Updated:
Voice2Bug Privacy Policy
This policy describes how the Voice2Bug website and service process data. It does not constitute legal advice.
1. Data controller and contact
The data controller for personal data processed in connection with operating the website, handling access-form submissions, and communicating directly with users is Adrian Maryniewski, trading as Adrian Maryniewski Consulting, Polish tax identification number (NIP) 5811870973, ul. 3 Maja 17/13, 82-500 Kwidzyn, Poland.
For privacy questions and data requests, contact adrian@maryniewski.pl.
In a B2B relationship, the organization using Voice2Bug may be the controller of personal data included in reports, while Voice2Bug may process that data on the organization's behalf. The allocation of these roles depends on the context and the arrangements with the organization.
2. Data that may be processed
2.1. Access, pilot, and contact forms
- email address and, if provided, first name, last name, and message content,
- form source, language, page path, and campaign parameters,
- referring page information,
- the user-agent string and the IP address or a hash of it, depending on the technical flow,
- email-confirmation status and technical identifiers associated with the message or activation process.
Personal data and secrets should not be included in campaign parameters or in URLs used to access the website.
2.2. Access, licensing, and workspace data
- email address and identifiers for the organization, user, license, and activation,
- a random, persistent installation or device identifier and, in selected server records, its hash,
- workspace role and settings, including destination settings,
- audit, security, and usage events needed to manage access and prevent abuse.
The installation identifier is a random UUID stored by the extension, not a fingerprint derived from device characteristics.
2.3. Material captured while reproducing an issue
The user initiates collection through the extension. Depending on the actions taken and the applicable permissions and settings, the material may include:
- user actions and steps used to reproduce the issue,
- visited URLs and navigation flow,
- manually captured screenshots of the visible area of the active tab,
- optional voice recording and its transcription,
- report content, title, steps, segments, and notes,
- operating system, architecture, user agent, browser version and language, and screen resolution,
- console logs,
- request metadata and allowed headers, as well as redacted snippets from request bodies and selected network responses.
The evidence policy limits the number and size of entries, filters irrelevant traffic, and redacts recognized secrets and some personal data. These filters reduce risk but do not guarantee detection of every sensitive item visible on a page or entered by a user.
2.4. Local extension data
Session data, settings, actions, URLs, console and network data, report drafts, screenshots, and audio may be stored temporarily in chrome.storage or IndexedDB on the user's device. Uninstalling the extension or using its local data-clearing feature may remove data from the device, but it will not delete copies already sent to server systems or configured destinations.
2.5. Website analytics data
After the user consents, the website may use Google Analytics 4 and Microsoft Clarity to measure visits and interactions. Email addresses and form-field content are not included in form analytics events. If consent is declined, non-essential analytics tools are not loaded.
3. How the data is used
- handling a request and confirming an email address,
- provisioning and activating a free 30-day trial,
- generating, storing, displaying, and delivering reports according to the selected configuration,
- transcribing, structuring, moderating, and enriching report material,
- providing support, maintaining security, auditing activity, and preventing abuse,
- performing website analytics and measuring campaigns after consent.
4. Data sent to AI services
Voice2Bug uses OpenAI and AWS Bedrock depending on the task and provider availability.
- Audio may be sent to OpenAI for transcription.
- Transcripts, text, actions, selectors, values, URLs, and data used to generate report titles or steps may be sent to OpenAI.
- Screenshots may be sent to OpenAI for image moderation.
- Filtered console, network, and report data may be sent to OpenAI or AWS Bedrock for classification, embedding generation, or other processing tasks.
- Report enrichment is routed through AWS Bedrock by default, with OpenAI available as a fallback.
Voice2Bug does not claim that Zero Data Retention is currently enabled or that OpenAI processing occurs in a single region. Processing also depends on provider account settings.
5. Where data is stored
- User's device:
chrome.storageand IndexedDB for settings and working material. - DigitalOcean Managed Redis: a job queue containing the task payload, including temporary audio and report context.
- Supabase: authentication data; organization, license, and report data; access-process data; and some stored assets.
- DigitalOcean Spaces: some screenshots, report HTML, and other report assets.
- AWS DynamoDB: form and subscriber data for workflows handled by AWS.
- Recipient system: a report delivered to Jira Cloud or email is then stored according to the rules of the organization and the selected system.
6. Technical providers and recipients
Depending on the function used, data may be handled by the following services:
- Cloudflare Pages: hosts the public website.
- DigitalOcean: hosts the backend, Redis queue, and report assets.
- Supabase: provides the database, authentication, some storage, and server functions.
- Amazon Web Services: provides Bedrock, Lambda, API Gateway, DynamoDB, SES, and CloudWatch.
- OpenAI: provides transcription, text processing, embedding generation, and moderation.
- Atlassian Jira Cloud: receives reports when configured by the organization as a destination.
- The recipient's email provider: receives a report or message when it is sent by email.
- Google Analytics 4 and Microsoft Clarity: provide analytics only within the scope enabled after consent.
- Sentry: may provide administration-panel monitoring if it is enabled.
This list describes the services' technical functions. Not every listed service is involved in every report.
7. Regions and possible transfers
Voice2Bug uses providers operating in different regions and does not claim that all servers or all processing operations are located exclusively in the European Union. In the codebase, AWS Bedrock requests default to eu-central-1, and a DigitalOcean storage endpoint points to Frankfurt; production settings, other services, backups, support access, and provider accounts may use different regions. For questions about the current architecture or data processing arrangements, contact adrian@maryniewski.pl.
8. Retention
- The Redis job payload has a technical retention period of up to 24 hours.
- After successful report generation, Voice2Bug attempts to remove audio from the Redis payload. If report generation or cleanup fails, the audio may remain until the payload expires.
- When a tokenized link expires, access through that link is restricted, but the report and its assets are not automatically deleted.
- Voice2Bug does not currently publish a single guaranteed automatic deletion period covering reports, assets, workspace data, and every copy of form data. Retention depends on the data category, storage location, relationship with the organization, and applicable retention mechanism.
- Data delivered to Jira Cloud, an email inbox, or another system operated by the organization is also subject to that system's retention rules.
Requests concerning specific data can be sent to adrian@maryniewski.pl.
9. Access to shared reports
A shared-report link contains a token that may be exchanged for a scoped HttpOnly cookie. Anyone with an active link can access the material. Treat the link as confidential and share it only with intended recipients. A shared link is not a private user account.
10. Data access, correction, and deletion requests
To ask about data, request a copy, correct data, or request deletion, email adrian@maryniewski.pl. Before fulfilling a request, Voice2Bug may need to verify the requester's identity or authority to act as an organization administrator.
Deleting local data or revoking a single share link does not delete every record, log, copy, or item already delivered to a system operated by the organization. Deletion requests are handled through a supervised process that covers the relevant data stores and any applicable retention requirements.
11. Technical measures and limitations
Public endpoints use HTTPS. Voice2Bug uses security measures, including access controls, tokenized links, rate limits, and the filtering and redaction of some report data. These measures do not guarantee detection of every sensitive item and do not replace the organization's security assessment. Details and limitations are described on the Security and Data Handling page.
12. Cookies and analytics consent
Essential website and administration-panel functions do not require analytics consent. Google Analytics 4 and Microsoft Clarity load only after consent. Declining consent does not prevent use of the access form.
Users can change their cookie preferences or withdraw consent through the website's cookie settings. Withdrawing consent does not automatically delete data collected before consent was withdrawn.
13. Policy changes
This policy may change when the product, providers, configuration, or data-processing requirements change. The current version and update date are published at voice2bug.com/privacy.