Privacy policy
Last updated: October 11, 2026
Bugcap is a Chrome extension that records bug reports, plus the website bugcap.io where you can share them as links. This policy explains what data each part handles, what we do with it, and the choices you have. If you have questions, email [email protected].
The Chrome extension
The extension captures nothing until you start a recording, and it stops capturing when the recording ends. A recording contains:
- Video of the tab, window or screen you choose to record.
- Audio from your microphone, only while it's unmuted. The mic starts muted for every recording.
- Console logs, warnings and errors from the recorded page.
- Network requests made by the page: URL, method, status, timing, and the response bodies of fetch and XHR requests.
- Steps: clicks, form field changes, form submits and page navigations. Typed values are never recorded, and nothing is captured from password fields.
- Device information such as browser, operating system, screen size, language and connection type, plus the page URL and title.
So that a report can show what happened just before you pressed record, the extension's page script keeps the last 200 console and network events in the page's own memory. They're added to a report only when you start a recording, and are never sent anywhere otherwise.
Reports are stored locally in your browser. Exports (PDF, Markdown and ZIP) are files saved to your device. Nothing is sent to us unless you choose "Share via link".
Your bugcap.io account
You need an account only to share reports as links. For an account we store:
- Your name, email address and a hashed password. If you sign in with Google or GitHub instead, we receive your name, email address and profile picture from that provider.
- The date you accepted our Terms of Service and this policy.
- Session records for signed-in browsers, including IP address and browser user agent.
- Tokens that connect the extension to your account. They're stored hashed, and you can revoke them from your dashboard.
Shared reports
When you share a report, we store the video, the report data (logs, network requests, steps and device information), a thumbnail and a short preview animation. We also store the report title, page URL, duration, file size, a view count and when it was first viewed.
Anyone with the link can view a shared report. Links use random, unguessable IDs and share pages ask search engines not to index them. Review a report before you share it, because it contains what was on screen and in the logs. You can delete a share from your dashboard at any time, which also deletes its files.
Product updates
You can sign up on bugcap.io to get occasional product updates by email. You don't need an account. For this we store your email address, your subscription status, where you signed up, and when you signed up, confirmed and unsubscribed. You're added only after you click the confirmation link we email you, and every update includes a one-click unsubscribe link.
How we use data
We use data to provide the service: to sign you in, host and show your shared reports, enforce plan limits such as the amount of shared video, and keep the service secure. We also use your email address to send account emails: a welcome email when you sign up, password reset links and password change notices, and a one-time notice when someone first views a report you shared. If you subscribe to product updates, we use that email address only to send those updates, and you can unsubscribe at any time. Signing up for an account doesn't subscribe you. We don't sell data or show ads.
Website analytics
To understand how people use bugcap.io and improve it, the website uses Google Analytics and Microsoft Clarity on every page, including shared report pages. They collect pages visited, referrers, approximate location, device and browser information, and how you interact with the page, such as clicks, scrolling and mouse movement. Clarity also makes session recordings and heatmaps of how pages are used, so what's shown on a page, including a shared report, can appear in those recordings. Both services set their own cookies. Apart from these, the only cookies bugcap.io sets are for signing in. The Chrome extension doesn't use either service.
Service providers
- Railway hosts the website, the database and file storage for shared reports.
- Google and GitHub handle sign-in, only if you choose to sign in with them.
- Resend delivers account emails and product update emails, and receives your email address and the content of those emails.
- Google Analytics measures website usage.
- Microsoft Clarity measures website usage and records sessions and heatmaps.
We may also disclose data when the law requires it.
Retention
Shared reports are kept until you delete them or your account is deleted. Account data is kept until your account is deleted. Product update subscriptions are kept until you ask us to delete them; after you unsubscribe we keep only the record that you did, so we don't email you again. Reports stored by the extension stay in your browser until you delete them or uninstall the extension.
Your choices
- Delete shared reports and revoke extension tokens from your dashboard.
- Use the extension without an account. Local recording and exports never need one.
- Unsubscribe from product updates with the link in any update email.
- Block analytics on bugcap.io with your browser's tracking protection or a content blocker. The site works the same without it.
- To delete your account or get a copy of your data, email [email protected]. Self-serve account deletion isn't available yet, so we handle these requests by hand.
Security
Data is sent over HTTPS. Passwords and extension tokens are stored hashed, and shared files are served through short-lived signed URLs. No system is perfectly secure, so please contact us if you find a problem.
Children
Bugcap isn't meant for children under 13, and we don't knowingly collect data from them.
Chrome Web Store Limited Use
The use of information received from the Bugcap extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this policy
If we change this policy, we'll update the date at the top of this page. Significant changes will be announced on the site.
Contact
Questions or requests about privacy: [email protected]. See also our Terms of Service.