Privacy Policy
Last updated [DATE]
This policy explains what DebuggerOS collects, why, and what happens to your source code when you use it. DebuggerOS is operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] (company number [COMPANY NUMBER]).
The short version: we read the parts of your repository needed to find and fix a specific bug, we send relevant code to a language model to do that, and we keep a record of the work so you can see what happened and be charged correctly. We do not sell your data and we do not use your code to train models.
What we collect
Account data
- Your email address, used to sign in by magic link and to contact you about the service.
- Authentication records — when you signed in, and from roughly where, to spot abuse.
- Your wallet balance and the ledger of top-ups and charges.
Your code and repository
When you connect a repository through GitHub, DebuggerOS receives an installation token scoped to the repositories you select. Using it, we read:
- File contents needed to investigate a reported bug, and the surrounding files they depend on.
- Repository metadata — branches, commits, build and check results.
- Build and test output produced when verifying a fix.
We also write to your repository: a fix is committed to a branch and raised as a pull request, and merged where you have allowed that. Everything written is attributable to the DebuggerOS GitHub App in your repository history.
Bug reports
When you report a bug through the in-app widget we collect what you send — your description, and where relevant the page you were on, console errors, network failures and a screenshot. Screenshots may capture whatever was on screen, so avoid reporting from a screen showing other people's personal data.
Why we process it
- To provide the service — finding the cause of a bug, producing a fix, and verifying it. This is necessary to perform our contract with you.
- To bill correctly — recording what each run cost against your balance.
- To keep the service working and safe — diagnosing failures, preventing abuse. Our legitimate interest in running a reliable service.
- To contact you about your account, and about the service where you have asked us to.
Who we share it with
We use a small number of processors. Each acts on our instructions, and none of them receive your data for their own purposes.
- [LLM PROVIDER] — receives the code and diagnostic context needed to reason about a bug and produce a fix. Under our terms with them, content sent through the API is not used to train their models.
- Supabase — our database and authentication. Stores your account, the ledger, run records and the report content described above.
- Stripe — payments. Stripe collects your card details directly; we never receive or store them. We hold only the fact of a payment and its amount.
- GitHub — the source of the code we read and the destination of the fixes we write, under the permissions you grant the GitHub App.
We may also disclose data where we are legally required to, or to establish or defend legal claims.
Training
We do not use your source code, your bug reports or your repository data to train machine learning models, and our agreements with model providers prohibit them from doing so with content sent through their APIs.
How long we keep it
- Account and billing records: for as long as your account exists, and afterwards for as long as tax and accounting rules require.
- Run records, bug reports and the code snapshots attached to them: [RETENTION PERIOD].
- Authentication logs: [RETENTION PERIOD].
Deleting your account removes your repository connections and stops all further access to your code.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to or restrict how we use it, and receive it in a portable form. To exercise any of these, contact [PRIVACY CONTACT]. You also have the right to complain to your local data protection authority.
International transfers
Our processors may handle data outside your country. Where that happens we rely on the transfer safeguards offered by those providers, including standard contractual clauses. Specific arrangements: [GOVERNING LAW / JURISDICTION].
Cookies and tracking
We do not use advertising or analytics cookies. Signing in stores a session token in your browser's local storage, which is required for the service to work. Our pages load typefaces from Google Fonts, which means your browser makes a request to Google when you visit.
Security
Repository access uses short-lived GitHub App installation tokens scoped to the repositories you choose, rather than personal access tokens. Data is encrypted in transit. Access to production data is limited to those who need it. To report a vulnerability, write to [SECURITY EMAIL].
Children
DebuggerOS is not intended for anyone under 16, and we do not knowingly collect their data.
Changes
We will update this policy as the product changes. Material changes will be notified by email or in the app before they take effect.
Contact
Questions about this policy: [PRIVACY CONTACT]. General support: [SUPPORT EMAIL].