Last updated: August 4, 2026
At BugZ, we take the security and privacy of your source code and configurations extremely seriously. This Privacy Policy details how we handle, process, and protect your data when utilizing our autonomous vulnerability scanning platform.
We process your code snippets and GitHub repository files strictly in-memory. Once the scan is complete, all analyzed buffers are completely destroyed.
We do not train LLMs on your source code. Your logic, structures, and proprietary intelligence never enter any third-party fine-tuning loops.
All payload transits between your browser, our servers, and Gemini AI processing nodes are protected with TLS 1.3 transport encryption.
When running a code scan, we ingest the source code snippet or crawl repository files from the public URL provided. This information is classified as Transient Scanning Data. It is transferred securely over HTTPS, compiled briefly in RAM to prepare the prompt context, and fed to the LLM audit endpoint. We store the final vulnerability result reports under your account history only if you are authenticated.
For logged-in users, we store profile credentials, usernames, and profile metadata provided by Clerk Authentication, and we reference scan history hashes in Convex Cloud. This is used solely to render your personal scan history and statistics dashboard.
We may update our privacy policies to reflect platform expansions. If changes are significant, we will notify users via dashboard flags or email alerts.