Privacy Policy
Last updated: August 1, 2025
1. Introduction
Bug3 ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our decentralized bug bounty platform.
2. Information We Collect
Blockchain Data (Public)
- Wallet addresses and transaction hashes
- Smart contract interactions and events
- Voting records and token balances
- Bug report metadata stored on IPFS
Platform Data (Private)
- Profile information (username, bio, contact details)
- Project descriptions and bounty details
- Bug report content and attachments
- Communication between users
- Usage analytics and platform interactions
Technical Data
- IP addresses and browser information
- Device identifiers and operating systems
- Cookies and local storage data
- Error logs and performance metrics
3. How We Use Your Information
We use collected information for:
- Platform functionality and user authentication
- Processing bounty submissions and payments
- Community voting and validation processes
- Customer support and communication
- Platform analytics and improvement
- Security monitoring and fraud prevention
- Legal compliance and dispute resolution
4. Information Sharing and Disclosure
Public Information
The following information is publicly available on the blockchain and IPFS:
- Wallet addresses and transaction history
- Bug report summaries and validation status
- Voting records and community decisions
- Bounty details and payout information
Limited Sharing
We may share private information with:
- Project owners (for relevant bug reports)
- Service providers (hosting, analytics, support)
- Legal authorities (when required by law)
- Business partners (with explicit consent)
No Selling
We do not sell, trade, or rent your personal information to third parties.
5. Data Storage and Security
Storage Locations
- Blockchain: Polygon network (immutable, public)
- IPFS: Distributed storage (immutable, content-addressed)
- MongoDB: Off-chain analytics (encrypted, access-controlled)
- Vercel: Platform hosting (secure cloud infrastructure)
Security Measures
- End-to-end encryption for sensitive communications
- Multi-signature wallet security for platform funds
- Regular security audits and penetration testing
- Access controls and authentication mechanisms
- Secure coding practices and vulnerability monitoring
6. User Rights and Control
Your Rights
- Access: Request copies of your personal data
- Correction: Update inaccurate or incomplete information
- Deletion: Request removal of personal data (where legally possible)
- Portability: Export your data in standard formats
- Objection: Opt-out of certain data processing activities
Limitations
Note that blockchain and IPFS data cannot be deleted due to their immutable nature.
7. Cookies and Tracking
We use cookies and similar technologies for:
- Essential platform functionality
- User authentication and session management
- Analytics and performance monitoring
- Personalized user experience
You can control cookie settings through your browser preferences.
8. Third-Party Services
Our platform integrates with third-party services that have their own privacy policies:
- MetaMask and other Web3 wallets
- Polygon blockchain network
- IPFS storage network
- Vercel hosting platform
- MongoDB cloud database
- Analytics and monitoring tools
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:
- Compliance with applicable data protection laws
- Contractual protections with service providers
- Security measures equivalent to your home jurisdiction
10. Children's Privacy
Bug3 is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information promptly.
11. Data Retention
We retain information for as long as necessary to:
- Provide platform services
- Comply with legal obligations
- Resolve disputes and enforce agreements
- Maintain security and prevent fraud
Blockchain and IPFS data is permanently stored and cannot be deleted.
12. Changes to This Policy
We may update this Privacy Policy periodically. Significant changes will be communicated through:
- Platform notifications
- Email announcements
- Website banners
Continued use of the platform constitutes acceptance of updated policies.
13. Contact Us
For privacy-related questions or requests:
- Email: privacy@bug3.io
- Data Protection Officer: dpo@bug3.io
- Platform: Privacy settings in user dashboard
- Mail: Bug3 Privacy Team, [Physical Address]