
// Privacy Policy
Your data, explained
How bugasm collects, uses, and protects your information.
Effective July 9, 2026
1. Data We Collect
Account information -- When you register, we collect your name, email address, and authentication credentials managed through our identity provider. If you sign in via a federated identity provider (Google, GitHub, etc.), we receive only the profile fields you authorize.
Lab activity -- We record which labs you attempt, your completion status, flag submissions, scores, streaks, and time spent. For AI-scored labs, we store the conversation transcript between you and the target LLM so the grading model can evaluate your attempt.
Session and device data -- We collect IP addresses, browser type, operating system, and referral URLs to maintain security and improve the platform.
Payment information -- If you purchase a subscription, payment details are processed by our third-party payment processor. We do not store full card numbers on our servers.
Author content -- If you create labs through Author Studio, we store your lab definitions, configurations, and any associated metadata.
2. Ephemeral Lab Environments
Lab environments (containers, sandboxed runtimes) are provisioned on demand and destroyed when your session ends or times out. No user-generated data persists inside a lab environment after teardown. The only artifacts retained are your flag submissions, scores, and -- for AI labs -- the graded conversation transcript.
Environments run in isolation using gVisor and network-policy enforcement. No data from your lab session is accessible to other users.
3. How We Use Your Data
Provide and operate the platform -- authenticate you, provision lab environments, track progress, issue certificates, and display leaderboards.
AI scoring and feedback -- conversation transcripts from AI labs are sent to a large language model for automated grading. Transcripts are not used to train third-party models.
Security and abuse prevention -- detect unauthorized access, monitor for platform abuse, and enforce rate limits.
Platform improvement -- aggregate, anonymized usage data helps us understand which labs are popular, where users struggle, and how to improve content.
Communications -- send transactional emails (password resets, certificate issuance) and, with your consent, product updates. You can opt out of non-essential emails at any time.
5. Third-Party Services
Authentication -- Our self-hosted identity provider manages identity, federation, and session tokens.
AI grading -- conversation transcripts are processed by large language model providers for scoring. We transmit only the lab transcript and grading rubric; no other personal data is included in the request.
Infrastructure -- cloud hosting providers process data on our behalf under data processing agreements.
We do not sell, rent, or trade your personal data to third parties.
6. Data Retention
Account data is retained for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law.
Lab activity records (completions, scores, flag submissions) are retained to support your progress history and certificates. These are deleted upon account deletion.
AI lab transcripts are retained for grading verification and platform improvement. They are purged upon account deletion.
Server logs containing IP addresses are retained for up to 90 days for security and debugging purposes.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
Access -- request a copy of the personal data we hold about you.
Rectification -- correct inaccurate or incomplete data.
Deletion -- request deletion of your account and associated data.
Export -- receive your data in a portable, machine-readable format.
Restriction -- limit how we process your data in certain circumstances.
Objection -- object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@bugasm.com. We will respond within 30 days.
8. Security Measures
All data in transit is encrypted via TLS. Data at rest is encrypted using AES-256.
Lab environments are sandboxed using gVisor with network-policy isolation, ensuring no cross-tenant data access.
Authentication tokens are short-lived and rotated automatically. Federated logout terminates both application and identity-provider sessions.
We conduct regular security reviews of our platform and infrastructure. If you discover a vulnerability, please report it to security@bugasm.com.
9. International Data Transfers
If you access the platform from outside the region where our servers are hosted, your data may be transferred internationally. We ensure appropriate safeguards (such as standard contractual clauses) are in place for any cross-border data transfers.
10. Children's Privacy
bugasm is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Continued use of bugasm after changes take effect constitutes acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy or how we handle your data, contact us at:
Email: privacy@bugasm.com
For security-related concerns: security@bugasm.com

