Privacy Policy

Effective 24 July 2026

This policy explains what BugClip collects, why, and who it's shared with. It covers two different kinds of data, because BugClip sits between two groups of people.

Two roles

  • Account data — information about you, our customer. For this we are the data controller.
  • Captured report data — what the widget records on your websites about your end users. For this you are the controller and BugClip is your processor: we handle it on your behalf and under your instructions. You're responsible for giving your end users appropriate notice and obtaining any required consent.

What we collect

Account data. When you sign up we collect your email address and, if you use Google sign-in, the basic profile your provider returns. We store the workspaces, projects, and settings you create.

Captured report data. When one of your users submits a report, the widget captures:

  • the screen recording or screenshot they chose to share;
  • the reporter's typed note, if any;
  • console logs and JavaScript errors from the page;
  • failed network request metadata — method, URL, status code, and duration;
  • a click trail (breadcrumbs) — the labels of elements interacted with, form submissions, and in-page navigation;
  • browser environment — user agent, viewport and screen size, language, timezone, platform, device memory, connection type, and referrer.

What we deliberately don't capture

The widget is built to avoid sweeping up sensitive data. It does not capture the values typed into form fields, the bodies or headers of network requests, or cookies and stored credentials. Failed requests are recorded as metadata only. This is a design choice, not a setting you have to configure.

How we use data

  • to provide the Service — store reports and show them to you;
  • to deliver reports where you've asked, such as to a Slack channel you connect;
  • to operate, secure, and improve the Service;
  • to contact you about your account and important changes.

We don't sell your data or your end users' data, and we don't use captured report data to build advertising profiles.

Free vs Pro

On the Free plan, technical context (console, errors, failed requests, click trail, environment) is discarded at upload rather than stored — we don't hold data you aren't paying us to hold. On Pro, that context is stored and shown on each report. See Plans & billing.

Who we share data with

We use a small set of sub-processors to run the Service. Each handles data only to provide their part of it:

  • Supabase — database, authentication, and file storage for recordings and screenshots.
  • Vercel — application hosting and delivery.
  • Paddle — merchant of record for paid plans; handles payment and billing data. We don't receive or store your full card details.
  • Google — only if you choose Google sign-in, to authenticate you.
  • Slack — only if you connect a Slack webhook, to deliver reports to your channel.

Share links

You can create a share link for a report to show it to someone outside your workspace. A share link makes that report — including its recording, note, and any captured context — viewable by anyone who has the link, until you revoke it. Links are unlisted and marked not to be indexed by search engines, but treat them as public: don't share a report you wouldn't want forwarded. Revoking a link takes effect immediately.

Retention and deletion

Reports are kept until you delete them or close your account. You can delete an individual recording from its page in the dashboard, which removes both the record and the stored file. You can delete your account yourself from your Account page in the dashboard — this permanently removes your workspaces, projects, and reports, including stored recordings. You can also email us and we'll do it for you.

Security

Recordings and screenshots are stored in a private bucket and served only through short-lived signed links. Access to your data is restricted to your workspace by row-level security. No system is perfectly secure, but we take reasonable measures to protect your data.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. For account data, contact us and we'll help. For captured report data, your end users should contact you as the controller; we'll support you in responding.

International transfers

The Service and its sub-processors may process data in countries other than yours. Where we transfer personal data across borders, we rely on our sub-processors' safeguards for such transfers.

Children

The Service isn't directed to children, and you shouldn't use the widget to knowingly collect data from children in a way that isn't permitted by law.

Changes

We may update this policy. If a change is material, we'll take reasonable steps to let you know. The effective date above always reflects the current version.

Contact

Questions or requests about privacy? Email us at support@bugclip.dev.