Back to bug.dr

Privacy Policy

Last updated: October 9, 2026

bug.dr is operated by Anže Pišlar, [STILL NEEDED - full street address]. Questions: privacy@bugdr.app.

01Who we are

bug.dr is a service for practicing how to fix production bugs with an AI assistant. It is operated by Anže Pišlar (the "operator"), trading as bug.dr. The operator's registered address is [STILL NEEDED - full street address].

If you have any questions about this policy or your data, email us at privacy@bugdr.app. We aim to reply within a few working days.

02What we collect

When you join the waitlist. Your email address (required). Your company name (optional). A short free-text reason for joining (optional). We collect exactly what you type into the form and nothing else at this stage.

After launch, when you create an account. Your account details (name, email, password hash, sign-in provider if you use one). Your onboarding answers: your role, your years of experience with production code and your goal (get hired, improve skills or both).

When you solve problems. Which problems you opened, started and solved. Time-on-task. The code and files you write in the workspace. Terminal commands and test runs. Prompts you send to the AI assistant and the responses the assistant returns. Token and cost usage for the AI. Your scores and streaks. Your contest history. Anything you choose to put on a public profile.

Operational data. Standard server logs (IP address, user agent, request timestamps). Cookies and similar storage as described in the Cookies and analytics section.

03Why we use it and our legal basis

We process your personal data on the following legal bases under the GDPR.

Consent. For the waitlist. By submitting your email you consent to us storing it and contacting you about the launch. You can withdraw this consent at any time and we will delete your entry.

Contract. After launch, to provide the service you signed up for: account access, the workspace, scoring, your profile, contest results, support replies.

Legitimate interests. To keep the service secure (logs, abuse detection, account integrity) and to improve the problems and the product. We balance these interests against your rights and only keep the minimum data needed.

04Who we share it with

We use a small number of processors to run bug.dr. Each one receives only the data it needs to do its job, under a written data-processing agreement.

  • Railway hosts the application and your workspace data.
  • Anthropic and OpenAI receive your prompts and the code context sent to the assistant. They return a response and may keep a temporary record for safety and abuse monitoring. We do not send them your account email or your full workspace history, only what the assistant needs to answer your current question. Neither Anthropic nor OpenAI trains on API prompts by default.

International transfers. Some of these processors may store or process data outside the European Economic Area. Where that happens, we rely on Standard Contractual Clauses (SCCs) to protect your data.

You decide whether to share your profile. We do not send your profile or scores to employers or recruiters unless you share it or ask us to.

05How long we keep it

Waitlist. Until we have sent the launch emails, plus a short grace period of 30 days after launch emails are sent, or until you ask us to delete your entry, whichever comes first.

Account and workspace data. For as long as your account is active. When you delete your account, we delete personal data within 30 days, except where we have to keep certain records for tax, accounting, or legal-hold reasons.

Backups. Encrypted backups are kept for 30 days and then rotated out.

06Cookies and analytics

We do not use third-party analytics.

07Your rights under GDPR

If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data ("right to be forgotten").
  • Restrict or object to certain processing, including direct marketing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Complain to your data protection authority. In Croatia, the supervisory authority is the Personal Data Protection Agency (AZOP). In Slovenia, it is the Information Commissioner. You can also complain to the authority in your country of residence.

To exercise any of these rights, email privacy@bugdr.app. We will reply within one month.

08Security

We protect your data with reasonable technical and organisational measures: encryption in transit (TLS), encryption at rest, access controls on operator accounts, audit logs for sensitive actions, and regular review of our processors. No system is perfectly secure, but we work to keep your data safe.

If we become aware of a personal data breach that is likely to affect you, we will notify you and the relevant authority as required by law.

09Children

bug.dr is not for people under 16. If you believe a child has signed up, we will delete the account.

10Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date at the top and, for material changes, email affected users or show a notice in the app. Older versions are available on request.