Privacy Policy
Last updated: May 19, 2026
Summary
We collect the minimum data we need to operate Friction Bounty: email addresses, bug reports, screenshots you choose to attach, and a small amount of context (page URL, browser, OS, viewport, IP address). We never sell your data. We never see your or your customers’ payment information.
What we collect
- Account data: name, work email, hashed password.
- Organization data: org name, widget settings, your Stripe restricted key (encrypted at rest).
- Report data: reporter email, title, description, optional screenshot (stored in Vercel Blob), page URL, browser, OS, viewport, IP address, optional anonymous fingerprint.
- Operational data: rate-limit records, request logs (Vercel platform, 24h retention).
What we don't collect
We do not embed third-party trackers or analytics in the widget. We never see end-user payment details — those flow exclusively to your Stripe account.
Sub-processors
We use the following vendors to operate the Service:
- Vercel — hosting, function logs, blob storage
- Neon — Postgres database (via Vercel Marketplace)
- Resend — transactional email
- Stripe — reward issuance (per-org, on your account)
Data retention
We keep reports until you delete them or your organization. Rate-limit logs are pruned periodically. If you delete your account, we remove your records within 30 days.
Your rights (GDPR / CCPA)
Email hi@frictionbounty.app with a request to access, correct, export, or delete data we hold about you. We respond within 30 days.
Security
We use scrypt with per-user salt for password hashing, HTTPS for all traffic, HMAC-signed session cookies, encryption at rest for Stripe keys, and Postgres-backed rate limits on the public widget and auth endpoints. Report security issues to security@frictionbounty.app.
Changes
We’ll update the date above and notify customers by email for material changes.