What We Collect
- Account info: name, email, hashed password
- Reminder data: titles, descriptions, due dates, completion status
- Usage data: notification history, escalation events, login timestamps
- Push notification tokens (for sending notifications)
- Canvas LMS tokens (encrypted, for assignment sync — Pro only)
- Discord webhook URLs (for notification delivery — Pro only)
- Stripe customer and subscription IDs (payment processing)
How We Use Your Data
- To send you reminder notifications via push, email, and Discord
- To sync assignments from Canvas LMS (if you connect it)
- To process payments via Stripe
- To improve the service and fix bugs
What We Don't Do
- We do not sell, share, or rent your data to third parties
- We do not use your data for advertising
Age Requirements (COPPA)
BugMe requires users to be at least 13 years old. We do not knowingly collect data from children under 13. If you are under 13, do not use this service. If we learn that we have collected data from a child under 13, we will delete the account immediately.
Data Security
- Canvas tokens are encrypted with AES-256-GCM
- Passwords are hashed with bcrypt (12 rounds)
- All connections use HTTPS/TLS
- Rate limiting protects against abuse
- Security headers (CSP, HSTS, X-Frame-Options) are enforced
Your Rights
- Export: Download all your data from Settings → Export My Data
- Delete: Permanently delete your account from Settings → Delete Account
- Correct: Update your profile information anytime in Settings
Third-Party Authentication
When you sign in with Google, we receive your name, email address, and profile picture. We do not access any other Google account data. Your Google credentials are never stored by BugMe — authentication is handled securely through Google's OAuth 2.0 protocol. You can revoke BugMe's access at any time from your Google Account settings.
Third-Party Services
- Google OAuth — Sign-in authentication. See Google's Privacy Policy.
- Stripe — Payment processing. See Stripe's Privacy Policy.
- Apple Push Notification service (APNs) — iOS push notifications.
- Firebase Cloud Messaging (FCM) — Android push notifications.