Privacy Policy
Last updated: September 19, 2026
NoxSpot ("we", "us", "our") is operated by No Box Dev. This policy describes how we collect, use, and protect your information when you use the NoxSpot service.
1. Information We Collect
Account information: When you sign up via GitHub OAuth, we receive your GitHub username and user ID. We store an encrypted copy of your GitHub access token to create issues on your behalf.
Bug reports: When end users submit bug reports through the NoxSpot widget, we collect:
- Screenshot of the current page (captured client-side)
- Page URL, browser name and version, operating system, viewport size
- Recent console errors (if any)
- Selected DOM element details (CSS selector, accessible name, data attributes)
- User-provided title, description, and optional name/email
- Custom application context (if configured by the site owner)
Auto-captured errors: If enabled by the site owner, JavaScript errors are automatically reported with the error message, source URL, and browser information.
Usage data: We log IP addresses temporarily for rate limiting. We do not use analytics trackers, cookies for tracking, or third-party advertising.
2. How We Use Your Information
- To create GitHub issues containing bug report details
- To upload screenshots to our storage (Cloudflare R2)
- To send Slack notifications (if configured)
- To display report status on tracking pages
- To send a resolution email when a reporter explicitly requests one
- To prevent abuse via rate limiting
3. Data Storage and Security
Your data is stored on Cloudflare's infrastructure (Workers, D1 database, R2 storage). GitHub access tokens and reporter email addresses retained for resolution notifications are encrypted at rest using AES-GCM. Reporter email addresses are not added to GitHub Issues. All communication uses HTTPS.
4. Third-Party Services
- GitHub: Bug reports are created as GitHub Issues in your configured repository
- Cloudflare: Hosting, database, and file storage
- Slack: Optional notifications (only if you connect a workspace)
- Postmark: Transactional resolution emails requested by bug reporters
- jsDelivr CDN: The widget loads screenshot libraries from this CDN
5. Data Retention
Issue data is retained in the connected GitHub repository according to that repository's policies. Screenshot files stored by NoxSpot are automatically removed after 90 days. Organization administrators can manage NoxSpot projects through NoxConnect or contact us to request deletion.
6. Your Rights
You can:
- Access your project configuration through NoxConnect
- Delete NoxSpot projects and associated service data through NoxConnect or by contacting us
- Disconnect third-party integrations (Slack) at any time
For data subject requests under GDPR or similar regulations, contact us at support@noboxdev.com.
7. Bug Reporters (End Users)
If you submit a bug report through the widget on someone else's website, the report details and any name you provide are shared with the site owner via GitHub Issues. Email addresses are kept private from GitHub and stored only when you request a resolution notification. The site owner can trigger that transactional update when resolving the report. We do not use bug reporter data for marketing or advertising.
8. Children's Privacy
NoxSpot is not directed at children under 13. We do not knowingly collect information from children.
9. Changes
We may update this policy. Changes will be posted on this page with an updated date.
10. Contact
Questions? Email us at support@noboxdev.com.