Legal
Privacy Notice
What we collect, why we collect it, and how long we keep it.
Last updated: 9 August 2026
1. Who we are
Đorđije Lazarević, sole trader, Bijeljina, Bosnia and Herzegovina, is the controller for personal data about BugCatch account holders. Contact: privacy@bugcatch.app.
For the error data you send us from your own applications, you are the controller and we act as your processor. We only process it to provide the service to you.
2. What we collect
Account data
- Name, email address, hashed password (or your Google account identifier if you sign in with Google).
- Two-factor authentication secrets, stored encrypted.
- Project names, API keys and notification preferences.
Error and monitoring data you send us
This is entirely under your control - it is whatever your application transmits. It typically includes stack traces, breadcrumbs, request URLs, browser and platform information, IP addresses, and any user identifier or custom tags you attach.
Do not send us special category data or payment card numbers. Use your SDK's scrubbing options to strip anything sensitive before it leaves your application.
Usage and technical data
- Event counts per billing period, for quota enforcement.
- Server logs, including IP address and timestamps, for security and debugging.
3. Why we process it, and on what basis
| Purpose | Legal basis |
|---|---|
| Providing the service and your account | Performance of a contract |
| Billing, invoicing and tax | Contract and legal obligation |
| Service and security emails | Contract and legitimate interests |
| Product update emails you can switch off | Legitimate interests, or consent where required |
| Preventing abuse and securing the platform | Legitimate interests |
4. How long we keep it
- Events: for the retention window of your plan - 7 days on Free, 30 on Starter, 90 on Pro, 365 on Business - after which they are deleted by a scheduled job.
- Uptime checks and server metrics: 30 days.
- Account data: until you delete your account, plus any period we must keep records for tax or accounting.
5. Who else processes it
We use a small number of subprocessors:
| Provider | Purpose |
|---|---|
| Paddle.com Market Ltd | Payments, invoicing, tax (Merchant of Record) |
| Hetzner Online GmbH (Helsinki, Finland) | Servers and database hosting |
| Porkbun LLC | Transactional email delivery |
| Google LLC | Sign-in with Google, if you use it |
We do not sell personal data, and we do not use your error data to train machine learning models.
6. Where data is stored
Servers and the database are hosted by Hetzner in Helsinki, Finland, inside the European Union. Some of our subprocessors may process limited data outside the EU; where that happens, the transfer relies on the European Commission's Standard Contractual Clauses or an equivalent safeguard.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, and to object to it. Write to privacy@bugcatch.app and we will respond within 30 days. You can also complain to your local data protection authority.
If your request concerns data sent to us by one of our customers, we will refer you to that customer, since they decide what happens to it.
8. Cookies
The application uses local storage to keep you signed in and to remember your theme. We do not use advertising or cross-site tracking cookies. Paddle sets its own cookies during checkout, governed by their privacy notice.
9. Security
Passwords are hashed with bcrypt, traffic is encrypted in transit, two-factor authentication is available on every account, and project owners can require it for their whole team. If a breach affects your data, we will notify you without undue delay.
10. Changes
We will post any change here and update the date above. For material changes we will email account holders.