Privacy Policy

Last updated: July 23, 2026

1. Who we are

BugVault ("we", "us") is a visual bug reporting and issue tracking platform built by ConcatString. This policy explains what information BugVault collects through its web application and browser extension, why, and how it's handled.

2. Information we collect

Account information

Name, email address, and password (stored as a salted hash, never in plain text) when you create an account or are invited to a project. If your organization uses Portal-based staff login, your credentials are verified directly against Portal — BugVault never stores your Portal password.

Bug report content

When you or your team submits a bug report — via the web app or the browser extension — we store the screenshot or screen recording you capture, any annotations you add, your written description, and technical metadata automatically attached to help reproduce the issue: the page URL, browser and OS, viewport/screen size, console errors, and failed network requests visible on that page at the time of capture.

Usage & device data

Standard web request metadata (IP address, approximate location derived from it, user agent) is processed to secure the service and populate report metadata. Push notification subscriptions are stored only if you opt in.

3. Browser extension permissions

The BugVault browser extension requests broad host permissions because a bug can occur on any website you test — the extension only activates and captures data on a page when you explicitly start a report. It does not monitor your browsing, collect data in the background, or transmit anything without your action. Session cookies are used solely to detect that you're already signed into the BugVault web app, so the extension can sign you in automatically.

4. How we use your information

  • To operate and maintain your account and projects
  • To display, organize, and let your team collaborate on bug reports
  • To send transactional email (invites, password resets, issue notifications)
  • To power optional AI features (e.g. duplicate detection, severity suggestions, fix suggestions) — report content is sent to our AI provider only when these features are enabled for your organization
  • To secure the platform and investigate abuse

5. Third-party services

We rely on infrastructure providers to run BugVault: a hosted Postgres database for storage, an object-storage provider for screenshots/recordings, an email delivery provider for transactional mail, and — only if your organization enables AI features — Anthropic's API for processing report content. Each processes data solely to provide their respective service to us and does not independently use it for other purposes.

6. Data retention & deletion

We retain account and report data for as long as your account or project is active. You can request deletion of your account or specific data at any time by contacting us at support@bugvault.dev.

7. Your rights

You may request access to, correction of, or deletion of your personal data, or export of your bug report data, by emailing support@bugvault.dev.

8. Children's privacy

BugVault is a business tool not directed at children, and we do not knowingly collect information from anyone under 16.

9. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the date at the top of this page.

10. Contact us

Questions about this policy or your data? Email support@bugvault.dev.