Privacy Policy
Last updated: June 2026
This Privacy Policy explains how BugBrain (“BugBrain”, “we”, “us”) collects, uses, discloses, and safeguards personal data. It also sets out the rights you have under the EU/UK General Data Protection Regulation (GDPR) and comparable laws. It covers our website, the BugBrain platform, and related services.
Our two roles: controller and processor
We act in two distinct roles. We are a data controller for the personal data of our own users and prospects: account, billing, support, marketing, careers, and contact-form data. We are a data processor for the personal data contained within the applications you ask BugBrain to test. For example, this includes content captured in screenshots, network logs, or page snapshots during a test run. You remain the controller of that data, and we process it only to provide the service under your instructions and our Data Processing Agreement.
Who we are & how to contact us
For privacy questions or to exercise your rights, contact our privacy team at privacy@bugbrain.tech. A formal Data Protection Officer is not legally required at our current scale. To reach our designated data-protection contact, use dpo@bugbrain.tech.
Personal data we collect
- Account & profile: name, email, password (stored only as an argon2id hash), organization, role, locale, timezone, avatar.
- Usage & device: log data, approximate location from IP, device/browser information, and (only with your consent) analytics events and session-replay interactions.
- Billing: plan, subscription status, and invoice history (payment details are handled by our payments provider, not stored by us).
- Support & communications: messages you send us, support-chat history, and contact-form submissions.
- Careers: if you apply for a role, your CV, contact details, and application information.
- Application data you direct us to test (processor role): artifacts such as screenshots, DOM/page snapshots, and network logs. These may incidentally contain personal data of your end users.
We do not sell personal data.
Why we process it, and our lawful bases
- To provide the service (run tests, manage your account, authenticate you): performance of a contract.
- To secure and operate the platform (security, fraud/abuse prevention, audit logging, service telemetry): legitimate interests.
- Analytics, session replay, and the support chat widget: consent (managed via our cookie banner; withdraw anytime).
- Marketing communications: consent, or legitimate interests for existing customers, with an opt-out in every message.
- To comply with legal obligations (tax, accounting, responding to lawful requests): legal obligation.
Recipients & subprocessors
We share personal data with vetted service providers who process it on our behalf: hosting, object storage, email delivery, analytics, support chat, payments, and AI model providers used to analyze applications under test. Each is bound by a data-processing agreement. The current list is on our Subprocessors page, where you can subscribe to be notified of changes.
International data transfers
Some recipients are located outside the EEA/UK (including the United States). Where that happens, we rely on a lawful transfer mechanism: the EU–US Data Privacy Framework where the recipient is certified, and/or the European Commission’s Standard Contractual Clauses with a transfer impact assessment and supplementary measures. Details are available on request.
How long we keep data
We retain personal data only as long as necessary for the purposes above. Account data is kept for the life of your account. Test artifacts are retained per your plan. Audit logs are kept for a fixed period for security and accountability, and backups roll off on a defined schedule. Our full retention schedule is available on request. When you erase your account or workspace, we delete or irreversibly anonymize the associated data (see your rights below). Residual copies in backups expire within the backup retention window.
Your rights
Subject to applicable law, you have the right to:
- Access a copy of your personal data, and data portability in a machine-readable format.
- Rectify inaccurate data (you can edit your profile, email, and password in your account settings).
- Erase your account and associated data (“right to be forgotten”).
- Restrict or object to certain processing, and to withdraw consent at any time (use “Cookie settings” in the footer for tracking consent).
Logged-in users can export their data and delete their account directly from account settings. If you cannot, or if you are an end user whose data we process on a customer’s behalf, email privacy@bugbrain.tech and we will respond within the statutory timeframe. You also have the right to lodge a complaint with your local data-protection supervisory authority.
Cookies & tracking
We use strictly-necessary cookies to run the site, and (only with your consent) analytics, session-replay, and support-chat cookies. Manage your choices anytime via “Cookie settings” in the footer. See our Cookie Policy for the full inventory.
Data security
We enforce per-organization data isolation. We encrypt stored credentials with AES-256-GCM, hash passwords with argon2id, and encrypt data in transit with TLS. We follow least-privilege access and redact sensitive fields from logs. Access to production data is restricted and audited.
Children
BugBrain is a business product not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We will post any changes here and update the date above. Material changes will be communicated as required. Questions? Email privacy@bugbrain.tech.