Trust

Privacy

BugBundler keeps core bug data on the client by default so teams can maintain tighter control over sensitive information. This page explains exactly what stays local, what we process, and where.

What stays on your device

  • Screenshots and debug context are captured locally.
  • Reports are exported as portable HTML files that your team controls and distributes.
  • No mandatory third-party report hosting — BugBundler's servers never see report content unless you choose to send it there.

What we do process, and where

Using BugBundler requires an account for your organization. We process the following data to operate that account:

  • Account data — name, email address, company, and role.
  • Billing data — subscription tier, seat count, and invoice history (payment card details are handled directly by Stripe; we never see or store full card numbers).

This data is hosted on Google Cloud within the EU: Cloud Functions run in Finland (europe-north1) and Firestore (our database) is located in Stockholm, Sweden (europe-north2).

Subprocessors

  • Google Cloud / Firebase — hosting, authentication, and database, EU regions (Finland & Sweden).
  • Stripe — payment processing and billing. Stripe is a global processor; card and payment data are handled under Stripe's own PCI-DSS compliant infrastructure and Standard Contractual Clauses govern any transfer outside the EEA.
  • Resend — transactional email delivery (e.g. account and billing notifications). US-based; Standard Contractual Clauses apply.

We don't use analytics, session replay, or crash-reporting SDKs that collect personal data from the extension or the bug reports it generates.

Your rights

Under GDPR you can request access to, correction of, export of, or deletion of your personal data. Contact privacy@bugbundler.com and we'll respond within 30 days. Account data is retained for as long as your organization has an active subscription, plus the period required for billing and tax records.

Documentation for procurement & legal review