Two kinds of data
We hold data about you, the member with the account, and data your app sends about the people who use it. A person is someone in your app. A member is someone on your Bugwalk workspace.
Your account
We store the email you sign up with, an optional name, and your GitHub login if you connect GitHub. A password is stored only as a bcrypt hash. We never keep the password itself. An account created with a magic link or GitHub can have no password at all.
The session
The dashboard session is an httpOnly cookie. In production it is marked Secure, and SameSite is Lax. The token is not stored in localStorage. Ingest from your app does not use that cookie. It uses a write-only project key, and it accepts no credentials.
What your app sends
The SDK records page views, clicks, HTTP requests, errors, and log lines from a visit, on one timeline. If you call identify(), that timeline is attached to the id or email you already have for that person. If you do not call identify(), the visit stays on a session id. Background work uses the same id and email when you call forPerson(). A cron or queue with no person stays on a session id.
You choose what is sent. You can sample, filter, or add your own redaction rules before a batch leaves your app.
Secrets
The SDK removes secrets inside your app, before an event is queued. Those rules cannot be turned off. Authorization and cookie headers are dropped. Field names such as password, secret, token, and card number are dropped. Known private keys, JWTs, and card numbers found inside a string are replaced. A value that matches never reaches Bugwalk.
The SDK does not read form field values, other than the visible text of a clicked button or link. It does not read localStorage, sessionStorage, IndexedDB, keystrokes, or environment variables. Request and response bodies are sent only if you opt in, only as JSON, and only up to 8 KB. The same rules still run.
Email addresses are kept when you send them. Naming a person by email is what identify() is for. Project, Privacy drops any extra field names you list, before they are stored.
Repositories
Bugwalk can pull the repositories you chose, run their tests, create one branch, and open a pull request. It cannot push to the default branch, comment, merge, or write to your database. A qualifying report can open a pull request on its own within the monthly allowance. After that, a member can ask from the report. Merging stays yours. Disconnect the repository, or uninstall the app, and that access stops.
Investigations
An investigation reads the session and, when a repository is connected, the code around the failing line. That evidence is sent to the model provider configured for the product, OpenAI unless another provider is set, so it can write the report. The report is stored with the issue so it can be read again.
We do not use your repositories or your customers’ sessions to train a model of our own.
Payment
Paid plans are billed through Polar. Bugwalk does not store your card number. Polar stores the payment method and tells us the plan, the status, and the period.
We send mail through Resend: magic links, billing notices, and the messages the product says it will send. We do not sell your email address, and we do not send marketing you did not ask for.
How long we keep it
The product shows history for the days on your plan: 30 on Pro, and 90 on Team. A workspace already on Free keeps 3 days. Events are deleted by month. A month is deleted after every day in it is older than that window, so a visit can remain stored for the rest of its month plus the plan window. It is not kept longer than that.
Account records, issues, and investigation reports stay while the account is open. They are not on the event clock.
Who else handles it
We use these companies to run the hosted product. Each one receives only what that job needs.
- Supabase holds the Postgres database.
- Fly runs the API.
- Cloudflare serves the website.
- Polar handles payment.
- Resend sends email.
- GitHub, when you connect a repository.
- OpenAI, or the model provider configured in its place, receives the evidence an investigation needs.
How we protect it
The hosted site and API are served over HTTPS. On top of that:
- Secrets are stripped in your process, before they reach us.
- Passwords are hashed with bcrypt. We cannot read them back.
- The session cookie is httpOnly, so a script on the page cannot read it.
- The dashboard API accepts signed-in requests only from the Bugwalk web origin.
- GitHub access is limited to the repositories you grant. Bugwalk can open a pull request on a new branch. It cannot push to the default branch, comment, merge, or write to your database.
- You can self-host the same server and keep every byte on your own machines.
What you can do
Skip identify() and people stay anonymous. Add redaction rules, or do not send a field. Disconnect a repository, or uninstall the GitHub App. Self-host if you want the data on your own infrastructure.
Email hello@bugwalk.dev to delete the account and the workspace data we still hold, or to ask for a copy of the account record. Event history already expires on the schedule above.
Children
Bugwalk is a tool for teams building software. We do not aim it at children, and we do not knowingly keep an account for anyone under 16. If you believe we have one, email hello@bugwalk.dev and we will delete it.
Changes
If this page changes, the date at the top changes with it. If a change takes more data than we take today, we email the account before it applies.
Contact
Questions about this page go to hello@bugwalk.dev. The rules for using the hosted product are on the Terms page.