// PRIVACY
Privacy
Bugbear is a security product, so we hold data to the same standard we scan for. This page is a plain-language summary of what we collect and what we deliberately don't.
Your source code is not retained
To scan a repo, Bugbear pulls the relevant source into an isolated, ephemeral sandbox, runs the agents, and discards the working copy when the scan finishes. We do not persist your source code or its git history. What we keep is the report: findings (file, line, severity, exploit path, and a suggested fix) plus scan metadata (repo name, branch, commit, grade, timing).
What we store, and where
Account and entitlement data (your plan and Bugbear-token balance) live in Clerk. Findings and scan metadata live in a managed Postgres database (Neon). Payment details are handled entirely by Dodo Payments — we never see or store your card number.
GitHub access
When you install the Bugbear GitHub App, we use a short-lived, per-installation token to read the code we scan and to post pull-request checks. We request the narrowest scopes needed and never use your token for anything other than the scan you asked for.
The optional live-surface probe
If you provide a deployed URL, Bugbear makes a small number of non-intrusive requests to inspect security headers, cookies, CORS, and basic performance. The probe blocks private and internal network ranges and never attempts to exploit the site.
We don't sell your data
We do not sell personal data or share it with advertisers. We use it only to run the product you signed up for.
Access & deletion
You can export or delete your scan data, or close your account, at any time. Email support@bugbear.sh and we'll take care of it.
This summary will grow into a full policy as Bugbear matures. Questions? support@bugbear.sh