π‘οΈ
Core Statement: Data minimization: report content (screenshots, annotations, recordings, diagnostics) is generated in your browser, and is uploaded only when you actively share or submit β it is then delivered through the share link or the integration you connected (Feishu Bitable / webhook).
Overview
This policy explains how the BugCapturer Chrome extension, its companion web app (app.bugcapturer.com) and the Web SDK embedded on third-party sites handle your data in v1.4.0. We follow a data-minimization approach: report content is generated in your browser; uploads are triggered solely by you, with clear retention periods and deletion at any time.
Data Processing
Report Generation & Processing
- Screenshots and annotations, screen recordings, diagnostic collection, and the assembly of report bodies all happen in your browser
- Capturing, annotating and recording happen on your device; content is uploaded only when you actively share or submit
- We do not read your browsing history, cookies, bookmarks, or other personal data
Sharing & Data Retention
- Upload trigger: shared content (screenshots, recordings, descriptions, technical metadata, diagnostics) is uploaded only when you actively click "Share" or submit. Capturing, annotating and recording happen on your device.
- Storage & retention: uploaded content is stored on Cloudflare R2 object storage. Anonymous shares are kept for 30 days and signed-in user shares for 90 days, then automatically deleted.
- Visibility: anyone with the share link can view the shared content. Links are randomly generated and cannot be enumerated; share pages are not indexed by search engines.
- Control: signed-in users can delete their shares anytime on the "My Shares" page. Deletion takes effect immediately (both files and records are removed).
- Abuse handling: share pages provide a report channel. Violating content is taken down within 24 hours of being reported.
- Account data: the sign-in system collects your email (for verification) and basic Google OAuth profile (if you sign in with Google), used only for account identification, never for marketing.
- Retention tiers: reports sent to a site project (including submissions from visitors with no account) follow the site owner's retention of 90 days; reports sent to a team integration follow the member retention of 90 days
Web SDK (Visitor Submissions)
- Embedding: website operators (e.g. internal UAT sites) embed the BugCapturer Web SDK, letting the site's visitors submit feedback directly via a floating widget β no browser extension required
- Collected data: annotated screenshot, issue description, optional contact info, page URL / title, environment info, and automatically collected console / network error records
- Reporter identity: the host site may inject the visitor's identity (name / email / user ID) via the identify API, which is attached to the report; without it, submissions are anonymous. Invalid identity fields are dropped server-side
- Data ownership: SDK reports belong to the embedding site's project owner (visible in their share list and integrations) and are retained for 90 days; to access or delete a report, contact the site operator
- Safeguards: submissions are only accepted from whitelisted domains, capped at 30 reports / day / project and 10 / day / IP; sensitive URL parameters are masked and only PNG screenshots up to 10 MB are accepted
Integrations (Feishu Bitable)
- Only when you add a Feishu Bitable integration in settings and actively share (or click "Test") does the server write one record to the Bitable you specified, via the Feishu Open Platform API
- The written content includes: description, feedback type, page URL (sensitive parameters redacted), page title, environment info, diagnostics (error counts and messages), screenshot link, share link and timestamps
- The Feishu app credentials (App ID / App Secret) are entered by you, used only to obtain an access token and write records, and stored in your integration config; deleting the integration deletes the credentials
- Failed writes are retried automatically and logged in the delivery log; after 20 consecutive failures the integration pauses automatically and you are notified by email
- The destination is a third-party table or endpoint you configure yourself, and the pushed content includes the diagnostics above β error messages included. Make sure that destination's access control and retention fit your requirements
Teams and Member Data
- Teams store the membership relationship (who belongs to which team), the invitation records and each member's display nickname β used only to attribute and display reports
- An invitation becomes membership only after the invitee explicitly accepts it; declining shares no data with the inviter
- Owner and member roles differ in management permissions. Members can use shared integrations, but never see the underlying credentials
- Leaving a team removes the membership relationship; reports already delivered to that team's integrations remain in those external systems and are governed by their own retention rules
Diagnostic Data Collection
- The extension can optionally collect console errors (error-level console output and unhandled JS exceptions) and failed network requests (HTTP status β₯ 400) from the current page
- This feature is on by default but fully optional β you can uncheck "Include diagnostic info" at any time before sharing or submitting
- Diagnostic data is only included in report content when you actively share or submit with the checkbox enabled
- Diagnostic data is never uploaded automatically in the background β it is only included in reports you actively share or send
- Console errors are temporarily stored in a hidden DOM element on the page (max 30 entries) and cleared when the page unloads
- Network errors are held in browser memory (max 20 entries) and cleared after sending feedback
Technical Metadata
- When you actively share or submit a report, the extension collects the page URL, page title, browser type, operating system, screen resolution, viewport size, device pixel ratio, and submission time
- This information is only used to help developers reproduce issues and is not collected separately or used for any other purpose
Screen Recording
- Screen recording captures the current tab as a WebM video file; the recording itself happens in your browser
- Recording content is only uploaded when you actively click "Share" or submit; "Download" saves the WebM file to a local location you choose
- Trimmed segments and extracted frames are cleared after you submit or download
URL Desensitization
- When collecting failed network requests, the extension automatically redacts sensitive URL parameters (tokens, passwords, API keys, etc.) by replacing their values with ***
- Sensitive parameter names include: token, key, secret, password, pwd, auth, access_token, refresh_token, api_key, private_key (case-insensitive)
- Example: https://api.example.com/data?token=abc123&id=456 β https://api.example.com/data?token=***&id=456
Permission Details
| Permission |
Purpose |
Privacy Impact |
activeTab |
Access current tab information for screenshot |
Temporary access only when you actively initiate |
storage |
Store your user settings and sign-in credential (keep you signed in) |
Stores the extension's local settings and sign-in state; cleared when you sign out or uninstall the extension |
scripting |
Inject annotation tools, diagnostic collectors, and recording controls into web pages |
Only active when you initiate |
tabCapture |
Capture the current tab's frame for screen recording |
Used only when you start a recording; footage is not uploaded until you share or submit |
offscreen |
Encode and process recording data inside the extension |
No network communication or personal data involved |
downloads |
Save your exported WebM recording to the downloads folder |
Written only when you actively download |
webNavigation |
Listen for page load completion during a recording to automatically resume the capture stream after navigation |
Only active while a recording is in progress; does not record browsing history |
contextMenus |
Add right-click menu shortcut |
No privacy data involved |
<all_urls> |
Enable screenshot, annotation, recording, and diagnostic data collection on any webpage |
Only active when you initiate; diagnostic data is optional and user-controlled |
Privacy Protection Commitments
- Active Sharing: Every upload requires you to actively click "Share" or submit β nothing is uploaded automatically in the background; uploads go to the share link or team integration you chose
- Data Minimization: Console errors are capped at 30 entries, network errors at 20 entries, and only the most recent subset is included in feedback
- Automatic Redaction: Sensitive URL parameters (tokens, passwords, API keys) are automatically redacted before inclusion
- Automatic Deletion on Expiry: Shared content is deleted automatically on expiry (anonymous 30 days / signed-in 90 days), and you can delete your own shares at any time
- No Selling, No Advertising: We do not sell your data or use it for advertising or profiling; data is only handled by the object storage and delivery infrastructure
- User Control: Diagnostic collection is optional and can be unchecked at any time; share links and stored reports can be deleted any time from "My shares"; uninstalling the extension clears its local data