Privacy Policy
Last updated: August 25, 2026
1. Who we are
BugSnap-AI is an autonomous QA agent service. This policy explains what data we collect, why, and how it's handled — including the fact that testing an application necessarily involves observing that application's content, not just your account details.
2. Scope
This policy covers data processed through the BugSnap-AI product. It distinguishes between two kinds of data: Customer Data (everything you submit to, or that the Service observes while testing, your application) and any personal data that may be contained within it — including personal information about your own end-users that the Service happens to encounter while exercising your application.
3. Information we collect
- Account data: name, email address, and password (stored as a salted hash, never in plain text).
- Organization data: workspace membership, roles, and settings.
- Application & test data: application URLs and routes, DOM/accessibility snapshots, screenshots, browser traces, form values and test data used during a run, error messages, and console/network metadata observed while testing.
- Credentials: login credentials you provide so the Service can authenticate to your application.
- AI processing data: the prompts and application context sent to AI providers, and their responses, used to plan and analyze test runs.
- Findings & evidence: defect reports, reproduction steps, and the screenshots/traces backing them.
- Billing data: handled directly by LemonSqueezy, our Merchant of Record — we never see or store full card numbers.
- Usage data: credit consumption, run metrics, and error logs.
4. Credentials
Credentials are encrypted at rest and never displayed again after entry. They are used only to authenticate to your application and perform the testing you've authorized. Where technically necessary, credentials may be decrypted within the isolated execution environment for the duration of a test run. Credentials are not intentionally included in AI prompts, logs, screenshots, reports, or anything shown back to you or anyone else, except where explicitly required for the run itself.
5. How we use information
We use Customer Data to operate the Service: running automated tests against applications you authorize, generating Findings, and providing support. Usage data such as credit consumption, run metrics, and error reports may be used to operate, secure, troubleshoot, and improve the Service itself.
We do not use Customer Data to train general-purpose AI models, and we do not disclose it for purposes unrelated to providing you the Service.
6. AI processing
To provide autonomous testing, BugSnap-AI sends relevant application observations — page content, workflow context, screenshots, and error information — to configured AI providers (currently OpenAI as primary, with Google Gemini and Groq as automatic fallbacks) so they can plan and analyze test runs.
We configure our accounts with these providers so that Customer Data is not used for their general model training, consistent with each provider's current API/business terms — but the exact retention and training behavior is each provider's own, published in their own policies, and can change on their end; we review these settings periodically rather than making a permanent guarantee about a third party's systems.
7. Sub-processors
We share limited data with these third-party services to operate BugSnap-AI. This list reflects what's actually in use today and is updated as our infrastructure changes:
8. Cookies
We currently use a single essential session cookie to keep you signed in. We do not run analytics or advertising scripts on this site today; if that changes, this section will be updated to reflect it before any such script goes live.
9. Security
We implement reasonable technical and organizational measures designed to protect data against unauthorized access, disclosure, alteration, and destruction, including encryption in transit and at rest for sensitive fields, per-tenant isolation, access controls, isolated browser execution for test runs, and audit logging. No system is completely secure, and we cannot guarantee absolute security.
10. Data retention
We retain different categories of data for different periods depending on their purpose, your plan, our operational requirements, and applicable law. Findings and run artifacts are retained according to your plan's finding-history window (currently 7/30/90 days depending on plan). Account, billing, security, and audit records may be retained longer where necessary for legal or fraud-prevention purposes.
11. Data deletion
You can request deletion of your account and its data at any time. On deletion, we remove your Customer Data, findings/evidence, and stored credentials, subject to backups (which expire on their own lifecycle) and any legal, accounting, fraud-prevention, or security records we must retain.
12. International data transfers
BugSnap-AI and the sub-processors listed above may process data in countries other than the one you're located in. Where required by applicable law, we use appropriate safeguards for these transfers; enterprise customers with specific requirements can request a Data Processing Addendum.
13. Security incidents
If we determine that a security incident has affected personal data, we will take reasonable steps to investigate, contain, remediate, and provide notifications where required by applicable law.
14. Your privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to withdraw certain consents. Submit requests to the contact below.
15. Children's privacy
BugSnap-AI is a business-to-business service and is not directed at children. We do not knowingly collect personal information from children where prohibited by applicable law.
16. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by updating the "Last updated" date above.
17. Contact
Questions about this policy? Email hello@bugsnap-ai.com.