LAST UPDATED SEPTEMBER 30, 2026

Privacy policy

BugSnitch captures browser context, creates GitHub or Linear issues, and helps you triage those issues. This page describes extension and BugSnitch gateway processing.

Chrome Web Store Limited Use

BugSnitch's use and transfer of user data complies with the Chrome Web Store User Data Policy, including Limited Use. We use and transfer data only to provide, secure, maintain, and support the requested capture, GitHub or Linear issue, and issue-triage workflow. We do not sell user data, use it for advertising or personalized advertising, or transfer it for creditworthiness, lending, or unrelated purposes.

Transfers to GitHub, Linear, Polar, a configured AI provider, a selected coding-agent app, or infrastructure provider occur only for the requested feature or support/security action. BugSnitch personnel do not routinely read captures, screenshots, diagnostics, issue bodies, prompts, or AI content. Limited human access can occur when you send material to support and ask us to investigate, when needed to investigate abuse or a security incident, or when required by law; access is limited to people who need it. Third-party services control their own access under their policies.

Data we process

Depending on the features you use, BugSnitch may process GitHub or Linear OAuth tokens and connected account metadata, Linear teams, GitHub repositories and pull requests visible to that authorization, issue title/body/labels/URL, selected destination and issue-triage data, page URL/title and visible viewport screenshots, annotations and selected-element metadata, and the optional diagnostic bundle. Linear uses authorization-code OAuth with PKCE and the read,issues:create scopes. Diagnostics can include timestamp/timezone, browser and operating-system details, viewport/screen measurements, recent errors and console entries, failed request metadata, clicks, and same-document navigation. Diagnostics are off by default, future-only, top-frame only, bounded to 120 seconds, redacted, and reviewable section by section.

Captures can contain anything visible on screen. BugSnitch does not intentionally collect keystrokes, form values, request or response bodies, cookies, authorization headers, full page storage, or session replay. Automated redaction is not a guarantee; review the exact draft and screenshot before sending.

When you use the issue board or history, local storage can contain issue titles, bodies, labels, numbers, URLs, repository metadata, author IDs/logins, state, comment counts, timestamps, and status-label changes. When you enter a paid license, BugSnitch processes the Polar license key, plan, validity, owner provider, and entitlement timestamps. The gateway stores a one-way stable license fingerprint with the owning GitHub or Linear account ID, never the raw key or provider token. Polar processes checkout, payment, tax, billing, invoices, and customer-portal data; BugSnitch does not receive full card details.

Optional AI and coding-agent features

AI and native features are optional. AI title/writing prompts contain only the description, annotation text, or selected issue text/context needed for that request. They exclude screenshot pixels, diagnostics, page URL, and page title. OpenRouter, OpenAI, Anthropic, and Google Gemini receive text directly with the API key you provide. Ollama receives text on your own computer at localhost:11434 or 127.0.0.1. BugSnitch Cloud AI receives the prompt, mode, Polar license key, and connected GitHub or Linear authorization at api.bugsnitch.dev, verifies account ownership, validates the entitlement, and sends the prompt to its configured AI service. Codex sends a bounded text prompt to the separately installed local Native Messaging companion. Each provider's retention and use are governed by its policy.

Coding-agent handoff is separate from BugSnitch AI generation. When you choose Copy prompt or a deep link, BugSnitch may place the reviewed repository, issue number/URL/title/body, annotations, and any enabled page-context block on the clipboard or in the selected agent app.

Where data goes

Linear authorization uses linear.app/oauth/authorize. Token exchange, refresh/revocation, account/team lookup, labels, and issue creation use api.linear.app. A reviewed Linear issue can include selected screenshot pixels as an embedded data URI, which Linear imports into its private storage.

The free plan allows 30 issues created through BugSnitch's gateway per UTC calendar month; issues submitted separately in GitHub are outside BugSnitch accounting. Paid plans are sold and entitlement-checked through Polar. GitHub Device Flow uses github.com/login; authenticated repository, issue, pull-request, and label requests use api.github.com. When you submit a reviewed GitHub issue that includes screenshots, the extension sends the image bytes to uploads.github.com/user-attachments/assets and adds the returned attachment URL to the issue body. This upload happens before the issue-creation request, so an attachment may remain on GitHub if that request later fails. BugSnitch has no operation to delete uploaded attachments. The gateway verifies the GitHub token, authorizes issue creation, accounts for the free allowance, and validates Polar entitlements. It forwards the reviewed issue body transiently to GitHub and does not intentionally log or persist OAuth tokens, license keys, issue bodies, or screenshot pixels.

Anonymous extension telemetry is optional and off by default. It is sent only after you enable it in Settings → Privacy. It includes fixed event names, extension/browser versions, bounded latency, consent state, and allowlisted error categories sent to api.bugsnitch.dev/telemetry. It does not send page URLs, titles, content, screenshots, annotations, diagnostics, issue text, repository names, GitHub accounts, email addresses, tokens, request data, console contents, or raw exception messages. It may be forwarded to GA4 for aggregate reporting. Website analytics on this site is a separate surface.

Storage, retention, and deletion

Drafts/captures/diagnostics use Chrome session storage, and disabling diagnostics removes its bundle from the draft. GitHub connections are remembered on this device in Chrome local storage until Disconnect, extension-data clearing, or uninstall; revoking GitHub access invalidates the token but does not erase the local copy. Linear OAuth access/refresh tokens and account/team metadata, Polar license state, settings, repository metadata, telemetry preference, up to 100 issue-history entries, and local Kanban caches use Chrome local storage. Linear access tokens expire and rotating refresh tokens replace the stored token. AI keys entered in Settings use session storage unless you choose Remember; OpenRouter keys obtained through the sign-in flow or popup connection are saved in local storage until the provider is disconnected. Clearing a draft or license, disconnecting a provider, clearing extension data, or uninstalling removes the applicable local copy.

Current GitHub issue creation uploads included screenshots to uploads.github.com as native attachments and adds the returned github.com/user-attachments/assets URL to the issue body. BugSnitch does not create screenshot commits in the repository. If Chrome upload permission is declined or GitHub's attachment endpoint is unavailable, issue creation with screenshots fails; there is no repository-commit fallback. An attachment upload may complete before a later issue-creation failure, and BugSnitch cannot delete that upload. Disconnect and local-data clearing do not delete GitHub issues or attachments. Screenshots or refs created by earlier versions may remain in GitHub repositories and are not removed by the current extension. The gateway retains limited account, quota, entitlement, idempotency, and operational records only as needed for service operation, abuse prevention, support, and legal obligations.

You can request access or deletion of BugSnitch-held service records by emailing support@bugsnitch.dev. This cannot remove data retained by GitHub, Polar, an AI provider, or a receiving coding-agent app under its policy.

Choices and contact

Settings let you review or remove captures and diagnostics, disable page context, disconnect GitHub or Linear, forget provider keys, clear license state, disable telemetry, and clear local extension data. Provider authorization can also be revoked from GitHub or Linear account settings.

Terms · Refund policy · Support · support@bugsnitch.dev

Website analytics

The public BugSnitch website uses Google Tag Manager and Google Analytics for page views and aggregate link or checkout interactions. This website analytics surface is separate from the extension. Extension telemetry is off by default and is sent only after explicit consent from the extension UI; it contains aggregate events and redacted error categories, never browsing data, screenshots, issue content, or GitHub data.