. 6(1)(b)) |
| Session management (cookies and tokens) | Access token, refresh token | Contract strictly necessary to keep you authenticated during use (Art. 6(1)(b)) |
| Ingesting and storing error telemetry via SDK | IP address, user agent, stack trace, end-user identifiers, browser/OS data | Legitimate interests — we and our Customers have a legitimate interest in detecting, diagnosing, and resolving application errors. This interest is not overridden by the rights of end users given the technical and security nature of the data (Art. 6(1)(f)) |
| IP address collection | IP address | Legitimate interests to associate errors with geographic context and to prevent abuse of our ingest endpoint (Art. 6(1)(f)) |
| GitHub and Slack integration | Repository metadata, Slack workspace tokens | Contract — necessary to provide the integration features you have enabled (Art. 6(1)(b)) |
| AI-powered error analysis | Error content, stack traces | Legitimate interests — to provide automated analysis features that improve debugging outcomes for Customers (Art. 6(1)(f)) |
| Recording AI usage metrics | Project identifier, token counts, duration | Legitimate interests — internal billing reconciliation and service improvement (Art. 6(1)(f)) |
| Organization membership and invites | Name, email address, role | Contract — necessary to manage team access to your organization (Art. 6(1)(b)) |
| Complying with legal obligations | Any data required by law | Legal obligation (Art. 6(1)(c)) |
Legitimate Interests Balancing
Where we rely on legitimate interests as our lawful basis, we have assessed that our interests are genuine, that processing is necessary to achieve them, and that they are not outweighed by the interests or fundamental rights of affected individuals. In particular:
- Error telemetry data is technical in nature and collected for the purpose of improving application reliability, not for profiling or marketing.
- IP addresses are not used to identify individuals for commercial purposes and can be anonymized at the Customer's discretion.
- Customers retain control over what data their SDK transmits and are responsible for their own lawful basis assessment in relation to their end users.
If you wish to object to processing based on legitimate interests, see Section 14 (Your Privacy Rights).
Sign In with Google
You may create a BugByBug account or log In using your Google account via Google Sign-In ("Continue with Google").
What we receive from Google
When you choose to sign in with Google, Google shares the following information with us based on the permissions you grant:
- Your full name (first and last name)
- Your Google account email address
- A cryptographically signed identity token confirming your identity
What we do not receive or store
We never receive, request, or store your Google password, recovery codes, or any other Google account credentials. The identity token we receive is validated once at sign-in and is not retained after your session is established.
What we do with this data
We use this information solely to create or locate your BugByBug account. If no account exists for your Google email address, one is created automatically and a welcome email is sent to you. If an account already exists, you are logged in. Your email address becomes your primary account identifier within BugByBug.
Google's own privacy practices
Your use of Google Sign-In is also governed by Google's Privacy Policy. We encourage you to review it to understand how Google handles your data before, during, and after the sign-in process.
Revoking Google access
You may revoke BugByBug's access to your Google account at any time through your Google Account permissions page. Revoking access does not delete your BugByBug account; it only removes the ability to sign in via Google. Contact us to set a password or delete your account if needed.
5. Data Controller and Data Processor Relationship (SDK Data)
BugByBug operates as both a data controller and a data processor depending on the context.
5.1 When BugByBug is the Data Controller
For data relating to your BugByBug account — such as your name, email address, and authentication credentials — BugByBug is the data controller. We determine the purposes and means of processing this data and are responsible for it under applicable privacy law.
5.2 When BugByBug is the Data Processor
When you integrate the BugByBug SDK into your application, errors and events from your end users are transmitted to BugByBug and stored on your behalf. In this context:
- You (the Customer) are the data controller. You determine what data is sent to BugByBug via the SDK (including optional end-user identifiers, custom metadata, and breadcrumbs), and you are responsible for ensuring a lawful basis exists for processing that data.
- BugByBug is the data processor. We process end-user data only on your documented instructions — specifically to ingest, store, analyze, and display error telemetry within your BugByBug account.
Your responsibilities as a data controller include:
- Informing your end users that error and diagnostic data may be collected via your application.
- Ensuring your privacy policy discloses the use of third-party error monitoring services.
- Configuring the SDK to avoid transmitting data you do not have a legal basis to process (e.g., sensitive personal data categories).
- Handling end-user data access and deletion requests that relate to data ingested through the SDK (see Section 14 for how we support this).
Data Processing Agreement (DPA)
If you are subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection legislation, a Data Processing Agreement may be required between us. Please contact [email protected] to request a DPA.
6. Sub-Processors and Third-Party Data Recipients
We share personal data with a limited number of trusted third parties who help us deliver the Services. These third parties act as sub-processors, they process data only on our instructions and are contractually bound to protect it.
6.1 Sub-Processor Categories
| Category | Purpose | Data Shared | Location |
|---|---|---|---|
| Cloud infrastructure providers | Hosting of application servers, databases, and storage | All data stored on the platform | United Kingdom and/or United States |
| Transactional email providers | Sending account emails (verification, password reset, invitations, welcome emails) | Email address, name | United Kingdom and/or United States |
| AI analysis providers | Powering AI-assisted error analysis features | Error content and stack traces submitted for analysis | United States |
| Slack Technologies, LLC | Delivering error alert notifications to connected Slack workspaces (only when you enable the Slack integration) | Slack workspace ID, channel ID, error summary | United States |
| Google LLC | Verifying identity during Google Sign-In | Google identity token (validated server-side and not retained) | United States |
We maintain an internal record of the specific vendors within each category. If you are a Customer subject to GDPR or UK GDPR and require a full list of named sub-processors for your own compliance purposes, contact us at [email protected] and we will provide it. We will notify you of any material changes to our sub-processors that may affect your data.
6.2 Other Disclosures
Outside of the sub-processors listed above, we will only disclose personal data to third parties in the following circumstances:
- Legal requirement — where we are required to do so by law, court order, or valid regulatory request.
- Protection of rights — where necessary to protect the rights, property, or safety of BugByBug, our Customers, or the public.
- Business transfers — in the event of a merger, acquisition, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
- With your consent — for any other purpose, only with your explicit prior consent.
We do not sell personal data to third parties. We do not share personal data with third parties for advertising or marketing purposes.
International Data Transfers
BugByBug is registered in the United Kingdom and the United States. We do not have a legal establishment within the European Economic Area. Where EU residents use our Services, their personal data may be transferred to and processed in the UK or US. Whenever we transfer personal data to a country that does not provide an equivalent level of data protection, we ensure appropriate safeguards are in place.
Transfers from the EU
For transfers of personal data from the EEA to the United Kingdom or the United States, we rely on one or more of the following mechanisms under GDPR Chapter V:
- Standard Contractual Clauses (SCCs) — The European Commission's 2021 SCCs are incorporated into our agreements with sub-processors located outside the EEA, including those in the United States.
- UK adequacy decision — The European Commission has recognised the United Kingdom as providing an adequate level of data protection, meaning transfers to BugByBug's UK operations do not require additional safeguards.
Transfers from the UK
For transfers of personal data from the United Kingdom, we rely on:
- International Data Transfer Agreements (IDTAs) — The UK's equivalent of SCCs, issued by the ICO and incorporated into our sub-processor agreements.
- UK adequacy regulations — Where the UK Secretary of State has made an adequacy finding for a specific country.
Your Rights Regarding Transfers
You have the right to request information about the specific transfer mechanisms we use for your data. Contact us at [email protected] with your request.
IP Addresses
When an error event is captured by the BugByBug SDK and transmitted to our platform, the IP address of the end user's device is included as part of the event payload.
Why IP addresses are collected
IP addresses are used to:
- Associate error events with a geographic region for debugging context (e.g., identifying region-specific issues or network failures).
- Detect and prevent abuse of the SDK ingest endpoint.
- Support incident investigation at the request of the Customer.
IP addresses as personal data
Under several privacy regulations, including the EU GDPR, UK GDPR, and the California Consumer Privacy Act (CCPA), IP addresses are considered personal data or personal information because they can be used — alone or in combination with other data — to identify an individual.
We treat IP addresses accordingly:
- They are stored encrypted at rest.
- They are accessible only to authorized BugByBug personnel and to the Customer who owns the project.
- They are subject to the same retention and deletion rules as other personal data (see Section 13).
- They are never sold or disclosed to third parties for advertising or profiling purposes.
IP address anonymization
If you do not wish to collect full IP addresses from your end users, you may configure the SDK to truncate or omit IP addresses before transmission. Please refer to the SDK documentation for configuration options.
Cookies
| Category | Type | Purpose | Duration |
|---|---|---|---|
| X-Access-Token | Essential | Contains your JWT access token to authenticate API requests | Until access token expiry |
| X-Refresh-Token | Essential | Contains your refresh token used to renew your session without re-entering credentials | Until refresh token expiry |
Both cookies are set with the following security attributes:
- HttpOnly — The cookies cannot be read by JavaScript, protecting them from cross-site scripting (XSS) attacks.
- Secure — The cookies are only transmitted over HTTPS, preventing interception over unencrypted connections.
- SameSite=Lax — The cookies are not sent on cross-site requests initiated by third parties, providing protection against cross-site request forgery (CSRF).
- IsEssential=true — These cookies are strictly necessary for the operation of the Services. Consent banners are not required for strictly necessary cookies under most regulatory frameworks, but we disclose them here for transparency.
Cookies We Do Not Set
We do not set:
- Advertising or tracking cookies
- Third-party analytics cookies (e.g., Google Analytics)
- Social media tracking pixels
- Persistent preferences cookies beyond what is necessary for authentication
Managing Cookies
Because our cookies are essential to authentication, blocking or deleting them will prevent you from remaining logged in to BugByBug. You may clear session cookies at any time by logging out, which explicitly deletes both X-Access-Token and X-Refresh-Token from your browser.
You can also manage cookies through your browser settings. For guidance, see:
10. Data Protection Officer (DPO)
Under the EU GDPR (Article 37) and UK GDPR, some organizations are required to appoint a Data Protection Officer. This obligation applies where an organization:
- is a public authority or body;
- carries out large-scale, systematic monitoring of individuals; or
- carries out large-scale processing of special categories of data.
BugByBug has assessed its processing activities and determined that a mandatory DPO appointment is not currently required under applicable law. All privacy-related queries and data subject requests should be directed to our team at [email protected]. We keep this assessment under review as our processing activities evolve.
11. Children and Minimum Age
The BugByBug platform is intended for use by developers, engineers, and business operators. It is not directed at children.
- Minimum age (EU): You must be at least 16 years old to create a BugByBug account, in accordance with Article 8 of the EU GDPR. Some EU member states have set a lower minimum age (no less than 13); if you are registering from one of those states, the applicable local age applies.
- Minimum age (UK): You must be at least 13 years old in the United Kingdom, in accordance with the UK GDPR and the Age Appropriate Design Code.
- Minimum age (all other regions): You must be at least 13 years old, or the minimum age required by the law in your jurisdiction if higher.
We do not knowingly collect personal data from anyone below the applicable minimum age. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete the data without undue delay.
If you are a Customer who operates a service used by children, you are responsible as data controller for ensuring that the BugByBug SDK is configured appropriately and that you have a valid lawful basis for processing children's data (which in most cases requires verifiable parental consent).
12. Automated Decision-Making and Profiling
12.1 Automated Decisions
BugByBug does not make automated decisions about individuals — including Customers or their end users that produce legal effects or similarly significant effects on those individuals. No automated process determines access to financial products, employment, insurance, or any other high-stakes outcome.
12.2 Profiling
BugByBug does not profile individuals for commercial, advertising, or behavioural targeting purposes. The AI-powered error analysis feature analyses error payloads and technical data (stack traces, browser metadata, application context) to assist developers in understanding and resolving software defects. This analysis:
- Is directed at software errors, not at individuals.
- Does not produce profiles of end users or make inferences about their character, preferences, or behaviour.
- Does not generate outputs that are used to make decisions about any individual.
You have the right under GDPR Art. 22 to not be subject to solely automated decision-making that produces significant effects. As we do not engage in such processing, this right is not engaged. However, if you believe automated processing is affecting you in a significant way, contact us at [email protected].
13. Data Retention
We retain different categories of data for different periods depending on their purpose and legal requirements.
13.1 Account Data
| Data | Retention Period |
|---|---|
| Name, email address, account status | For the lifetime of your account, plus 30 days after deletion to allow for recovery before permanent purge |
| Hashed password | Deleted immediately upon account deletion |
| Authentication tokens (access, refresh) | Automatically expire; refresh tokens are invalidated on logout |
| Email verification and password reset tokens | Deleted immediately upon use or expiry |
13.2 Organization and Project Data
Organization and project records, including member roles, API keys, and GitHub integration metadata, are retained for the lifetime of the organization or project within BugByBug. When you delete a project or organization, associated data is scheduled for permanent deletion within 30 days.
13.3 Error and Event Data (SDK-Ingested)
Error records and individual error events are retained for a rolling 60-day window by default. Customers on higher-tier plans may have extended retention periods as defined in their plan terms.
You may manually delete individual errors, projects, or your entire dataset at any time from within the BugByBug dashboard. Deleted data is purged from our systems within 3–5 business days.
13.4 Integration Data
Slack and GitHub integration tokens and configuration are retained for as long as the integration is active. Disconnecting an integration removes the associated tokens from our systems within 30 days.
13.5 AI Analysis Metrics
Aggregated AI usage metrics (token counts, model type, duration) are retained for 12 months for billing reconciliation and service improvement purposes. These records do not contain personal data beyond a project-level identifier.
13.6 Legal and Compliance Holds
Notwithstanding the above, we may retain data for longer periods where required by applicable law, regulation, or a valid legal process (e.g., a court order or law enforcement request). We will notify you of any such hold to the extent permitted by law.
14. Data Deletion and Your Rights
14.1 Deleting Your Account
You may request deletion of your BugByBug account and all associated personal data at any time by:
- Using the account deletion option in your dashboard settings, or
- Emailing [email protected] from the address associated with your account.
Upon receiving a verified deletion request, we will:
- Permanently delete your name, email address, and authentication data.
- Remove you from all organizations you are a member of.
- Anonymize or delete audit logs associated with your account.
- Complete the deletion within 3–5 business days and confirm via email.
14.2 Deleting SDK-Ingested Data
As the data controller for SDK-ingested error data, you (the Customer) are responsible for responding to end-user deletion requests that relate to data processed through the SDK. We support this through:
- Project-level deletion — deleting a project deletes all associated error records and events.
- API-based deletion — you may use the BugByBug API to delete individual error records or groups of errors containing a specific end-user identifier or email address.
- Data export — before deletion, you may export your error data via the dashboard or API.
If you need assistance fulfilling an end-user data subject access or deletion request, contact [email protected].
14.3 Your Privacy Rights
Depending on your location, you may have rights including:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate personal data.
- Right to erasure — request deletion of your personal data ("right to be forgotten").
- Right to restriction — request that we limit how we process your data in certain circumstances.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to certain types of processing.
- Rights related to automated decision-making — we do not make automated decisions about individuals that produce legal or similarly significant effects.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or within the timeframe required by applicable law).
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. For material changes, we will notify you via email or a prominent notice in the dashboard at least 30 days before the changes take effect.
Your continued use of the Services after the effective date constitutes your acceptance of the updated policy.
16. Contact Us and Supervisory Authorities
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
BugByBug
Email: [email protected]
Address: 1111B S Governors Ave, Suite 27904, Dover, DE 19904, United States
Supervisory Authorities
If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the data protection supervisory authority in your country or region without any cost to you.
United Kingdom
Information Commissioner's Office (ICO)
Website: https://ico.org.uk
Telephone: 0303 123 1113
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
European Union
BugByBug is not established within the European Union. EU residents may lodge a complaint with the supervisory authority of the EU member state where they habitually reside, work, or where the alleged infringement occurred. A full list of EU supervisory authorities is maintained by the European Data Protection Board at https://www.edpb.europa.eu.
Other Regions
If you are based outside the UK or EU, you may have the right to contact a local privacy regulator. Please consult the laws of your jurisdiction for details.
Stop spending hours chasing
bugs. Start fixing them
We give your team the context, insights and direction needed to understand what went wrong and move from error to resolution faster.