Browser extension privacy

Last updated 11 October 2026

The Bug Smash extension sends information only when you ask it to, and only to the Bug Smash server you signed in to (bugsmash.dev unless you changed it in the extension's settings) or to the smash command-line tool on your own computer. It has no analytics, no ads, and doesn't sell or share data. This page adds to our main Privacy Policy.

When you report a bug or send a page to your agent

Sent to your Bug Smash project, only when you click Send:

  • a screenshot of the visible part of the page, with your markings (you can paint over private details, or leave the screenshot out);
  • the page's address and title, the title and note you type, and your severity guess;
  • your window size and browser version;
  • the page's recent console errors and failed network requests, if you include them (you see them before sending).

Members of the project's workspace can see what you send, and so can the coding agents they connect.

Console capture (optional, off until you turn it on)

When on, a small script in each page keeps that page's last 50 console errors and failed requests in the page's own memory, so a report includes what happened before you clicked. Nothing is stored by the extension or sent anywhere unless you report a bug from that page. Turning it on asks Chrome for access to all sites; turn it off in the extension's settings.

Sharing a login with the CLI

When you run smash login --from-extension and type its code into the extension on a site's tab, the extension reads that site's cookies and local storage and sends them to the smash tool on your computer, over 127.0.0.1. They never go to Bug Smash's servers. Chrome asks you to allow each site first; you can remove a site in the extension's settings. The CLI keeps the login in a file only your user account can read.

Letting the CLI drive a window (--attach)

When you type the code from smash run start --attach, the extension opens a separate window and lets the CLI on your computer control it, for sites that block test browsers. It uses Chrome's debugger permission for that window only (Chrome shows a bar while it's in use), over 127.0.0.1. Your other tabs aren't touched. Closing the window or clicking Cancel on the bar stops it.

Signing in

You sign in by approving a code on the Bug Smash site. The extension keeps the resulting API token, your name and email, and your project list in Chrome's storage for this profile. Revoke the token any time under Account → API tokens.

Live run progress

While you're signed in, the extension checks your project for running test runs (every 30 seconds while one runs, every five minutes otherwise) to show progress and the bug count on its icon. These requests carry only your token.

Removing data

Uninstalling the extension deletes everything it stored. Captures you sent stay in your project until someone dismisses or deletes them; deleting your Bug Smash account deletes workspaces only you belong to.

Chrome Web Store Limited Use

The use of information received from Chrome APIs by the Bug Smash extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use that information only to provide the features described on this page. We don't sell it, use it for advertising or creditworthiness, or let people read it except with your permission, for security, or as the law requires.

Questions: support@bugsmash.dev.