Privacy Policy
Last updated 11 October 2026
Bug Smash is a product of ArusLogic, a division of ARUS ENTERPRISES LLC. This policy explains what personal data we collect when you use the Bug Smash website, web app, API, smash CLI and browser extension, why, who we share it with, and the choices you have. In short: we collect what we need to run the Service, we don't sell or share personal data for advertising, and we have no ads and no tracking cookies.
1. Who we are, and our role
ARUS ENTERPRISES LLC (a Wyoming company) is the controller of your account, billing and website data.
For the content your workspace puts into Bug Smash (bugs, screenshots, traces, videos, console logs and captures), your workspace's owner is the controller and we are its processor: we handle it only to provide the Service, under our Data Processing Addendum. If that content includes your personal data and you want it changed or removed, ask the workspace owner first; we'll help them.
2. What we collect
Your account. Name, email address, password (stored only as a salted hash), avatar emoji and colour. If you sign in with Google, we receive your name, email and profile picture address from Google; we don't get your Google password or access to anything else.
Workspaces. Workspace and project names, members and their roles, invitations (the invited email address), activity and XP.
Billing. Stripe handles payment. We keep your Stripe customer ID, plan, subscription status and billing period. We never see or store full card numbers. Stripe may collect your billing address and tax ID to work out tax.
Your workspace's content. Everything you or your tools send to a project, such as bug reports, notes, page addresses, screenshots, traces, videos, console errors and failed network requests. This may contain personal data about other people if it appears on the pages being tested.
Sign-in tokens. API tokens for the CLI and extension (stored hashed, with a name and last-used time), sessions (with IP address and browser user agent, for security), and device sign-in codes while they are pending.
Technical and error data. Our hosting keeps request logs (IP address, time, path, user agent) for security and debugging. When something breaks, Sentry receives the error and the code path that caused it, configured so it gets no user details, cookies, headers, request bodies or query strings.
Emails and support. When we email you (sign-in links, password resets, invitations, billing notices) our email provider records whether it was delivered. If you write to us, we keep the conversation.
3. The CLI and the browser extension
- The
smashCLI keeps your API token in your operating system's keychain (or a file only your user can read) and its settings in~/.bugsmash. It sends to Bug Smash only what you or your coding agent ask it to record: runs, steps, bugs, screenshots and traces. - Saved logins for the sites you test (
smash login) stay on your computer, readable only by your user. They are never uploaded to Bug Smash. When you hand a login over from the extension, it goes straight to the CLI over your own computer's loopback address (127.0.0.1), after you type a pairing code, and only for the site you allowed. - The CLI has no analytics or telemetry.
- The extension sends information only when you ask it to. Extension privacy lists exactly what it collects and when.
4. Why we use it (and our legal bases)
- To provide the Service: run your account and workspaces, store and show your content, sign you in, and support you (performance of our contract with you).
- To bill you and keep tax and accounting records (contract; legal obligation).
- To keep the Service secure and working: prevent abuse and fraud, enforce our terms, fix errors (our legitimate interests in a safe, reliable service).
- To email you about the Service: sign-in, security, billing, invitations and changes to these policies (contract; legitimate interests). Any optional email we add, such as a weekly digest, can be turned off in your profile and has an unsubscribe link.
- To meet legal obligations and answer lawful requests.
We don't sell personal data, share it for cross-context behavioural advertising, use it to train AI models, or make decisions with legal effects about you by automated means alone.
5. Who we share it with
- Service providers that host and run Bug Smash for us, under contracts that limit their use of the data. They are listed, with what they do and where, on our subprocessors page.
- Your workspace: other members and viewers of a workspace see its content and your name, avatar and activity there. Coding agents your workspace connects can read what the workspace can.
- Integrations you turn on, such as an issue tracker or chat app, receive what you choose to send them.
- Legal and safety: when the law requires it, or to protect the rights and safety of people or of Bug Smash.
- A buyer or successor if the business is merged, sold or reorganised, under this policy.
6. Cookies and local storage
We use only cookies the Service needs to work, so we don't show a cookie banner:
- Sign-in session cookies (set by our auth system), which keep you signed in for up to 30 days.
bs_last_project, which remembers the last project you opened.- Your light or dark theme choice, kept in your browser's local storage.
We don't use advertising or cross-site tracking cookies. Stripe sets its own cookies on its checkout and billing pages, for fraud prevention.
7. How long we keep it
- Account data: while your account exists. Deleting your account (Account → Profile) deletes it, and the workspaces where you are the only member.
- Screenshots, traces and videos: your workspace's plan window (30 days on Free, one year on paid plans), then deleted automatically. Other workspace content stays until someone deletes it or the workspace is deleted.
- Sessions expire after 30 days; pending sign-in codes after minutes; invitations after 7 days.
- Billing records: as long as tax law requires (usually up to 7 years), mostly held by Stripe.
- Error reports and server logs: up to 90 days.
- Backups: deleted data leaves our database backups within 30 days.
8. International transfers
We are based in the United States and our servers are in the United States (US East). If you use Bug Smash from elsewhere, including the EU, UK or Switzerland, your data is transferred to the US. We rely on the European Commission's Standard Contractual Clauses (and the UK Addendum), included in our DPA and in our providers' terms, and on providers' certifications under the EU-US Data Privacy Framework where they have them.
9. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or US state laws such as California's), you can ask us to:
- tell you what personal data we hold about you and give you a copy, including in a portable format;
- correct it (you can change your name and email yourself in Profile);
- delete it (you can delete your account yourself in Profile);
- restrict or object to how we use it, including use based on our legitimate interests;
- withdraw consent, where we rely on it.
Email support@bugsmash.dev from the address on your account. We reply within 30 days (45 for some US states) and may need to confirm it's you. You may use an authorised agent. We won't treat you differently for using these rights. If you're unhappy with our answer, you can complain to your local data protection authority.
California: in the last 12 months we collected the categories in section 2 (identifiers, commercial information, internet activity) for the purposes in section 4, and disclosed them only to the service providers in section 5. We don't sell or share personal information, and we don't use sensitive personal information for inferring characteristics.
10. Security
Data is encrypted in transit (HTTPS) and at rest. Files are in private storage and reached only through short-lived signed links. Passwords and API tokens are stored hashed. Every query is scoped to the workspace that owns the data. See Security for more, and how to report a problem. If a breach affects your personal data, we'll tell you and the authorities as the law requires.
11. Children
Bug Smash is for professional use and not for anyone under 16. We don't knowingly collect their data; if you think we have, tell us and we'll delete it.
12. Changes
When we change this policy, we update the date at the top. If a change matters, we'll email account holders or show a notice in the app before it takes effect.
13. Contact
Questions or requests about privacy go to support@bugsmash.dev, or by post to:
ARUS ENTERPRISES LLC (ArusLogic)
30 N Gould St Ste N
Sheridan, WY 82801
United States
support@bugsmash.dev