Third parties that process data on our behalf when you use BugCapture. Last updated 18 August 2026.
Current
| Subprocessor | What it does | Data it holds | Location |
|---|---|---|---|
| Google Cloud / Firebase (Google LLC) | Authentication, database, file storage, server functions, dashboard hosting | Account details, workspace membership, bug report metadata, screenshots and report files, integration credentials | Database and file storage in asia-south2 — Delhi, India. Server functions in asia-south1 — Mumbai, India. Account identifiers and sign-in are handled by Google's identity infrastructure. |
| Cloudflare, Inc. (Cloudflare R2) | Storage and delivery of screen recordings | Video files you record, and nothing else — no account details, no report metadata | Stored in Cloudflare's object storage with automatic region placement; Cloudflare selects the location. |
| Razorpay Software Private Limited | Card and UPI payments for the Team plan | Your payment details, which you enter on Razorpay's checkout — they are never sent to or stored on our servers. We hold only the payment reference, amount and status. | India |
There is no analytics provider, no error-tracking service and no AI or model vendor. Nothing you capture is sent to any party other than those above and the integrations you connect yourself, described next.
Not subprocessors: your integrations
When you connect an integration and file a report to it, that transfer happens at your instruction, using a credential you supplied, to an account you control. They are your vendors, not ours.
We list them because data does travel there and you should know. Nothing is sent to any of these unless you connect it and file to it.
| Destination | Sent when you file |
|---|---|
| Jira | Title, description, QA metadata, screenshots (as attachments), a share link |
| GitHub | Title, description, screenshots (uploaded into your repository), a share link |
| ClickUp | Title, description, screenshots (attachment and an inline image URL), a share link |
| Jira Service Management | As Jira, filed as a request on your service desk |
| GitLab | Title, description, a share link; screenshots by link |
| Linear | Title, description, QA metadata, a share link |
| Notion | Title, description and QA metadata as page content, a share link |
| Trello | Card title, description, a share link |
| Asana | Task name, notes, a share link |
| Azure Boards | Work item title, description, a share link |
| Bitrix24 | Task title, description, a share link |
| Sentry | Title, description and environment as an event, a share link |
| Slack | A message containing the title, QA metadata and a share link |
| Microsoft Teams | A message containing the title, QA metadata and a share link |
| Your own endpoint (custom webhook) | A JSON payload containing the report, to a URL you supply |
Once filed, that data is governed by your agreement with them and their retention rules, not ours. Deleting a BugCapture report does not remove an issue you filed.
Planned, not yet in use
| Service | For | Status |
|---|---|---|
| Resend (email delivery) | Sign-up welcome and "assigned to you" notices | Built and deployed, and sending nothing. The feature is switched off at three independent points: both feature flags are off, no provider key is configured, and no sending domain exists. It will not process any data until all three are changed — and when that happens it moves to the table above, with the notice described below. |
Changes
New subprocessors are announced to workspace admins by email at least 30 days before they start processing data, so you have time to object or leave.