SnagFrog collects what it needs to deliver bug reports from people who use an app to the developer who makes it, and nothing else. No ads, no trackers on reports or the dashboard, and nothing is sold.
SnagFrog is run by Gjorge Karakabakov. Questions or requests: gorgekara@gmail.com.
Two kinds of people use SnagFrog
- Developers sign up, add their apps, and read and answer reports.
- Reporters send a report through a developer's SnagFrog page, web widget or app. They don't need an account.
When you send a report, it goes to the developer of that app, and they decide what happens with it (in privacy-law terms they're the controller and SnagFrog processes the report on their behalf). To get a report changed or deleted, ask the developer — replying to their email works — or email me and I'll pass it on.
What a report contains
- What you type: the summary and details, and your name and email if you give them.
- Files you attach, such as screenshots.
- Technical details, listed under “What we'll include” before you send: app version, operating system, device model, browser, screen and window size, language and time zone. The web widget also adds the page address and recent console errors from that page.
- From a Mac app using SnagFrog's helper: the end of the app's log files and a snapshot of the app window. These are listed on the form and you can untick them; if you do, they're deleted.
- Messages you send later, by email or on your report's tracking page.
Your IP address is used to limit how many reports, uploads and sign-in emails can be sent in a short time. Only a one-way hash of it is stored, in a counter that's deleted within a day.
What SnagFrog keeps about developers
- Your email address, used to sign in with a one-time link.
- Your workspace: apps and their settings, reports, replies, internal notes, labels and saved replies.
- API tokens, stored only as a one-way hash.
SnagFrog sends sign-in links, report confirmations, replies and notifications. Reply-to addresses contain a random code so your answer lands in the right conversation. Email that reaches SnagFrog's inbox without matching a report is forwarded to me so it isn't lost.
AI assistants
Developers can connect an AI assistant, such as Claude, to their workspace through SnagFrog's MCP server, for example to help fix a bug. Report content the assistant reads is then sent to that AI provider under the developer's own account and the provider's terms. SnagFrog itself doesn't send reports to AI providers.
Where data is stored
- Supabase: database, sign-in and file storage, in Frankfurt, Germany.
- Netlify: hosts the website and runs the server code in Frankfurt. Like any host it keeps standard request logs for a limited time.
- Resend: sends and receives email, in the United States.
- Google Fonts: serves the typeface, which shares your IP address with Google.
- Polar: handles payments for paid plans as the merchant of record. Card details go to Polar and its payment processor, never to SnagFrog; SnagFrog only learns the plan, its status and your billing email.
- PostHog: counts visits to the public pages, in Frankfurt, Germany. See below.
Data is encrypted in transit. Attachments are private and only shown through links that expire.
Cookies
The dashboard sets one sign-in cookie so you stay signed in. Report pages, tracking pages and the widget set no cookies. There's no advertising on any page.
Visitor counts
The home page, this page, the terms and the sign-in page count anonymous visits with PostHog, hosted in the EU (Frankfurt): which of those pages were opened, where visitors came from, and which links and buttons were clicked. It runs without cookies and stores nothing on your device, your IP address isn't kept, and there's no session recording. Report pages, tracking pages, the widget and the dashboard don't load it at all, so nothing in a report ever reaches it.
How long data is kept
- Reports, messages and files stay until the developer deletes them, the app, or their account.
- Files that were uploaded but never sent with a report may be kept until they're cleaned up.
- Developers can delete their account and everything in it under Account in the dashboard. It happens immediately. You can also email me.
Your rights
You can ask for a copy of your data, a correction, or deletion. If you're in the EU or UK you also have the right to object, to restrict processing and to complain to your data protection authority. Email gorgekara@gmail.com; I answer within 30 days.
Changes
If this page changes in a way that matters, the date at the top changes and developers get an email.