We collect what's needed to run BugCatch: your account details, the bug reports your team captures, and basic usage telemetry. We don't sell any of it, and we don't train models on it. Bug report content belongs to the workspace that captured it — we process it on their instructions. Redaction runs before storage, and on paid plans content is encrypted at rest. This summary has no legal effect; the sections below do.
Scope, and which hat we wear
BugCatch is a product of Sphoro (sphoro.com). This policy covers [registered entity name] of [registered address] ("BugCatch", "we"), and applies to the BugCatch website, browser extension, SDK, API and dashboard.
We handle personal data in two distinct roles, and the difference matters:
- As controller — for data about our own customers: account holders, workspace members, billing contacts, people who email us, and visitors to this website. We decide why and how that data is processed, and this policy is our notice to you.
- As processor — for the content of bug reports. That data belongs to the workspace that captured it. We process it on that customer's instructions, under our terms and any data processing addendum they've signed. If you were recorded in someone's bug report, if you were recorded by someone else tells you who to contact.
What we collect
Account and workspace data
- Name, email address, password hash, and profile image if you set one.
- Workspace name, membership list, roles, and project configuration.
- Integration credentials and tokens for the trackers you connect, held encrypted.
Billing data
- Plan, seat count, billing period, invoice history, and billing address or tax ID.
- Card details are collected and stored by [payment processor], not by us. We see a token, the last four digits, the card brand and the outcome of a charge.
Bug report content
Covered in detail in the next section — it's the part most worth reading.
Usage and technical data
- Server logs: IP address, timestamp, request path, status code, user agent.
- Product events: which features are used, and errors thrown by our own software.
- Email delivery status for transactional messages we send you.
Support and marketing
- The content of emails and support conversations you send us.
- Where you've opted in, your email for product announcements — unsubscribe in one click, at any time.
What's inside a bug report
When someone captures a bug, the report can contain any of the following, depending on how the project is configured and which capture was used:
| Component | What it can contain |
|---|---|
| Screenshot | Whatever was on the page, including any personal data displayed at the time. Fields you mark as private are blurred before capture. |
| Screen recording | A recording of a tab, window or screen, with optional microphone audio and the reporter's narration. |
| Rewind buffer | The last ~2 minutes of screen activity. Held in a local, in-memory buffer and discarded continuously — nothing is uploaded unless the reporter presses Rewind. |
| Console logs | Errors, warnings and stack traces, which may include values from your application. |
| Network activity | Request URLs, methods, status codes, timings, and headers or payload fragments — after redaction rules have been applied. |
| Environment | Browser and version, OS, viewport, device pixel ratio, page URL, release build, locale, timezone, and the signed-in user identifier your app supplies. |
| Reporter identity | The name and email of the person filing, plus anything they typed into the description. |
You are the controller of everything the widget captures from them. Telling them what is captured and having a lawful basis for it is your responsibility, not ours — we'll give you whatever technical detail your notice needs. Ask at info@sphoro.com.
Why we process it
- To run the service — store reports, upload and transcode media, run analysis, push issues to your tracker, render the triage queue.
- To authenticate and authorise — sign you in, and check every request against workspace membership and project access.
- To bill you — process subscriptions, apply plan limits, issue invoices.
- To support you — answer questions, and reproduce a problem you report to us.
- To keep it secure — detect abuse, rate-limit, investigate incidents, keep an audit trail of triage actions.
- To improve the product — using aggregated, de-identified usage statistics, never the contents of your bug reports.
- To comply with the law — tax records, and responses to lawful requests.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use bug report content to train machine learning models.
Legal bases
Where the GDPR or UK GDPR applies to our processing as controller:
| Purpose | Basis |
|---|---|
| Providing the service and support | Performance of a contract |
| Billing, tax and accounting records | Legal obligation; contract |
| Security, abuse prevention, audit logging | Legitimate interests — keeping the service safe for everyone |
| Aggregated product analytics | Legitimate interests — improving a product you pay for |
| Product marketing email | Consent, withdrawable at any time |
Where we act as processor, the customer determines the basis. Our processing is governed by their instructions and our data processing addendum.
AI analysis
On plans that include it, reports are sent to Anthropic (Claude) or OpenAI (ChatGPT) and analysed through that provider's API, to produce a summary, a proposed root cause, draft reproduction steps and a suggested severity.
- The workspace chooses which of the two providers is used, under Settings → AI. Only the chosen one receives report content.
- The model sees the report after redaction rules have run.
- Our agreement with the provider prohibits training on the data we send.
- Data is sent for the duration of the request and is not retained by the provider for any purpose beyond that, other than the abuse-monitoring window their terms describe.
- AI analysis can be disabled per project. With it off, nothing leaves our infrastructure for analysis and every other feature works unchanged.
Redaction and encryption
Redaction runs before storage. Configurable rules strip tokens, cookies, authorisation headers, card-number patterns and any pattern you add, out of logs and payloads before the record is written. Because redaction runs before encryption, the stored row never contained the secret in the first place.
Encryption. Data is encrypted in transit with TLS. On Team and Enterprise, content columns are additionally encrypted at rest with AES-256-GCM under a per-workspace data key, itself wrapped by a master key.
In the browser. You can mark elements to blur before capture, and password fields are masked by default.
Redaction is a strong control, not a guarantee. A secret in an unusual place — a value printed into a screenshot, a token in a URL fragment we've no rule for — can still get through. Keep data you must not disclose out of what you capture.
The rest of the controls
- Every request is checked against workspace membership and project access inside a guard, so no endpoint ships without the check.
- Projects are either visible to the whole workspace or restricted to an explicit member list.
- Media is uploaded straight to object storage over a short-lived presigned URL and served the same way — the bytes never sit on an open bucket.
- Triage actions are recorded in an audit trail. Roles are owner, admin, member and viewer, applied per workspace, with SSO/SAML and SCIM on Enterprise.
- Access to production by our own staff is limited to the people who need it and is logged.
International transfers
Our primary infrastructure is in [primary region]. Some sub-processors operate elsewhere, so personal data may be transferred outside your country — including outside the EEA or UK.
Where that happens, transfers are covered by the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), by an adequacy decision, or by another lawful transfer mechanism. Enterprise customers can request data residency in a specific region. Ask at info@sphoro.com for a copy of the clauses we rely on.
How long we keep it
| Data | Retention |
|---|---|
| Bug reports and media — Free | 7 days |
| Bug reports and media — Team | 90 days |
| Bug reports and media — Enterprise | 365 days, or a custom window agreed with you |
| Account and workspace records | For the life of the account, then 30 days |
| Invoices and tax records | As long as tax law requires, typically 6–7 years |
| Server and security logs | Up to 90 days |
| Support conversations | 24 months |
| Backups | Rolling, expiring within 30 days |
You can delete a bug, project or workspace at any time. Deletion removes the record from the live service immediately and works through backups within 30 days. Rewind buffers are never retained at all unless a reporter presses Rewind — the buffer is discarded continuously in the browser.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy;
- correct data that's wrong or incomplete;
- delete data, where we've no overriding obligation to keep it;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- not be discriminated against for exercising any of these rights;
- complain to your data protection authority — in the EU, your local supervisory authority; in the UK, the ICO; in India, the Data Protection Board.
Email info@sphoro.com. We'll verify who you are and respond within 30 days, or tell you why we need longer. There's no charge unless a request is manifestly excessive.
Under India's Digital Personal Data Protection Act, you may also nominate someone to exercise your rights if you're unable to. Our grievance officer is listed at the foot of this page.
If you were recorded by someone else
If your data appears in a bug report captured by one of our customers — you used their product, or you appear in a recording they made — that customer is the controller. We hold the data on their behalf and can't unilaterally hand it over or delete it.
Contact them first. If you can't identify or reach them, email info@sphoro.com with whatever detail you have and we'll route the request to the right workspace and follow up until it's dealt with.
What the extension can see
The extension requests the permissions listed on its Chrome Web Store page. In practice:
- It captures only when a user starts a capture, or into the local Rewind buffer when Rewind is enabled for that workspace.
- The Rewind buffer lives in an isolated offscreen document with a bounded memory cap, holds roughly the last two minutes, and is overwritten continuously. If nobody presses Rewind, nothing is ever uploaded.
- It does not read page content in the background, does not track browsing history, and sends nothing to us outside an explicit capture.
- It works on any site, including localhost and staging behind authentication — which is exactly why the point above matters.
Children
BugCatch is a tool for software teams and isn't directed at children. We don't knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, email info@sphoro.com and we'll delete it.
Security incidents
If a breach affects your personal data, we'll notify the affected customers without undue delay and, where required, within 72 hours of becoming aware — with what we know, what we're doing, and what you should do. We'd rather send an early notice with incomplete detail than a tidy one three weeks late.
To report a vulnerability, email info@sphoro.com. We won't pursue legal action against good-faith research that respects our users' data and gives us reasonable time to fix the issue.
Changes to this policy
We'll update this page as the product changes. Material changes are announced by email to workspace owners and in the dashboard at least 30 days before they take effect. Every version is dated, and superseded versions are available on request.
Contact us
Privacy questions, data requests and grievances all reach a person, not a queue.
- Privacy & data requests
- info@sphoro.com
- Security
- info@sphoro.com
- Data protection / grievance officer
- [name], reachable at info@sphoro.com
- EU / UK representative
- [name and address, if required]
- Post
- Sphoro — [registered entity name, registered address]