SnapBug Privacy Policy
Last updated: October 20, 2026 | Effective: October 20, 2026
This is a translation of the Korean original. The Korean version is the authoritative text. If a translation differs in meaning, the Korean version controls.
SnapBug, made by the solo developer kukuDev ("the operator"), is a mobile bug-report writing tool for AI coding agents. It writes your bug description and device details directly into a screenshot so you can hand a single picture to an AI coding agent.
The app has no sign-up and no login, and core data such as report text, annotations, and device details is stored only on your device. This policy explains what the app processes, what it does not, and how the app treats the original files in your gallery. By using the app you agree to this policy.
Ad mediation, bidding and international transfers
We are adding Liftoff Monetize, AppLovin and Unity Ads through Google AdMob mediation and bidding. Multiple participating providers may process information to bid and select an ad when an ad is requested; processing is not limited to the provider whose ad is displayed. This section supplements the advertising data collection, sharing, retention and international transfer provisions of this policy.
Providers by ad format
| Ad format | Participating providers |
|---|---|
| Banner | Google AdMob + Liftoff Monetize + Unity Ads |
| Interstitial | Google AdMob + Liftoff Monetize + AppLovin + Unity Ads |
| App open | Google AdMob + Liftoff Monetize + AppLovin |
| Native | Google AdMob + Liftoff Monetize + AppLovin |
| Rewarded | Google AdMob + Liftoff Monetize + AppLovin + Unity Ads |
This applies only to ad formats actually offered in each app. Not every app displays every format. Availability of each provider depends on app version, region, consent, configuration and account approval. Processing by new partners starts only after the effective date and completion of required consent procedures.
Advertising information processed
SDKs may process advertising IDs and app or device identifiers; IP address and approximate location inferred from it (country or region); device model, OS, language, network and display characteristics; app identifier, version, installation and session information; ad requests, bids, impressions, clicks, views, rewards and conversion events; consent and advertising privacy preferences; and fraud prevention signals. The actual fields depend on the provider, SDK, platform and consent settings.
Advertising and analytics purposes
Information is used to deliver, select and bid for ads; provide personalized or non-personalized ads where permitted; manage ad frequency; measure ad performance and revenue and produce statistics; prevent invalid clicks and fraud; and improve advertising service quality. Advertising analytics are separate from the existing Firebase Analytics app usability analysis. Existing purposes for other app data remain unchanged.
Providers, privacy policies and international transfers
The advertising information described above may be sent over the network to the relevant providers during SDK initialization, ad requests, bidding and ad interactions, and processed outside South Korea. The transferred data and purposes are described above. The countries below are locations disclosed by the providers, not a guarantee of the server used for each request. Any legally required consent or other transfer requirements must be met first; reading this policy or continuing to use the app does not replace required consent.
| Participating providers | Disclosed processing countries | Retention | Contact and privacy rights |
|---|---|---|---|
| Google AdMob (Google LLC) | United States and global server locations disclosed by Google | Google's service-specific retention and deletion policies | Contact and privacy rights |
| Liftoff Monetize (Liftoff Mobile, Inc.; LMI, Inc.; Vungle SEA Pte. Ltd.) | United States, Singapore, Japan and Germany (primary data centers) | Its published policy provides for 30 days in the active database in pseudonymized form for end-user information; backups are retained indefinitely | Contact and privacy rights |
| AppLovin Corporation | United States; consult the provider's policy or contact channel for additional locations | Typically up to two years; device information may be kept for less time or until a deletion request, subject to legal and dispute-related exceptions | Contact and privacy rights |
| Unity Ads (Unity Technologies S.F.) | United States and disclosed affiliate or service provider locations, including Israel, Canada, Japan, New Zealand, Switzerland and the United Kingdom | As necessary for service purposes, with possible extensions for legal obligations, fraud prevention and disputes | Contact and privacy rights |
Your choices and questions
You can use device advertising settings to delete or reset the advertising ID or restrict personalized advertising, and change consent through advertising privacy options where offered in the app (availability varies by region). Opting out of personalization does not stop all advertising data processing. Contact [email protected] or the providers' privacy contacts below to request access, deletion, restriction or refusal of international transfers. Refusing required consent restricts the relevant processing and may make related ad or reward features unavailable. If you do not agree with this amendment, you may stop using the app before it takes effect.
1. Information We Process and Why
The app does not create accounts and does not collect personally identifying information such as your name, email address, or phone number.
1.1. Information kept on your device and never transmitted
The following is stored only on your device and is not sent to the operator's servers.
| Item | Where it is stored |
|---|---|
| Report body (problem description), title, type, severity, status, tags | App database |
| Project names and settings | App database |
| Screenshot annotations (coordinates for pen, rectangle, arrow, and so on) | App database |
| Device context: device model, OS version, screen size and orientation, network connection type, battery level, language setting, capture time | App database (attached to the report) |
| Reduced thumbnails of detected screenshots (512 px on the long side) | App-private storage |
| App settings (theme, language, watching on/off, guide history) | App preference storage |
Device context is collected to fill in the environment details needed to reproduce a bug, and it stays inside the report. The app does not collect location data, contacts, call logs, or address books.
1.2. Information processed automatically to run the service
| Item processed | Processor | Purpose |
|---|---|---|
| Advertising identifier (Ad ID) | Google AdMob | Showing banner and native ads and measuring performance |
| Diagnostic and crash logs (error details, time of occurrence, device and OS information) | Google Firebase Crashlytics | Diagnosing and improving app stability |
| Usage statistics (app and OS version, device model and language, screen views, feature usage events, session information, install source, app instance identifier) | Google Firebase Analytics | Improving features and analysing usability. Report contents, screenshots and raw device context are not included |
| App integrity verification tokens | Google Firebase App Check, Google Play Integrity | Blocking tampered app builds from server features |
| Purchase token and product ID | Google Play, the operator's verification server (Firebase Cloud Functions) | Verifying and restoring the ad-removal in-app purchase |
| App version lookup request | Google Play store page | Update notice |
1.3. Voice input (important)
The app lets you describe a bug by speaking. This feature uses the Android operating system's speech recognition service, and the audio recorded while you hold the microphone button may be sent off your device (for example, to Google's speech recognition servers) for transcription. Whether and how this happens depends on your device manufacturer, OS version, and system settings, and it is not under the operator's control.
The operator does not collect or retain voice data. The app receives only the transcribed text, which is stored on your device as the report body. If you prefer not to use voice input, do not grant the microphone permission and type instead.
2. How the App Treats Original Screenshots in Your Gallery (important)
Instead of keeping its own copies, the app references the original files in your gallery directly. Because of this design, the app performs two operations on those files.
2.1. It writes report information into the original file. When you save a report or edit a note, the app writes the description, type, severity, and device context into the metadata area of that screenshot file (an iTXt chunk for PNG, an XMP packet for JPEG). The visible content of the photo (its pixels) does not change; the file grows slightly. This record is what lets an AI coding agent read the report from the picture alone.
2.2. Deleting a report moves the original to the system trash. When you delete a report, the app first asks whether to move the corresponding screenshot to the Android system trash. On Android 11 and later you can restore it yourself from your Gallery or Photos app trash within 30 days.
Both operations go through the permission approval flow that Android requires. If you have not granted the "Manage Media" permission (which you can turn on yourself in settings), a system confirmation dialog appears each time, and if you decline, the original is left unchanged. Even then the report itself is saved normally inside the app, and the information is re-embedded into a temporary file at export time, so what you hand over is the same.
3. Sharing and Disclosure
The operator shares information with the third parties below only as needed to run the service, and never transmits report bodies, annotations, or device context anywhere.
- Google AdMob: processing the advertising identifier and serving banner and native ads
- Google Firebase (Analytics, Crashlytics, App Check, Cloud Functions): analysing usage statistics, processing crash logs, verifying app integrity, running purchase receipt verification
- Google Play: processing in-app purchases and verifying receipts
Beyond this, information may be transferred where required by law, where necessary to protect the operator's rights or safety, or in connection with a business transfer such as a merger or acquisition.
3.1. When you export a report yourself
When you use the export feature, an image file containing the report information is handed to an app you choose (a messenger, a file app, a cloud drive, an AI coding tool, and so on). That transfer is an action you direct, and handling after the transfer is governed by that app's or service's privacy policy. The operator is not involved and keeps no copy.
The exported image contains your report body and device context as metadata. Please keep this in mind when choosing where to share it.
4. Storage and Retention
Report data is stored in a database in app-private storage, inside the Android app sandbox where other apps cannot reach it. No separate database encryption is applied — the app relies on operating system app isolation and device lock-screen encryption. On a rooted or unlocked device, that protection is weaker.
Detected screenshots are left in your gallery as originals; only reduced thumbnails are cached in app storage. Deleting the app removes the report data and thumbnail cache, and the original screenshots in your gallery remain.
The app has no in-app trash, so deleting a report is immediate and permanent (the original screenshot moves to the system trash as described in 2.2). The operator does not retain reports, so there is no server-side retention period for them. Crash logs and purchase verification records are retained according to the policies of the respective services (Google Firebase, Google Play).
5. Security
External communication is encrypted with TLS/HTTPS, and server features such as purchase verification block abnormal requests using App Check. The ad-removal entitlement is stored in the operating system's secure storage (backed by the Android Keystore). Release builds are code-obfuscated. That said, no method of transmission over the internet can be guaranteed to be completely secure.
6. App Permissions
| Permission | Purpose | Required? |
|---|---|---|
| Photos and videos (photo access) | Checking whether a new screenshot was added; reading the original image of a report and writing metadata into it | Required for automatic screenshot detection |
| Notifications | Screenshot detection alerts and watching status | Required for detection alerts |
| Microphone | Only while you hold the button to describe a bug by voice | Optional |
| Manage media | Avoids a system confirmation dialog each time you save or delete | Optional (you turn it on yourself in settings) |
| Background execution (foreground service) | Keeps watching alive so screenshots are not missed while the screen is off | Needed for always-on watching |
| Ignore battery optimization | Prevents manufacturer power-saving policies from stopping the watch | Optional (recommended) |
| Receive boot completed | Restarts always-on watching after a reboot | Optional (can be turned off in settings) |
| Internet | Showing ads, sending crash logs, verifying purchases | Required |
The app does not record your screen. Always-on watching only checks whether a new image was added.
7. Your Rights
- Delete reports: You can delete one or many reports in the app; the app asks whether to move the original screenshots to the system trash.
- Restore originals: Originals in the system trash can be brought back from the "Restore" button on the report detail screen or from your gallery app.
- Refuse changes to originals: If you decline the system confirmation dialog, the gallery original is not modified. You can turn the "Manage Media" permission off at any time in settings.
- Advertising identifier: You can reset it or opt out of personalized ads in your device settings.
- Withdraw permissions: Photo, notification, and microphone permissions can be withdrawn at any time in Android settings.
- Delete everything: Uninstalling the app deletes all data the app kept.
The app has no accounts, so there is no separate account-closure procedure.
8. Children's Privacy
The app is intended for developers and testers and is not directed to children under 14. The operator does not knowingly collect personal information from children under 14.
9. International Data Transfers
Google (AdMob, Firebase, Play) and the operating system's speech recognition service may process data on servers outside your country. The operator takes reasonably necessary steps to see that data is handled securely.
10. Privacy Officer and Remedies
Please direct questions, complaints, and requests for remedy regarding the handling of personal information to the address below. The operator responds promptly and in good faith.
- Privacy officer: kukuDev operator
- Contact:
Users in Korea may also contact the following bodies to report or seek advice about privacy infringement:
- Privacy Infringement Report Center (KISA): privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
- National Police Agency Cyber Bureau: ecrm.police.go.kr / 182
11. Changes to This Policy
The operator may update this policy from time to time. For significant changes, notice will be given at least 30 days before the change takes effect, through an in-app notice or a similar method. Please check the "Last updated" date at the top periodically. If you need an earlier version, request it at the contact address below.
12. Contact
For questions about this privacy policy, please contact: