Legal
Privacy Policy
Last updated: 8 September 2026. This policy describes how DebugBundle collects, uses, and protects information.
Who operates DebugBundle
The hosted DebugBundle service is operated by Owen Far in Malta. For privacy questions or requests, contact support@debugbundle.com.
What we collect
When you use the hosted DebugBundle service, we collect:
- Account information (email address, hashed password)
- Event data submitted through SDKs and the ingestion API
- Usage metrics (bundle requests, event counts, alert deliveries, webhook deliveries)
- Session data for authentication purposes
- OAuth consent, grant, token-family, and verified identity records when you link an approved remote MCP integration
Linked AI integrations
When you explicitly link DebugBundle to an approved AI integration, the integration can request only the read scopes shown during consent. The OpenAI Plugin is limited to your verified email for account or workspace policy; authorized project and service metadata; incident metadata; existing redacted debug artifacts and reproductions; stored runtime-improvement evidence; aggregate product analytics; and sanitized endpoint-health configuration and results. Project names and redacted operational evidence may still be personal data if your organization included personal data in those fields.
OpenAI receives the selected categories only to answer the requests you make in a linked ChatGPT or Codex account. DebugBundle sends a tool result only after a linked user requests a matching operation. OpenAI handles that result under its own terms, privacy policy, workspace settings, and data controls.
This integration does not return raw logs, full chat history, prompt or model content, individual analytics journeys, credentials, payment data, object-storage keys, signed URLs, or database-only identifiers. It does not modify projects, incidents, artifacts, analytics settings, or health checks. Do not use the connection for projects that may return payment-card data, protected health information, government identifiers, access credentials, or other regulated sensitive data prohibited by the connected service.
DebugBundle does not create a separate stored copy of MCP tool results. The authorized source records remain subject to the retention periods below. Operational integration logs are retained for 14 days and contain only bounded request metadata such as tool, outcome, duration, and size category; they do not contain prompts, tool arguments, results, email addresses, credentials, or customer content.
You can remove any optional product scope before allowing access, review retained OpenAI connections in DebugBundle, and revoke the connection from Settings. Revocation stops future access but does not delete the underlying DebugBundle records. Account export and deletion controls remain available separately below.
How we use your data
Event data is used solely to provide DebugBundle services: incident grouping, bundle generation, alerting, and retrieval. We do not sell event data or use it for advertising.
DebugBundle acts as controller for account, billing, service-administration, security, and first-party product-telemetry information. For project data that a customer submits and controls, DebugBundle acts as a processor on that customer's instructions. We process information as needed to provide the service and meet our legal obligations, and for legitimate interests such as securing, maintaining, and improving the service. Where applicable law requires consent, we ask for it before that processing begins.
First-party product telemetry
We use DebugBundle's own AnalyticsBundle feature on debugbundle.com and app.debugbundle.com to understand aggregate page usage, route journeys, coarse device and referrer categories, session behavior, and fixed friction signals. This data is processed by DebugBundle and is not sent to an advertising or third-party analytics provider.
Standard mode uses a project-scoped opaque browser value and a separate derived hash for returning-visitor counts. App routes are stored as templates rather than project or incident identifiers. We do not include email addresses, names, account IDs, form values, raw click text, raw query strings, screenshots, DOM snapshots, precise location, raw IP addresses, secrets, or payment data in this telemetry.
Redaction
DebugBundle applies automatic redaction to sensitive patterns (passwords, authentication headers, cookies, card numbers, SSNs) before storage. See the redaction documentation for details.
Data retention
Hosted DebugBundle uses tier-based retention. Raw event blobs are retained for 7 days on Free, 14 days on Solo, and 30 days on Team. Incidents, bundles, and reproductions are retained for 7 days on Free, 30 days on Solo, and 90 days on Team. Self-hosted instances control their own retention.
For linked OAuth integrations, used authorization codes are physically deleted within 24 hours, used or revoked refresh-token families within 30 days, and expired or revoked grants within 90 days. Active grants remain until expiry, revocation, account suspension or deletion, or loss of required membership.
For a technical explanation of how cleanup works, see the security documentation.
Service providers and international transfers
We use service providers for hosting, storage, email delivery, payments, and other infrastructure needed to operate DebugBundle. A linked integration such as OpenAI receives data only after the consent and tool request described above. These providers may process information outside your country. Where an international transfer requires protection under applicable law, we use appropriate contractual and technical safeguards.
Access, export, and deletion
Hosted organization owners can review their account settings to download a JSON export of retained organization-account data and to permanently delete the current organization account. Deletion removes retained projects, incidents, tokens, audit history, and stored debugging artifacts for that organization.
Depending on applicable law, you may ask to access, correct, delete, restrict, or object to processing of your personal information, or request a portable copy. You may also lodge a complaint with your local data-protection authority. Contact support@debugbundle.com to make a request; we may need to verify your identity first.
Local-first mode
When using DebugBundle in local-only mode, no data is transmitted to DebugBundle servers. Events and bundles remain on the machine or storage volume where you run the SDK and CLI.
Contact
For privacy-related questions, see our contact page.