Privacy Policy

Last updated: August 1, 2025

1. Introduction

Bug3 ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our decentralized bug bounty platform.

2. Information We Collect

Blockchain Data (Public)

  • Wallet addresses and transaction hashes
  • Smart contract interactions and events
  • Voting records and token balances
  • Bug report metadata stored on IPFS

Platform Data (Private)

  • Profile information (username, bio, contact details)
  • Project descriptions and bounty details
  • Bug report content and attachments
  • Communication between users
  • Usage analytics and platform interactions

Technical Data

  • IP addresses and browser information
  • Device identifiers and operating systems
  • Cookies and local storage data
  • Error logs and performance metrics

3. How We Use Your Information

We use collected information for:

  • Platform functionality and user authentication
  • Processing bounty submissions and payments
  • Community voting and validation processes
  • Customer support and communication
  • Platform analytics and improvement
  • Security monitoring and fraud prevention
  • Legal compliance and dispute resolution

4. Information Sharing and Disclosure

Public Information

The following information is publicly available on the blockchain and IPFS:

  • Wallet addresses and transaction history
  • Bug report summaries and validation status
  • Voting records and community decisions
  • Bounty details and payout information

Limited Sharing

We may share private information with:

  • Project owners (for relevant bug reports)
  • Service providers (hosting, analytics, support)
  • Legal authorities (when required by law)
  • Business partners (with explicit consent)

No Selling

We do not sell, trade, or rent your personal information to third parties.

5. Data Storage and Security

Storage Locations

  • Blockchain: Polygon network (immutable, public)
  • IPFS: Distributed storage (immutable, content-addressed)
  • MongoDB: Off-chain analytics (encrypted, access-controlled)
  • Vercel: Platform hosting (secure cloud infrastructure)

Security Measures

  • End-to-end encryption for sensitive communications
  • Multi-signature wallet security for platform funds
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Secure coding practices and vulnerability monitoring

6. User Rights and Control

Your Rights

  • Access: Request copies of your personal data
  • Correction: Update inaccurate or incomplete information
  • Deletion: Request removal of personal data (where legally possible)
  • Portability: Export your data in standard formats
  • Objection: Opt-out of certain data processing activities

Limitations

Note that blockchain and IPFS data cannot be deleted due to their immutable nature.

7. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential platform functionality
  • User authentication and session management
  • Analytics and performance monitoring
  • Personalized user experience

You can control cookie settings through your browser preferences.

8. Third-Party Services

Our platform integrates with third-party services that have their own privacy policies:

  • MetaMask and other Web3 wallets
  • Polygon blockchain network
  • IPFS storage network
  • Vercel hosting platform
  • MongoDB cloud database
  • Analytics and monitoring tools

9. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Compliance with applicable data protection laws
  • Contractual protections with service providers
  • Security measures equivalent to your home jurisdiction

10. Children's Privacy

Bug3 is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information promptly.

11. Data Retention

We retain information for as long as necessary to:

  • Provide platform services
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain security and prevent fraud

Blockchain and IPFS data is permanently stored and cannot be deleted.

12. Changes to This Policy

We may update this Privacy Policy periodically. Significant changes will be communicated through:

  • Platform notifications
  • Email announcements
  • Website banners

Continued use of the platform constitutes acceptance of updated policies.

13. Contact Us

For privacy-related questions or requests:

  • Email: privacy@bug3.io
  • Data Protection Officer: dpo@bug3.io
  • Platform: Privacy settings in user dashboard
  • Mail: Bug3 Privacy Team, [Physical Address]