Privacy Policy
Last updated: August 14, 2026 · Developer: FOX Chang
1. Contact
- Developer: FOX Chang
- Email: fox100039@gmail.com
- Phone: +886 983-101-085
- This policy covers the BugEzy Chrome extension and the bugezy.dev website.
2. What We Collect
The table below maps every permission declared in the extension's manifest.json to the data it accesses and why.
| Permission | Data accessed | Why it is needed |
identity | Google account email, name and avatar (OAuth scopes: openid, email, profile) | Sign-in and account identification |
activeTab | URL of the active tab and a screenshot of its visible area | Recording bug reports and screenshot annotation |
storage | Local settings on your device (session token, language, microphone and mode preferences, ticket wallet state) | Keeping you signed in and remembering preferences |
downloads | No additional data collected | Exporting a report as a JSON file to your computer |
offscreen | Microphone audio stream (only while you have the microphone enabled and are recording) | Background audio capture for speech-to-text |
Content scripts
<all_urls> | DOM changes, console messages and failed network requests (4xx/5xx) on the tab you start recording on | The extension must work on any website, so it declares an all-URLs match. Nothing is collected or uploaded until you press record; only console errors and 4xx/5xx are captured — successful request bodies are not. |
In addition to the permissions above, using the service involves:
- Bug report contents: console messages, network errors, DOM interaction traces (rrweb), page URL and title, browser and screen information, voice recordings and their transcripts, screenshots, and any notes you type.
- Terminal logs (optional, only if you use the CLI tool): program error output and runtime environment details. Common secrets (database URLs, API keys, tokens, emails, phone numbers, national ID numbers, card numbers) are masked on your machine before upload.
- Usage counters: recordings, rewinds, MCP AI reads and token estimates, used to enforce free-plan limits.
- Payment and plan records: ECPay order number, amount, timestamp and plan expiry. We never see or store your card number.
- Promo code and ticket records: codes you redeem, ticket status and expiry.
- Feedback submissions (optional): what you write in the feedback form, plus a country code derived from your IP.
- Country code: derived by Cloudflare from your connection (e.g.
TW) to determine payment availability. We do not store your IP address.
3. How We Use It
- To record, store, display and share your bug reports.
- Speech-to-text (Groq Whisper) and AI text correction/summarisation (Cloudflare Workers AI).
- To enforce free-plan limits and manage paid subscriptions.
- To process payments through ECPay.
- To notify the developer of key events (new sign-up, new report, code redemption, successful payment) via a Discord webhook; these notifications include your account email.
- We do not use your data for advertising, do not sell it, and do not use it to train any AI model.
4. Third-Party Services
We rely on the following processors. Each links to its own privacy policy.
- Cloudflare (Workers / R2 / Workers AI) — API compute, report and screenshot storage, AI text correction and summarisation: privacy policy
- Groq (United States) — speech-to-text; your audio is sent to Groq's Whisper service for transcription: privacy policy
- Supabase — database for accounts, plans, tickets and report metadata: privacy policy
- ECPay — payment processing (card details are collected by ECPay directly and never pass through our servers): privacy policy
- Google — OAuth sign-in and basic account details: privacy policy
- Discord — operational notifications to the developer (including your account email): privacy policy
5. Storage, Retention and Security
- All data is transmitted over HTTPS.
- Large report assets (DOM traces, screenshots) are stored in Cloudflare R2; accounts and metadata in Supabase (PostgreSQL). Both are encrypted at rest.
- The database has Row Level Security enabled and denies all anonymous access; only our server can read or write, using a managed key.
- Settings and your session token live in
chrome.storage.local on your own device and never leave it.
- Retention: reports are kept for 7 days on the free plan and 90 days on paid plans (including users with an active promo ticket). Expired reports and their attachments (DOM traces, voice, screenshots) are deleted automatically by a daily job and cannot be recovered. You can also delete reports individually or in bulk from the extension at any time.
- Retention is evaluated against your plan at the time of deletion. If you downgrade from paid to free, reports created while you were paying will then fall under the 7-day rule — export anything you want to keep before downgrading.
- Sign-in sessions expire after 90 days and are then purged automatically.
- Uninstalling the extension removes all locally stored data from your device.
6. Your Rights
- Access & export: export any report as JSON from the extension.
- Correction: edit the transcript and notes in the editor before uploading.
- Deletion: delete individual reports at any time, or email us to delete your account and all associated data.
- Withdraw consent: sign out in the extension, or revoke the app from your Google Account settings.
- To exercise these rights contact fox100039@gmail.com or +886 983-101-085. We respond within 30 days.
7. Data Sharing
- We do not sell your data.
- Your report list is visible only to you after signing in.
- An individual report link is "anyone with the link can view" (similar to Google Docs link sharing) — share it carefully and avoid posting it publicly.
- We disclose data only where required by law.
8. Cookies and Tracking
- We use no third-party tracking cookies, advertising pixels, Google Analytics, or any cross-site tracking.
- The extension uses
chrome.storage.local to keep your sign-in state and preferences.
9. Google API Services User Data Policy (Limited Use)
10. Children's Privacy
- BugEzy is not directed at children under 13, and we do not knowingly collect personal information from them.
- If you believe a child has provided us with personal data, please contact us and we will delete it.
11. Changes to This Policy
- If this policy changes we will update the "Last updated" date at the top of this page.
- Material changes will be announced on the site's home page.
Contact: fox100039@gmail.com · +886 983-101-085