Use BugCatch for lawful work, don't try to break it, and pay for the plan you're on. Bug reports you capture stay yours — we process them to run the service and nothing else. We can't promise the service is perfect, and our financial liability is capped at what you paid us in the last twelve months. This summary has no legal effect; the sections below do.
Who these terms are between
BugCatch is a product of Sphoro (sphoro.com), operated by [registered entity name] of [registered address] ("BugCatch", "we", "us"). These terms form a binding agreement between us and you — the individual or organisation using the service ("you", "your", "Customer").
If you accept these terms on behalf of a company, you confirm you're authorised to bind it, and "you" means that company. If you signed a separate written agreement with us, that agreement wins wherever it conflicts with this one.
By creating an account, installing the extension, embedding the SDK, or calling the API, you accept these terms. If you don't accept them, don't use the service.
What the service is
BugCatch captures bug reports from a browser and turns them into tickets your engineers can act on. The service comprises:
- a browser extension that captures screenshots, screen recordings and a rolling Rewind buffer of recent screen activity;
- a browser SDK you embed in your own product so your users can report bugs without installing anything;
- an API and background workers that store reports, run AI analysis, redact sensitive values and push issues to your tracker;
- a dashboard for triage, assignment, commenting and sharing.
Features described on our website reflect the service as it stands today. We build in the open and the product changes; availability, support and changes covers what happens when it does.
Accounts and workspaces
Your data lives inside a workspace. Members of a workspace hold a role — owner, admin, member or viewer — and each role's permissions are enforced by the API, not just hidden in the interface.
- You're responsible for everything done under your account and for keeping credentials and API keys secret.
- You must give accurate account information and keep it current.
- Accounts are for a named person. Don't share one login between people; add members instead.
- The workspace owner controls membership, billing and deletion. Removing an owner's access is on you, not us, when someone leaves your team.
- You must be at least 16, or the age of digital consent where you live, whichever is higher.
Tell us at info@sphoro.com as soon as you suspect unauthorised access.
Plans, limits and fair use
Each plan carries limits on projects, members and retention, listed on our pricing page. Those limits are enforced by the API when you create something new — so exceeding a limit blocks the next creation rather than deleting anything you already have.
Bug reports themselves are unlimited on every plan, including Free. That's a genuine offer, not an invitation to use us as bulk media storage: we may contact you, and ultimately apply a limit, if a workspace's usage is wildly out of proportion to normal bug reporting — automated capture loops, or storage volumes that suggest the service is being used as a general-purpose CDN or backup target.
We'll always reach out before applying any such limit, except where usage is actively degrading the service for others.
Billing, taxes and renewals
Paid plans are billed per member, per month, in advance — monthly or annually, as you choose at checkout. Payments are processed by [payment processor]; we don't store your card details.
- Renewal. Subscriptions renew automatically at the end of each billing period at the then-current price, until cancelled.
- Adding members. Adding a member mid-period is charged pro rata for the remainder of that period, and in full from the next one.
- Removing members. Removing a member reduces the next invoice. We don't refund the current period — see the Cancellations & Refunds policy.
- Taxes. Prices exclude VAT, GST, sales tax and any other applicable tax, which is added at checkout where required. You're responsible for any withholding tax.
- Failed payments. If a charge fails, we'll retry and email you. Access to paid features may be paused until payment succeeds.
- Price changes. We'll give at least 30 days' notice before a price change affects you, and it only takes effect at your next renewal. If you don't accept it, cancel before that date.
Cancellation, refund eligibility and downgrades are covered in full by the Cancellations & Refunds policy, which forms part of these terms.
Trials and the free plan
The Free plan is free for as long as you use it, within its stated limits. Paid trials run for the period stated at signup; unless you cancel before it ends, the subscription continues and the first charge is taken on the date shown in your billing settings.
Trial and free workspaces are provided as-is, with no availability commitment. We may change or withdraw the Free plan's limits with 30 days' notice.
Acceptable use
You agree not to:
- use the service to capture recordings of people who haven't consented where consent is legally required, or on sites you have no right to record;
- deliberately capture and upload payment card data, health records, government identifiers or other sensitive categories of personal data through bug reports;
- upload malware, or content that is unlawful, infringing, or that harasses or defames someone;
- probe, scan, load-test or attempt to bypass the authentication, tenancy or rate-limiting controls of the service, except under a security test we've agreed to in writing;
- reverse engineer, decompile or attempt to extract source code, except to the extent that restriction is unenforceable where you live;
- resell, sublicense or white-label the service, or use it to build a competing product;
- use automated means to create accounts, or share one account across an organisation to avoid per-member pricing;
- remove or obscure any proprietary notice in the software.
Rewind and screen recording capture whatever is on screen, which in a real workflow may include another person's data, a colleague's inbox, or an internal system you're only authorised to view. You are the controller of what you point the recorder at, and you're responsible for having the right to record it.
Your data and what we do with it
You own your content. Bug reports, recordings, logs, comments, project configuration and everything else you or your users put into BugCatch ("Customer Data") remain yours. We claim no ownership over any of it.
You grant us a worldwide, non-exclusive, royalty-free licence to host, store, transmit, transcode, redact, display and otherwise process Customer Data solely to provide, secure and support the service, and to comply with the law. That licence lasts as long as we hold the data and ends when it's deleted.
- We do not sell Customer Data.
- We do not use Customer Data to train machine learning models, ours or anyone else's.
- We do not access the contents of your bug reports except where you ask us to for support, where it's necessary to investigate abuse or a security incident, or where the law requires it.
Where we process personal data on your behalf, we act as your processor and you as controller. The Privacy Policy sets out the detail, including sub-processors, transfers and retention. A data processing addendum is available on request at info@sphoro.com.
Deletion. You can delete a bug, project or workspace at any time. Deletion removes the record from the live service immediately and from backups within 30 days, except where we're legally required to keep it.
Confidentiality
Each of us may learn things about the other that aren't public — Customer Data, security detail, pricing on a negotiated agreement, unreleased features. "Confidential Information" means anything marked confidential, or that a reasonable person would understand to be confidential given what it is and how it was shared.
Each party will:
- use the other's Confidential Information only as this agreement allows;
- protect it with at least the care it uses for its own confidential information;
- disclose it only to employees, contractors and advisers who need it and are bound by equivalent obligations.
This doesn't cover information that is public through no fault of the recipient, was already properly known to them, was lawfully received from someone else without restriction, or was independently developed. Where disclosure is legally compelled, the recipient will tell the other party first if it's lawfully able to, and disclose no more than required.
These obligations continue for three years after the agreement ends, and indefinitely for Customer Data.
AI analysis
On plans that include it, each report is analysed automatically to produce a summary, a proposed root cause, draft reproduction steps and a suggested severity. Analysis runs on Claude through Anthropic's API, or on ChatGPT through OpenAI's, whichever the workspace selects under Settings → AI — in both cases under terms that prohibit training on the data sent to it.
- The model sees the report after redaction rules have been applied.
- AI analysis can be turned off per project. With it off, every other part of the service works unchanged.
- Output is a suggestion, not a finding. It can be wrong, and it is always editable by a triager.
You should not rely on AI output as the sole basis for a decision with legal, financial or safety consequences.
Third-party integrations
Connecting Jira, GitHub, Linear, Slack or a webhook endpoint authorises us to send report data to that service on your behalf, using the credentials you supply. Once data reaches a third-party service it is governed by that service's terms and privacy policy, not ours.
We're not responsible for a third party's availability, security or changes to its API. If a provider breaks or removes an API we depend on, we may have to change or retire that integration.
Extension and SDK
We grant you a limited, revocable, non-exclusive, non-transferable licence to install and use the extension and to embed the SDK in products you operate, for the term of your subscription and in accordance with these terms.
- The extension runs with the permissions declared in its store listing and captures only when a user triggers a capture, or — for Rewind — into a local buffer that is discarded unless the user presses Rewind.
- If you embed the SDK in a product used by your own customers, you're responsible for telling them what it captures and for having a lawful basis to capture it. We'll give you the technical detail you need to do that; the disclosure itself is yours to make.
- The extension and SDK update automatically. We support the current version and the one before it.
Intellectual property
The service, its software, design, documentation and the BugCatch name and marks are ours or our licensors', and nothing in these terms transfers any of it to you beyond the licence in extension and SDK. Aggregated, de-identified statistics about how the service is used — figures that cannot identify you, your users or your content — remain ours and may be used to operate and improve the product.
Feedback
If you send us an idea, a bug report about BugCatch itself, or a feature suggestion, we may use it freely and without obligation or compensation. We won't identify you as its source publicly without asking.
Availability, support and changes
We aim for high availability but commit to a specific uptime target only where an Enterprise order form or SLA says so. Planned maintenance is announced in advance where practical.
Support is provided at the level of your plan: community for Free, priority email for Team, and a named contact with agreed response times for Enterprise.
We may add, change or remove features. If we remove or materially degrade a feature you rely on and you're on a paid plan, we'll give at least 30 days' notice by email or in the dashboard, and you may cancel and receive a pro-rata refund for the unused paid period.
Suspension and termination
You may cancel at any time from your billing settings; the Cancellations & Refunds policy explains what happens to access and money.
We may suspend or terminate your access if:
- you materially breach these terms and don't fix it within 14 days of us telling you (immediately, where the breach is unlawful use, an active security threat, or non-payment beyond 30 days);
- we're required to by law; or
- your use is causing, or is about to cause, harm to the service or to other customers — in which case we'll limit the suspension to what's necessary and restore access as soon as it's safe.
On termination, your right to use the service ends. You can export your data for 30 days after termination, after which it's deleted. Anything you owe us survives, as do your data, confidentiality, intellectual property, disclaimers, limitation of liability, indemnity, governing law and general.
Disclaimers
Except as expressly stated here, the service is provided "as is" and "as available", without warranties of any kind, whether express, implied or statutory, including any implied warranty of merchantability, fitness for a particular purpose, accuracy or non-infringement.
We do not warrant that the service will be uninterrupted or error-free, that AI analysis will be accurate, that redaction will catch every sensitive value in every payload, or that a recording will capture every detail of a defect. Redaction is a strong control, not a guarantee — you remain responsible for keeping data you must not disclose out of what you capture.
Nothing here excludes a warranty or right that cannot lawfully be excluded, including consumer rights where they apply to you.
Limitation of liability
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, lost goodwill, or the cost of substitute services — even if told such loss was possible.
Our total aggregate liability arising out of or relating to these terms or the service is limited to the greater of (a) the fees you paid us in the twelve months before the event giving rise to the claim, or (b) [USD 100].
These limits do not apply to death or personal injury caused by negligence, fraud or fraudulent misrepresentation, either party's breach of the other's intellectual property rights, your payment obligations, or any other liability that cannot lawfully be limited.
Indemnity
You'll defend and indemnify us against third-party claims arising from Customer Data you or your users put into the service, from your use of the service in breach of these terms, or from your infringement of someone's rights — including claims that a recording was made without a required consent.
We'll defend and indemnify you against third-party claims that the service, used as we intend, infringes their intellectual property rights, and we'll pay the damages finally awarded. This doesn't apply where the claim arises from Customer Data, from a modification we didn't make, or from use of the service in combination with something we didn't supply.
In each case the indemnified party must notify the other promptly, let them control the defence, and give reasonable co-operation.
Changes to these terms
We may update these terms. If a change materially affects your rights or obligations, we'll give at least 30 days' notice by email to the workspace owner and in the dashboard, and the change takes effect at the end of that notice period. Continuing to use the service after that date means you accept the new terms; if you don't, cancel before then and the Cancellations & Refunds policy applies.
Minor changes — clarifications, typos, a new sub-processor already covered by our notice process — take effect when published. Every version is dated, and superseded versions are available on request.
Governing law and disputes
These terms are governed by the laws of [governing jurisdiction], without regard to conflict-of-laws rules. The courts of [courts / seat] have exclusive jurisdiction, except that either party may seek injunctive relief in any competent court to protect its intellectual property or confidential information.
If you're a consumer, this doesn't deprive you of the protection of the mandatory laws of the country where you live.
Before filing a claim, please email info@sphoro.com. Most disputes are a misunderstanding about billing or scope, and we'd rather resolve one in a week than a year.
General
- Entire agreement. These terms, the Privacy Policy, the Cancellations & Refunds policy, and any order form or DPA you've signed, are the whole agreement between us on this subject.
- Assignment. You may not assign these terms without our written consent. We may assign them to an affiliate or in connection with a merger or sale of assets, on notice to you.
- Severability. If a provision is unenforceable, it's narrowed to the minimum extent necessary and the rest stands.
- No waiver. Not enforcing something once doesn't waive the right to enforce it later.
- Force majeure. Neither party is liable for a delay caused by events outside its reasonable control, excluding payment obligations.
- Notices. We'll email the workspace owner. You should write to info@sphoro.com.
- Independent parties. Nothing here creates a partnership, agency or employment relationship.
- No third-party rights. Nobody other than you and us can enforce these terms.
Questions about these terms
Write to us — a real person answers.
- Legal
- info@sphoro.com
- Billing
- support@sphoro.com
- Security
- info@sphoro.com
- Post
- Sphoro — [registered entity name, registered address]