Legal
Subprocessors
Every provider that processes data for us, what each one receives, and when. Most are involved only if you use the feature that needs them.
Subprocessors
- Cloudflare, Inc.
- PurposeHosting, compute, storage, network delivery and DDoS protection for every part of the service
- DataAll service data: account data, telemetry you send, configuration, request metadata
- WhenAlways
- Resend
- PurposeTransactional email
- DataRecipient address and message: sign-in and confirmation links, alert emails (issue title, culprit, level, environment, release), status-page notices
- WhenWhenever we send email
- Polar Software, Inc.
- PurposePayments, as merchant of record
- DataOrganization id, the purchasing person's email, plan or credit pack, usage counts for metered overage
- WhenOrganizations billed through Polar (the default)
- Stripe, Inc.
- PurposePayments
- DataOrganization id, the purchasing person's email, plan, invoice items, overage usage
- WhenOrganizations billed through Stripe
- Twilio Inc.
- PurposeVoice calls for paging
- DataThe phone number on a voice channel and a spoken summary of the alert (issue title and culprit)
- WhenOnly if you add a voice channel
- Apple Inc. (Apple Push Notification service)
- PurposePush notifications to the iOS app
- DataDevice push token, and a notification title and body (alert kind, issue title, culprit)
- WhenOnly if you register an iOS device
- Google LLC (Firebase Cloud Messaging)
- PurposePush notifications to the Android app
- DataDevice push token, and a notification title and body (alert kind, issue title, culprit)
- WhenOnly if you register an Android device
- Anthropic, PBC
- PurposeAI fix suggestions and mobile chat
- DataThe context of the issue you ask about: title, exception, stack frames with source lines, recent breadcrumbs, release; files from a repository you connected; your chat messages
- WhenOnly when someone in your organization runs the fix agent or chat with an Anthropic model
- OpenAI, L.L.C.
- PurposeAI fix suggestions
- DataThe same issue context as above
- WhenOnly when someone runs the fix agent with an OpenAI model
- Google LLC (Gemini API)
- PurposeAI fix suggestions
- DataThe same issue context as above
- WhenOnly when someone runs the fix agent with a Gemini model
| Provider | Purpose | Data | When |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, compute, storage, network delivery and DDoS protection for every part of the service | All service data: account data, telemetry you send, configuration, request metadata | Always |
| Resend | Transactional email | Recipient address and message: sign-in and confirmation links, alert emails (issue title, culprit, level, environment, release), status-page notices | Whenever we send email |
| Polar Software, Inc. | Payments, as merchant of record | Organization id, the purchasing person's email, plan or credit pack, usage counts for metered overage | Organizations billed through Polar (the default) |
| Stripe, Inc. | Payments | Organization id, the purchasing person's email, plan, invoice items, overage usage | Organizations billed through Stripe |
| Twilio Inc. | Voice calls for paging | The phone number on a voice channel and a spoken summary of the alert (issue title and culprit) | Only if you add a voice channel |
| Apple Inc. (Apple Push Notification service) | Push notifications to the iOS app | Device push token, and a notification title and body (alert kind, issue title, culprit) | Only if you register an iOS device |
| Google LLC (Firebase Cloud Messaging) | Push notifications to the Android app | Device push token, and a notification title and body (alert kind, issue title, culprit) | Only if you register an Android device |
| Anthropic, PBC | AI fix suggestions and mobile chat | The context of the issue you ask about: title, exception, stack frames with source lines, recent breadcrumbs, release; files from a repository you connected; your chat messages | Only when someone in your organization runs the fix agent or chat with an Anthropic model |
| OpenAI, L.L.C. | AI fix suggestions | The same issue context as above | Only when someone runs the fix agent with an OpenAI model |
| Google LLC (Gemini API) | AI fix suggestions | The same issue context as above | Only when someone runs the fix agent with a Gemini model |
Services you choose to connect
These receive data because you choose to use them, and they act under their own terms, not as our subprocessors.
- Google, GitHub or Microsoft sign-in: Their sign-in flow; we receive your account id, email, name and avatar.
- GitHub repositories you connect: Files the fix agent reads; the branch, commit and pull request it opens when you ask for one.
- Slack, Discord, Microsoft Teams, PagerDuty and webhooks: Alert contents you route there: kind, issue title, culprit, level, environment, release and a link.
- Your browser's push service: Web push notifications, end-to-end encrypted so the push service cannot read them.
Changes
We update this page before a new subprocessor receives data, and we email organization owners when we add one. To object, write to privacy@bugwatch.io.