Privacy Policy

Last updated: May 19, 2026

Summary

We collect the minimum data we need to operate Friction Bounty: email addresses, bug reports, screenshots you choose to attach, and a small amount of context (page URL, browser, OS, viewport, IP address). We never sell your data. We never see your or your customers’ payment information.

What we collect

  • Account data: name, work email, hashed password.
  • Organization data: org name, widget settings, your Stripe restricted key (encrypted at rest).
  • Report data: reporter email, title, description, optional screenshot (stored in Vercel Blob), page URL, browser, OS, viewport, IP address, optional anonymous fingerprint.
  • Operational data: rate-limit records, request logs (Vercel platform, 24h retention).

What we don't collect

We do not embed third-party trackers or analytics in the widget. We never see end-user payment details — those flow exclusively to your Stripe account.

Sub-processors

We use the following vendors to operate the Service:
  • Vercel — hosting, function logs, blob storage
  • Neon — Postgres database (via Vercel Marketplace)
  • Resend — transactional email
  • Stripe — reward issuance (per-org, on your account)

Data retention

We keep reports until you delete them or your organization. Rate-limit logs are pruned periodically. If you delete your account, we remove your records within 30 days.

Your rights (GDPR / CCPA)

Email hi@frictionbounty.app with a request to access, correct, export, or delete data we hold about you. We respond within 30 days.

Security

We use scrypt with per-user salt for password hashing, HTTPS for all traffic, HMAC-signed session cookies, encryption at rest for Stripe keys, and Postgres-backed rate limits on the public widget and auth endpoints. Report security issues to security@frictionbounty.app.

Changes

We’ll update the date above and notify customers by email for material changes.

Contact