bugmanager_
TermsPrivacyRefunds

Privacy Policy

Version 1.0.1 — effective 2026-08-11

This is a draft prepared without review by a licensed attorney. It describes what the product actually does today; have it reviewed before relying on it, especially the international-transfer and rights sections if you expect customers in the EU/UK or California.

This Privacy Policy explains what BugManager, operated by Ogo-Oluwa Alege ("we", "us"), collects, why, and what you can do about it.

1. What we collect

Account data (from Google Sign-In): your email address and display name. We never see or store your Google password.

Billing data: handled by Stripe. We store your Stripe customer and subscription IDs, your plan, and payment status — never your card number, which goes directly to Stripe.

Project & bug report data: when your end users submit a bug report through your widget, we may collect the report description, page URL, console errors, viewport size, user agent, and — only if you've enabled it for that project — a snapshot of specific localStorage/ sessionStorage keys you've explicitly allow-listed. This is your data to configure; we don't capture browser storage unless you turn it on and name the keys.

Usage data: agent-run logs (what our automated triage decided and why), API request metadata, and rate-limit counters, used to operate and secure the Service.

2. How we use it

  • To operate the Service: triage and categorize reports, run the dashboard, send the notifications you configure.
  • To process payments and manage subscriptions.
  • To respond to support requests.
  • We do not sell your data or your customers' data, and we do not use Customer Content to train AI models.

3. Who we share it with (subprocessors)

We use the following third-party services to operate BugManager. Each processes a limited slice of data as described:

Subprocessor What it handles
Google (Sign-In) Authenticates your account; we receive your email/name, never your password.
Google Cloud Vertex AI (Gemini) Receives bug report content (description, console errors, URL) to perform automated triage, categorization, and fix suggestions.
Stripe Processes payments and stores payment methods; we never receive full card numbers.
Neon Hosts our Postgres database (all product data).
Google Cloud Run Hosts the application itself.

We may add or change subprocessors as the Service evolves; material changes will be reflected here with an updated version/date.

4. Data retention & deletion

  • Bug report data is retained per your project's configured retention window (visible and adjustable in your project's Settings tab), then automatically deleted.
  • Account deletion: when you delete your account, it's deactivated immediately and your data is permanently purged within 30 days. This window exists so an accidental deletion can be recovered — contact contact@bugmanager.tech within 30 days if you deleted by mistake.
  • Billing records: Stripe retains transaction records independently of account deletion, as required for tax and accounting purposes.

5. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, email contact@bugmanager.tech. We'll respond within a reasonable time, and no later than any legally required deadline in your jurisdiction.

6. Cookies & local storage

We use browser localStorage to keep you signed in (an opaque session token — not a tracking identifier) and to remember dashboard preferences. We don't use third-party advertising trackers.

7. Children's privacy

The Service is not directed at children under 13 (or the equivalent minimum age in your jurisdiction), and we don't knowingly collect personal data from them.

8. International data transfers

Our infrastructure (Google Cloud, Neon) may process and store data in regions outside your own. (Placeholder — needs review: add region-specific detail and a transfer mechanism, e.g. SCCs, if you expect EU/UK customers.)

9. Security

Passwords are never stored — authentication is delegated entirely to Google. API keys and session tokens are stored as one-way hashes, never in plaintext. All traffic is encrypted in transit (TLS).

10. Changes to this policy

Material changes update the version and effective date at the top of this page.

11. Contact

Privacy questions or requests: contact@bugmanager.tech