Solution

GDPR-ready bug reporting with EU data residency

Most bug-reporting tools require uploading screenshots and session data to a third-party cloud before your team can even see them. BugBundler doesn't need to — and the account data it does process stays in the EU, in Finland and Sweden.

Where your data actually lives

  • Bug report content — screenshots, DOM snapshots, console logs, and network activity — is captured and assembled into a portable HTML file on the reporter's device. There is no feature to upload it to BugBundler's servers at all — sharing a report means sending that exported file yourself, the same way you'd share any other file (email, chat, or attached to a ticket).
  • Account, workspace, and billing data — name, email, company, role, and subscription details — is processed on Google Cloud in the EU: Cloud Functions in Finland (europe-north1) and Firestore in Stockholm, Sweden (europe-north2).
  • No always-on server dependency for the report-capture workflow itself, so there's no cross-border transfer question to answer for the data your reporters care most about protecting.

How that compares

Based on each vendor's published privacy and security documentation as of 2026:

Tool Report data location Notes
BugBundler Stays on-device Account data in Finland/Sweden (EU) by default.
Marker.io AWS EU (Ireland) Requires uploading captures to their cloud.
BugHerd AWS, may move to AU/UK/US Reserves the right to transfer data outside the EU; Australia has no EU adequacy decision.
Jam.dev GCP US (Central) Report data is stored outside the EU by default.
Userback AWS, region unspecified GDPR-compliant; no confirmed EU-only option.

For procurement and legal review

  • A Data Processing Agreement is available covering BugBundler's processing of account and billing data.
  • Full subprocessor disclosure — including Stripe (payments) and Resend (transactional email) — is listed on the Privacy page.
  • Formal certifications (SOC 2, ISO 27001) are not yet obtained — we'd rather say that plainly than overclaim. See the Compliance page for current status and roadmap.

Frequently asked questions

Is BugBundler GDPR-compliant?

BugBundler is built around GDPR's data-minimization principle: bug report content (screenshots, DOM snapshots, console and network logs) is captured and stored on the reporter's device, and BugBundler stores none of it. Sharing a report means sending the exported HTML file yourself, or sending it to your own Jira, which passes through BugBundler's EU infrastructure to reach Jira and is not retained. The account and billing data BugBundler does process (name, email, company, role) is hosted on Google Cloud infrastructure located in the EU, with Cloud Functions in Finland and Firestore in Stockholm, Sweden. A Data Processing Agreement is available on request.

Where is BugBundler's account data physically stored?

Account, workspace, and billing metadata is stored in Google Cloud's europe-north2 region (Stockholm, Sweden) and processed by Cloud Functions running in europe-north1 (Finland). Bug report content itself is not stored on BugBundler's servers by default.

Does BugBundler use any subprocessors outside the EU?

Payment processing (Stripe) and transactional email delivery (Resend) involve subprocessors headquartered outside the EU. Both operate under Standard Contractual Clauses. Full subprocessor details are listed on the Privacy page.

For your DPIA

Hand this page to whoever runs your review

The residency position is short enough to check in a few minutes, and a DPA is available on request before you commit to anything.