Privacy Policy
Last Updated: February 1, 2026
BugStack ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- GitHub Profile Information: Username, email address, profile picture, GitHub ID
- Account Settings: Preferences, notification settings, subscription tier
1.2 Error Data
When your application sends errors to BugStack, we collect:
- Error Logs: Error messages, stack traces, error types
- Code Context: Relevant code snippets from files where errors occur
- Metadata: Timestamps, error frequency, browser/environment information
- File Paths: Locations where errors occur in your codebase
1.3 Repository Information
When you connect GitHub repositories:
- Repository Names: Names of repositories you enable
- File Contents: Only files related to errors (with your permission)
- Pull Request Data: PRs created by BugStack, their status, and metadata
1.4 Usage Information
We automatically collect:
- Technical Data: IP address, browser type, device information, operating system
- Usage Data: Features used, errors processed, fixes generated, time spent in dashboard
- Analytics: How you interact with our service, button clicks, page views
1.5 Payment Information
- Billing Data: Name, billing address, company name (if provided)
- Payment Method: Card type and last 4 digits (processed by Stripe)
- Note: We do NOT store full credit card numbers - Stripe handles all payment processing
1.6 Communications
- Support Emails: When you contact support@bugstack.ai
- Feedback: Any feedback or suggestions you provide
2. How We Use Your Information
2.1 To Provide the Service
- Detect and analyze errors in your applications
- Generate code fixes using frontier AI models
- Create pull requests on GitHub
- Display errors and fixes in your dashboard
- Process payments and manage subscriptions
2.2 To Improve the Service
- Analyze usage patterns to improve features
- Debug and fix issues with BugStack
- Develop new features based on usage data
- Monitor service performance and uptime
2.3 To Communicate With You
- Send service-related notifications (errors detected, PRs created)
- Respond to support requests
- Send billing and subscription updates
- Send important security or privacy updates
- Send marketing emails (only with your consent - you can opt out anytime)
2.4 For Security and Compliance
- Prevent fraud and abuse
- Enforce our Terms of Service
- Comply with legal obligations
- Protect our rights and the rights of our users
2.5 With Your Consent
Any other purpose with your explicit consent
3. How We Share Your Information
We do NOT sell your data. We only share your information in these limited circumstances:
3.1 Third-Party Service Providers
We share data with service providers who help us operate:
AI Model Providers
- What We Share: Error messages, stack traces, code context
- Purpose: Generate code fixes using AI
- Data Processing: AI providers process data according to their respective privacy policies
- Training: We do NOT allow AI providers to use your data for model training
GitHub
- What We Share: Pull request content, repository information
- Purpose: Create PRs and integrate with your repositories
- Access: Only repositories you explicitly enable
- Learn more: https://docs.github.com/en/site-policy/privacy-policies
Stripe
- What We Share: Billing information, payment details
- Purpose: Process payments and manage subscriptions
- Security: Stripe is PCI-DSS compliant
- Learn more: https://stripe.com/privacy
Hosting Providers (Vercel/Render)
- What We Share: Application data, error logs
- Purpose: Host and deliver the service
- Security: Data encrypted in transit and at rest
3.2 Legal Requirements
We may disclose your information if required by law, such as:
- In response to a subpoena, court order, or legal process
- To protect our rights, property, or safety
- To protect the rights, property, or safety of our users or the public
- In connection with fraud investigation or prevention
3.3 Business Transfers
If BugStack is acquired or merged with another company, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
3.4 With Your Consent
We may share your information for any other purpose with your explicit consent.
4. Data Security
4.1 Security Measures
We implement industry-standard security measures:
- Encryption: All data encrypted in transit (TLS/SSL) and at rest (AES-256)
- Access Controls: Limited employee access on a need-to-know basis
- Authentication: Secure GitHub OAuth for account access
- API Keys: Encrypted storage of API keys and tokens
- Monitoring: Continuous security monitoring and logging
4.2 Your Responsibility
- Keep your account credentials secure
- Use strong, unique passwords
- Do not share your API keys
- Report security vulnerabilities to security@bugstack.ai
4.3 No Guarantee
While we implement strong security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
5.1 Active Accounts
- Error Data: Retained for 90 days, then automatically deleted
- Account Data: Retained while your account is active
- Usage Data: Retained for up to 2 years for analytics
5.2 Closed Accounts
When you close your account:
- Most data deleted within 30 days
- Some data retained for legal/compliance purposes (up to 7 years)
- Backups may contain data for up to 90 days
5.3 Manual Deletion
You can request immediate data deletion by emailing support@bugstack.ai
6. Your Privacy Rights
6.1 Access and Portability
- Access: View your data in your dashboard
- Export: Request a copy of your data in machine-readable format
- Contact: Email support@bugstack.ai for data exports
6.2 Correction and Deletion
- Correct: Update your account information in settings
- Delete: Delete individual errors from your dashboard
- Close Account: Delete your entire account and all associated data
6.3 Opt-Out Rights
- Marketing Emails: Unsubscribe link in every email
- Service Emails: Cannot opt out (required for service operation)
- Analytics: Contact us to opt out of analytics tracking
6.4 Do Not Sell
- We do NOT sell your personal information
- We do NOT share your data for advertising purposes
- California residents: See Section 8 for CCPA rights
7. International Data Transfers
7.1 Location
- Our servers are located in the United States
- Data may be processed in countries other than your own
- We ensure appropriate safeguards for international transfers
7.2 EU-US Data Transfers
For EU users:
- We comply with GDPR requirements
- Data transfers use Standard Contractual Clauses (SCCs)
- You have rights under GDPR (see Section 6)
8. Regional Privacy Rights
8.1 California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect
- Know whether we sell or disclose your personal information
- Access your personal information
- Delete your personal information (with exceptions)
- Opt out of the sale of your personal information (we don't sell data)
- Non-discrimination for exercising your rights
To exercise these rights: Email support@bugstack.ai with "CCPA Request" in the subject line.
8.2 European Residents (GDPR)
If you are in the EEA or UK, you have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase your personal data
- Restrict processing of your personal data
- Data portability
- Object to processing
- Withdraw consent at any time
Legal Basis for Processing:
- Contract Performance: To provide the service you signed up for
- Legitimate Interests: To improve and secure our service
- Consent: For marketing communications (you can withdraw anytime)
- Legal Obligation: To comply with applicable laws
To exercise these rights: Email support@bugstack.ai
Supervisory Authority: You have the right to lodge a complaint with your local data protection authority.
8.3 Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate. Contact us for information about your specific rights.
9. Cookies and Tracking
9.1 Cookies We Use
- Essential Cookies: Required for service functionality (login, session management)
- Analytics Cookies: Help us understand how you use the service
- Preference Cookies: Remember your settings and preferences
9.2 Third-Party Cookies
- GitHub (for OAuth authentication)
- Stripe (for payment processing)
- Analytics providers (if used)
9.3 Your Choices
- Most browsers allow you to refuse cookies
- Disabling essential cookies may prevent you from using the service
- You can clear cookies at any time through your browser settings
10. Children's Privacy
BugStack is not intended for children under 18. We do not knowingly collect information from children under 18. If you believe we have collected information from a child under 18, contact us immediately at support@bugstack.ai.
11. Changes to This Privacy Policy
11.1 Updates
- We may update this Privacy Policy from time to time
- We will notify you of material changes via email or dashboard notification
- The "Last Updated" date at the top shows when this policy was last revised
11.2 Your Continued Use
Continued use of BugStack after changes constitutes acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices:
Email: support@bugstack.ai
Privacy Inquiries: privacy@bugstack.ai
Security Issues: security@bugstack.ai
Website: https://bugstack.ai
Summary (Plain Language)
What we collect:
- Your GitHub profile info (username, email)
- Error logs from your apps
- Usage data (how you use BugStack)
- Payment info (processed by Stripe)
How we use it:
- Fix bugs in your apps using AI
- Improve BugStack
- Send you service notifications
- Process payments
Who we share with:
- AI model providers (to generate fixes)
- GitHub (to create pull requests)
- Stripe (to process payments)
- No one else (we don't sell your data)
Your rights:
- View your data anytime
- Delete your data anytime
- Export your data
- Opt out of marketing emails
Questions? Email us at support@bugstack.ai