BugsRadar

Security and data

The shortest way to protect data is not to keep it. BugsRadar forwards your events and stores none of them; what it does keep, it keeps encrypted, on servers in the European Union.

What is never stored

The events your applications send - error messages, exception types and stack traces, message templates and their properties, the environment, host name and application version - stay in memory only until they are delivered to the channels of their project. They are not written to disk or to a database. While an error keeps repeating, BugsRadar keeps in memory a counter with its latest sample and the id of the message it sent to your chat, to update that message with the count. That is all.

So there is no archive of your errors on our side to leak, to subpoena or to forget to delete. From the moment of delivery the message lives in your Telegram, Discord or Pushover, under the terms of that service.

What is stored

Nothing is sold to anyone. The full list, the legal bases and your rights are in the Privacy Policy.

Channel credentials

A Telegram bot token, a Discord webhook URL or a Pushover token is encrypted with AES-256-GCM before it is saved. After saving you see only a mask such as …a1b2; the credentials never appear in our logs and can't be edited, only replaced by creating a new channel. BugsRadar uses them for three things: to send its own messages, to write the count of repeats into them, and to check the channel with the service when you save it or press Check again.

The bot, the webhook and the application are yours. Revoke the token or delete the webhook on the service's side at any time: BugsRadar turns the channel off and shows the reason.

API keys

Every project has two API keys, primary and secondary. A key does one thing: it sends events to its project. Whoever has it can fill your channels with messages, but can't read anything or change settings. If a key leaks, move your applications to the other key and press Regenerate next to the leaked one; it stops working at once.

Keep the keys in configuration, an environment variable or the secrets of your CI system, and never in a browser, mobile or desktop app you ship to others, or in a public repository: see Keep the API key secret.

Transport

Traffic to the website, the web app and the API is encrypted with HTTPS. The packages talk to api.bugsradar.com over TLS, and the key travels in a request header, never in the URL. Sign-in needs no password: each browser signs its requests to the API with its own key, which is deleted from our server when you sign out.

Where the servers are

BugsRadar runs on servers in the European Union, at Hetzner. We aim to process personal data within the European Economic Area; the services you connect - Telegram, Discord, Pushover - receive the content of your events at your instruction and handle it under their own terms.

Payments

Paid plans are bought through Stripe. Your card details never reach BugsRadar: we keep only the customer and subscription identifiers, your plan and its period. Stripe is also the source of truth for when a paid period ends; BugsRadar checks with Stripe before it changes your plan.

Your account

You can see and change your projects and channels in the web app at any time. To delete your account, write to support@bistriy.com: your personal data is deleted or anonymized within a reasonable period, except for the records we must keep under tax and accounting law.

Reporting a vulnerability

Found a security problem in BugsRadar, the web app, the API or a package? Write to support@bistriy.com. Every report is read by the team that runs the service, and you will get an answer.