BugSnitch에 대한 개인정보처리방침
BugSnitch 제작자: Scaling Adventures
Full policy: https://bugsnitch.dev/privacy/ (source of truth). Questions: support@bugsnitch.dev.
BugSnitch has one purpose: capture browser context, create GitHub or Linear issues you review first, and triage those issues. GitHub, Linear, Polar, configured AI providers, and coding-agent apps are separate services with their own policies. BugSnitch does not sell user data or use it for advertising.
DATA HANDLED (only when the related feature is used)
- Authentication: GitHub OAuth Device Flow codes and access token; Linear OAuth access/refresh tokens (PKCE, read and issues:create); connected account, team, repository, label, and issue metadata. GitHub's "repo" scope can include private repositories.
- Website content and captures: active page URL, title, hostname, viewport size, the selected element's selector/tag/accessibility name/bounds, annotation text and color, and PNGs of the visible viewport. Captures can contain anything visible on screen. You review everything before it is sent.
- Optional diagnostics: off by default, future-only, bounded, redacted console/network/action entries you can remove section by section.
- Optional AI prompts: description, annotation, or selected issue text only. Never screenshot pixels, diagnostics, page URL, or page title. Your provider API key goes only to that provider.
- Optional telemetry: off by default; after consent sends an allowlisted aggregate payload with no page URLs, content, screenshots, tokens, or account identifiers.
WHERE DATA GOES
- GitHub (github.com, api.github.com, uploads.github.com) and Linear (linear.app, api.linear.app) receive the reviewed issue, screenshots, and authorization requests.
- The BugSnitch gateway (api.bugsnitch.dev) verifies the GitHub token, enforces the free allowance of 30 issues per UTC month, validates Polar entitlements, authorizes the final issue request, and forwards the reviewed issue body transiently to GitHub. It does not intentionally log or persist OAuth tokens, license keys, issue bodies, or screenshot pixels; it retains limited account, quota, entitlement, idempotency, and operational records.
- Optional AI providers you configure (OpenRouter, OpenAI, Anthropic, Google Gemini, local Ollama, BugSnitch Cloud AI) receive the text prompt directly.
- The optional Codex native companion is a separately installed local program that receives bounded text prompts only.
LOCAL STORAGE
Tokens and AI keys stay in session storage unless you choose "Remember on this device". Drafts, annotated PNGs, and diagnostics live in session storage and are removed after issue creation. Settings, issue history (up to 100 entries), repository metadata, and telemetry consent live in local extension storage until changed, cleared, or uninstalled. Nothing is placed in synchronized storage, page DOM, logs, or telemetry.
PERMISSIONS
Capture uses activeTab and scripting after your action. storage keeps the data above. clipboardWrite copies a reviewed screenshot, issue URL, or prompt only when you choose it. identity opens Linear's OAuth consent page. Broad site access, nativeMessaging, and OpenAI/Anthropic hosts are optional and requested only when you enable those features. No remote code is executed.
YOUR CONTROLS
Settings let you disconnect GitHub or Linear, forget provider keys, clear the license, turn diagnostics, page context, and telemetry on or off, remove captures, and clear all local extension data. Revoke authorizations any time from GitHub or Linear account settings. Request access or deletion of gateway records at support@bugsnitch.dev.