legal
Privacy policy
Last updated September 17, 2026
Bugmark is built to be local-first. This policy explains what the Bugmark Chrome extension and this website do with information.
Summary
- Screenshots, recordings, network and console logs, annotations and comments are stored only in your browser, on your device.
- We do not upload, sell or share the content you capture. It leaves your device only when you export it or create a GitHub issue.
- Passwords, tokens, API keys, card numbers and authorization headers are masked before network data is saved.
- The extension can send anonymous feature-usage counts (never page addresses or content). You can turn this off in Settings.
- This website uses Google Analytics for Firebase to measure visits. You can decline it in the banner.
Information the extension stores on your device
When you capture feedback, the extension saves the following locally in your browser’s storage (IndexedDB and extension storage):
- The annotated screenshot and a thumbnail
- Your title, comment, type, priority and status
- Page URL and title, viewport size, pixel ratio, scroll position, browser and operating system
- Screen recordings (video, tab audio and, if you allow it, your microphone)
- Up to 150 recent console messages and JavaScript errors from the page
- Up to 150 recent network requests: method, URL, status and timing, and for fetch/XHR calls the query parameters, request and response headers, request payload and response body (text only, capped at 16 KB / 32 KB). Values that look like passwords, tokens, API keys, session IDs or card numbers, and Authorization/Cookie headers, are replaced with “[redacted]” before saving. You can turn payload recording off in Settings.
- Steps to reproduce: the names of buttons, links and fields you interacted with and pages you visited. The text you type is never stored.
- Optional “after” screenshots you capture, upload or paste
- CSS selectors and computed styles for elements you choose to inspect
- Your settings, such as your name, branding and the position of the floating button
This data never leaves your device unless you export a report or backup file and choose to share it. Uninstalling the extension removes it.
GitHub issues
If you connect GitHub, your access token is stored only in your browser’s extension storage. When you create an issue, the extension sends that item’s title, comment, steps, context, logs and (if enabled) its screenshot, recording and HAR file directly from your browser to GitHub’s API, into the repository you choose. We never receive your token or this content. GitHub’s own privacy terms apply to data stored there.
Anonymous usage statistics in the extension
To learn which features are used, the extension sends anonymous events to Google Analytics (through Firebase), for example “screenshot captured” with the capture mode, “report exported” with the format, or “recording finished” with a rounded duration. Each event includes the extension version, your browser’s interface language, a random installation ID created by the extension and a session ID. It never includes page addresses or website names, page titles, screenshots, recordings, comments, console or network logs, GitHub repositories or tokens, or anything you type on a page. Switch it off at any time in Settings → Privacy → Share anonymous usage statistics. When you uninstall the extension, Chrome opens a short page on this website that records the uninstall and asks why.
Permissions the extension requests
- Access to websites — to show the feedback button and drawing tools on pages you review, and to capture the visible tab.
- Storage & unlimited storage — to keep your screenshots locally on your device.
- Scripting & active tab — to start annotating on tabs that were already open when you installed the extension.
- Tab capture & offscreen documents — to record the current tab (and your microphone, if you allow it) when you start a recording.
- Debugger — used only while you take a mobile · tablet · desktop capture, to render the page at those screen sizes. Chrome shows a notice while it runs.
- Messages from bugmark.site — so our install page can show whether Bugmark is installed. No other website can talk to the extension.
This website
This website does not require an account. We use Google Analytics for Firebase to understand how visitors find and use the site: pages viewed, approximate location (country/city), device and browser type, referring site and campaign, scroll depth, clicks on buttons such as “Add to Chrome”, downloads and page-speed measurements. Google Analytics sets first-party cookies (such as _ga) to recognise returning visitors. IP addresses are not logged or stored by Google Analytics 4, Google signals and ad personalisation are turned off, and we don’t use this data for advertising. You can decline analytics in the cookie banner; to change your choice later, clear this site’s data in your browser. Google’s privacy policy applies to the data it processes on our behalf.
If you email us, we use your message only to respond to you.
Contact
Questions about privacy? Email support@your-domain.com.