Skip to content

Updated:

Voice2Bug Security and Data Handling

This page describes the current technical model and its limitations. It is not a certification, a security audit, or a statement of compliance.

1. What the extension may capture

During an issue reproduction session, Voice2Bug may capture:

  • user actions and step order,
  • visited URLs,
  • manually captured screenshots of the visible area of the active tab,
  • optional audio and transcription,
  • operating system, architecture, browser, language, and screen resolution,
  • console logs,
  • metadata and selected headers from requests and selected network responses, plus redacted body snippets.

Voice2Bug does not use continuous screen video recording. Audio and screenshots are optional.

The extension does not store the complete contents of localStorage, sessionStorage, or cookies from the sites you visit.

2. When collection starts

The user starts context collection in the extension while reproducing an issue. If the extension does not have valid stored consent, it asks what may be captured before the session starts. The session will not start without consent.

To capture audio, the user must enable voice recording. A screenshot of the visible area of the active tab is taken only on request. An administrator may enable an allowlist of domains. Attempts to start a session outside that list are blocked.

3. What users see before a report is delivered

In manual mode, the preview appears only after the material has been uploaded to the server system, processed, and turned into a report. The user can then edit or remove selected draft items, including the title, steps, and some evidence. These changes do not undo the earlier upload or processing.

A workspace administrator may enable automatic delivery to configured destinations. In that mode, a report may be sent after generation without separate approval in the report view.

Before a pilot, the administrator should review the destination settings and choose either manual or automatic delivery.

4. Filtering and redaction of technical data

The evidence policy limits the number and size of entries, filters out some irrelevant traffic, permits only selected headers, and redacts recognized secrets, tokens, email addresses, and selected data in URLs or request bodies. Requests that change data and requests that produce errors may still be retained as evidence when ordinary traffic is omitted.

Redaction reduces risk but does not guarantee that every item of sensitive data will be detected. Screenshots are not blurred automatically. Users should still avoid reproducing issues with production data that contains secrets, personal data, or other specially protected information.

5. Where data is stored

  • Locally: chrome.storage and IndexedDB store settings, session data, and working material, including local audio and screenshots used during the session.
  • Supabase: stores authentication, organization, license, and report data, as well as some files.
  • DigitalOcean Spaces: stores private audio and task data in the current flow, as well as some screenshots, rendered report HTML, and related files.
  • DigitalOcean Redis: stores working task data or references to files stored in Spaces. The legacy flow may store audio directly in the task data.
  • AWS: handles selected signup-form data, email messages, logs, and report enrichment through Bedrock.
  • The organization's system: Jira or an email inbox receives a report after the destination has been configured.

6. AI processing

OpenAI receives audio for transcription when the user enables voice recording and the system detects speech. Depending on the task, OpenAI may also receive text and transcripts, actions, URLs, data used to generate steps, screenshots for moderation, and filtered report, console, or network data. AWS Bedrock is used to enrich reports, and OpenAI may act as a fallback.

Voice2Bug does not claim that Zero Data Retention is active, that OpenAI processing occurs in a single region, or that all servers are located in Europe.

7. Protection in transit

Public Voice2Bug endpoints use HTTPS. HTTPS protects data while it is in transit; it does not determine how data is stored on a device, server, log, or recipient system. Voice2Bug does not describe reports as end-to-end encrypted.

8. Access to screenshots and report files

The current server system includes mechanisms for private uploads and proxied access to report files. However, behavior depends on the deployment configuration, report path, and fallback mechanism for legacy data. Voice2Bug therefore does not guarantee that every existing screenshot has been stored only as a private object.

Before testing with sensitive data, the organization should ask Voice2Bug to confirm the current configuration and run a controlled test of its own scenario.

Sharing a report creates a random token. The URL token may be exchanged for a scoped HttpOnly cookie, and report files may be served through the server system. Anyone with an active link is treated as the holder of an access token. Share links only with intended recipients.

Access through a workspace-bound link is blocked when access to that workspace is blocked or when the link is manually revoked. A legacy or anonymous link may have a fixed expiry date. Expiring or revoking a link restricts access through its token but does not automatically delete the report or its files.

10. Retention

  • Task data in Redis has a lifetime of up to 24 hours.
  • In the current flow, audio is stored as a private object in DigitalOcean Spaces. After the task is completed, the system attempts to delete it. The legacy flow may store audio in Redis and remove it from the task data after successful completion. If an error occurs, audio may remain until the task expires.
  • Voice2Bug does not publish one guaranteed automatic deletion date for reports, reproduction records, related files, or all copies of form data because the active mechanisms differ between storage locations.
  • Data sent to Jira or email is also subject to the organization's retention rules and those of the destination provider.

11. Deleting a report or data

Deleting local data or a single share does not mean that every record and copy has been deleted. Send data requests to support@voice2bug.com. Each request is reviewed separately after verifying the identity or authority of the requester or organization administrator.

Voice2Bug does not currently claim complete deletion from every storage location with a single click.

12. Technical services and regions

Voice2Bug uses Cloudflare, DigitalOcean, Supabase, Amazon Web Services, and OpenAI as technical services. Jira receives data when that integration is enabled. With website consent, the marketing site may use Google Analytics and Microsoft Clarity. The administration panel uses Sentry for error monitoring only when the service is configured.

The providers operate in different regions. The code routes Bedrock to eu-central-1 by default, and the DigitalOcean storage endpoint may point to Frankfurt. This does not mean that every component, backup, or support access remains in the EEA.

This list covers technical services visible in the code. It does not confirm which entities have signed contracts, and it is not a register of DPAs or SCCs or a complete legal list of subprocessors.

13. Access to reports through MCP

The OAuth connection is assigned to the workspace shown during login. Voice2Bug checks the client, user, membership, and permissions before a report is read. MCP exposes read-only report operations. It does not grant access to the repository or tools that write data.

Before returning data, Voice2Bug checks access and the active license again, applies rate limits, and records an audit event. The connection can be removed in the admin panel. Voice2Bug treats report content as untrusted material, not as instructions for the agent.

14. Limitations and organization responsibilities

  • Voice2Bug does not replace a security audit, an extension approval process, or the organization's data classification process.
  • Installing the extension and capturing or processing data may require IT or security approval.
  • The organization should limit a pilot to authorized users and controlled, non-sensitive data.
  • The administrator should review automatic delivery settings, email recipients, the Jira project, and link-sharing rules.
  • Voice2Bug does not claim SOC 2, ISO 27001, HIPAA, or equivalent certification.

15. Security and data processing contact

Send questions about the architecture, current configuration, reporting a security issue, or data-processing terms for a pilot to support@voice2bug.com. Providing this contact address does not mean that a data processing agreement has been signed for a particular organization.

More information is available in the Privacy Policy.