// Privacy Policy

Your data, explained

How bugasm collects, uses, and protects your information.

Effective July 9, 2026

1. Data We Collect

Account information -- When you register, we collect your name, email address, and authentication credentials managed through our identity provider. If you sign in via a federated identity provider (Google, GitHub, etc.), we receive only the profile fields you authorize.

Lab activity -- We record which labs you attempt, your completion status, flag submissions, scores, streaks, and time spent. For AI-scored labs, we store the conversation transcript between you and the target LLM so the grading model can evaluate your attempt.

Session and device data -- We collect IP addresses, browser type, operating system, and referral URLs to maintain security and improve the platform.

Payment information -- If you purchase a subscription, payment details are processed by our third-party payment processor. We do not store full card numbers on our servers.

Author content -- If you create labs through Author Studio, we store your lab definitions, configurations, and any associated metadata.

2. Ephemeral Lab Environments

Lab environments (containers, sandboxed runtimes) are provisioned on demand and destroyed when your session ends or times out. No user-generated data persists inside a lab environment after teardown. The only artifacts retained are your flag submissions, scores, and -- for AI labs -- the graded conversation transcript.

Environments run in isolation using gVisor and network-policy enforcement. No data from your lab session is accessible to other users.

3. How We Use Your Data

Provide and operate the platform -- authenticate you, provision lab environments, track progress, issue certificates, and display leaderboards.

AI scoring and feedback -- conversation transcripts from AI labs are sent to a large language model for automated grading. Transcripts are not used to train third-party models.

Security and abuse prevention -- detect unauthorized access, monitor for platform abuse, and enforce rate limits.

Platform improvement -- aggregate, anonymized usage data helps us understand which labs are popular, where users struggle, and how to improve content.

Communications -- send transactional emails (password resets, certificate issuance) and, with your consent, product updates. You can opt out of non-essential emails at any time.

4. Cookies and Tracking

We use strictly necessary cookies for authentication sessions and CSRF protection. These cannot be disabled without breaking core functionality.

We may use analytics cookies to understand aggregate usage patterns. Where required by law, we obtain your consent before setting non-essential cookies.

We do not sell your data to advertisers or use third-party ad-tracking pixels.

5. Third-Party Services

Authentication -- Our self-hosted identity provider manages identity, federation, and session tokens.

AI grading -- conversation transcripts are processed by large language model providers for scoring. We transmit only the lab transcript and grading rubric; no other personal data is included in the request.

Infrastructure -- cloud hosting providers process data on our behalf under data processing agreements.

We do not sell, rent, or trade your personal data to third parties.

6. Data Retention

Account data is retained for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law.

Lab activity records (completions, scores, flag submissions) are retained to support your progress history and certificates. These are deleted upon account deletion.

AI lab transcripts are retained for grading verification and platform improvement. They are purged upon account deletion.

Server logs containing IP addresses are retained for up to 90 days for security and debugging purposes.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

Access -- request a copy of the personal data we hold about you.

Rectification -- correct inaccurate or incomplete data.

Deletion -- request deletion of your account and associated data.

Export -- receive your data in a portable, machine-readable format.

Restriction -- limit how we process your data in certain circumstances.

Objection -- object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@bugasm.com. We will respond within 30 days.

8. Security Measures

All data in transit is encrypted via TLS. Data at rest is encrypted using AES-256.

Lab environments are sandboxed using gVisor with network-policy isolation, ensuring no cross-tenant data access.

Authentication tokens are short-lived and rotated automatically. Federated logout terminates both application and identity-provider sessions.

We conduct regular security reviews of our platform and infrastructure. If you discover a vulnerability, please report it to security@bugasm.com.

9. International Data Transfers

If you access the platform from outside the region where our servers are hosted, your data may be transferred internationally. We ensure appropriate safeguards (such as standard contractual clauses) are in place for any cross-border data transfers.

10. Children's Privacy

bugasm is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Continued use of bugasm after changes take effect constitutes acceptance of the revised policy.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, contact us at:

Email: privacy@bugasm.com

For security-related concerns: security@bugasm.com