Security
Where your data goes, and how to keep private data out.
This page is for security and vendor reviews. It says where BugTape stores data, who processes it, how long it is kept, and which settings stop private data from leaving your users' browsers or your servers.
- Data regionSydney, Australia: the app and its database. There is no EU region.
- SOC 2BugTape is not SOC 2 certified. We answer security questionnaires.
- In the browserInputs masked before a report is sent, and reports go out only on an error or a user report
- Sealed detailsClient details you mark are sealed with your key; BugTape cannot read them
- Scoped keysCapture keys can only send and are stored as digests. Agent tokens reach only the projects and scopes you grant
- 7 or 30 daysRecorded events are deleted after your plan’s window
Where data is stored
Report data and the BugTape database stay in Australia. The BugTape app runs on Fly.io in Sydney, and its Postgres database is Neon on AWS in the ap-southeast-2 (Sydney) region. Email delivery and payments go through the services in the table below, some of which are outside Australia.
In the browser, the SDK keeps recent activity in memory. The replay, network and console record is sent only when a user submits a report or an error is reported automatically. The SDK also sends a small activity signal so the console can show who is active now: the page address, page title and last click. In strict mode that signal carries only the page path. Turn it off with presence: false.
Keep private data out
You choose how much each app sends. Pick the setting in Setup when you copy the install snippet.
- Standard. Typed values in inputs are masked, and emails, card numbers and tokens are scrubbed from recorded text. Visible page text is recorded unless you mark it with
data-bugtape-ignore. - Strict (
privacy: 'strict'). Every character of page text in the replay becomes a solid block in the browser before it is sent (so “Anna Smith” is recorded as “▇▇▇▇ ▇▇▇▇▇”). Titles, labels and alt text are masked too, URLs lose their query strings, and request bodies are never kept. Layout, clicks and scrolls stay, so the replay still shows what the user did. Error messages, stack traces and the first text of console messages are still sent after the PII scrub, so an error message that includes a client name carries it. - Sealed client details (
tokenize: { publicKey }). Text in elements you mark withdata-bugtape-tokenleaves the browser as a placeholder such as ⟦bt:1⟧. The real values are sealed with your public key; BugTape stores them but cannot open them. Your team opens them on the issue page with the private key, which stays in the browser tab. How it works. - Errors only (
disableDomRecording: true). No page replay at all. Errors and failed requests are still reported. - Server errors only. The Python and Node.js SDKs and the HTTP API send a stack trace and code location. The Node.js SDK never reads request bodies, headers or query strings and also redacts messages by pattern. The Python SDK never reads frame locals and redacts numbers, amounts, emails, SQL and IDs from messages by pattern.
send_messages=Falsesends only the exception type.
Before you install on screens with client data, follow the privacy checklist: send one report and search the stored data for the private values.
Subprocessors
| Company | What it does for BugTape | Data it handles | Location |
|---|---|---|---|
| Fly.io | Runs the BugTape app | Reports and account data in transit and in use | Sydney, Australia |
| Neon | Postgres database | Stored reports, issues and accounts | AWS ap-southeast-2, Australia |
| Stripe | Payments | Billing contact and card details (BugTape never sees card numbers) | Stripe's global infrastructure |
| Resend | Email delivery | Email address and the message | United States |
| OpenAI, then Anthropic, then Google | AI summaries. OpenAI by default; the next one is used only if a provider is unavailable | The relevant slice of a report, never account passwords or keys | United States |
| Cloudflare | DNS and the public marketing site | Website visits; no report data | Global |
How long data is kept
- Recorded events: 7 days on Free, 30 days on Pro and Prepaid credits. Then they are deleted.
- Issues and their summaries: until you delete them or your account.
- Account data: until you delete the account, or after 12 months without activity.
- Server logs: up to 90 days.
Export and deletion
Account owners can export their data and delete their account through the API (POST /v1/auth/data-export, then POST /v1/auth/data-delete/request and /confirm). Email hi@bugtape.ai and we will do it for you.
Access and security
- All connections to BugTape use HTTPS.
- Passwords are stored as bcrypt hashes. Capture keys are stored as digests, so they cannot be read back.
- Changing a password or email signs out every existing session.
- Agent tokens are limited to the scopes and projects you grant. Capture keys can only send reports.
- When BugTape support opens your workspace to help, the console shows a banner, and support can never change billing.
- BugTape is not SOC 2 certified. We answer security questionnaires on request.
Data processing agreement
If your organisation needs a signed data processing agreement, email hi@bugtape.ai.
Report a security issue
Email hi@bugtape.ai with the details. A person replies within 5 business days.