SnapBug Privacy Policy
Last updated: July 26, 2026 | Effective: July 26, 2026
> This is a translation of the Korean original. The Korean version at > docs/legal/ko/privacy_policy.md is the authoritative text. If a translation > differs in meaning, the Korean version controls.
SnapBug, made by the solo developer kukuDev ("the operator"), is a mobile bug-report writing tool for AI coding agents. It writes your bug description and device details directly into a screenshot so you can hand a single picture to an AI coding agent.
The app has no sign-up and no login, and core data such as report text, annotations, and device details is stored only on your device. This policy explains what the app processes, what it does not, and how the app treats the original files in your gallery. By using the app you agree to this policy.
1. Information We Process and Why
The app does not create accounts and does not collect personally identifying information such as your name, email address, or phone number.
1.1. Information kept on your device and never transmitted
The following is stored only on your device and is not sent to the operator's servers.
| Item | Where it is stored |
|---|---|
| Report body (problem description), title, type, severity, status, tags | App database |
| Project names and settings | App database |
| Screenshot annotations (coordinates for pen, rectangle, arrow, and so on) | App database |
| Device context: device model, OS version, screen size and orientation, network connection type, battery level, language setting, capture time | App database (attached to the report) |
| Reduced thumbnails of detected screenshots (512 px on the long side) | App-private storage |
| App settings (theme, language, watching on/off, guide history) | App preference storage |
Device context is collected to fill in the environment details needed to reproduce a bug, and it stays inside the report. The app does not collect location data, contacts, call logs, or address books.
1.2. Information processed automatically to run the service
| Item processed | Processor | Purpose |
|---|---|---|
| Advertising identifier (Ad ID) | Google AdMob | Showing banner and native ads and measuring performance |
| Diagnostic and crash logs (error details, time of occurrence, device and OS information) | Google Firebase Crashlytics | Diagnosing and improving app stability |
| Anonymous usage statistics (app and OS version, device model and language, screen views, feature usage events, session information) | Google Firebase Analytics | Improving features and analysing usability. Report contents, screenshots and raw device context are not included |
| App integrity verification tokens | Google Firebase App Check, Google Play Integrity | Blocking tampered app builds from server features |
| Purchase token and product ID | Google Play, the operator's verification server (Firebase Cloud Functions) | Verifying and restoring the ad-removal in-app purchase |
| App version lookup request | Google Play store page | Update notice |
1.3. Voice input (important)
The app lets you describe a bug by speaking. This feature uses the Android operating system's speech recognition service, and the audio recorded while you hold the microphone button may be sent off your device (for example, to Google's speech recognition servers) for transcription. Whether and how this happens depends on your device manufacturer, OS version, and system settings, and it is not under the operator's control.
The operator does not collect or retain voice data. The app receives only the transcribed text, which is stored on your device as the report body. If you prefer not to use voice input, do not grant the microphone permission and type instead.
2. How the App Treats Original Screenshots in Your Gallery (important)
Instead of keeping its own copies, the app references the original files in your gallery directly. Because of this design, the app performs two operations on those files.
2.1. It writes report information into the original file. When you save a report or edit a note, the app writes the description, type, severity, and device context into the metadata area of that screenshot file (an iTXt chunk for PNG, an XMP packet for JPEG). The visible content of the photo (its pixels) does not change; the file grows slightly. This record is what lets an AI coding agent read the report from the picture alone.
2.2. Deleting a report moves the original to the system trash. When you delete a report, the app first asks whether to move the corresponding screenshot to the Android system trash. On Android 11 and later you can restore it yourself from your Gallery or Photos app trash within 30 days.
Both operations go through the permission approval flow that Android requires. If you have not granted the "Manage Media" permission (which you can turn on yourself in settings), a system confirmation dialog appears each time, and if you decline, the original is left unchanged. Even then the report itself is saved normally inside the app, and the information is re-embedded into a temporary file at export time, so what you hand over is the same.
3. Sharing and Disclosure
The operator shares information with the third parties below only as needed to run the service, and never transmits report bodies, annotations, or device context anywhere.
- Google AdMob: processing the advertising identifier and serving banner and native ads
- Google Firebase (Analytics, Crashlytics, App Check, Cloud Functions): processing crash logs, verifying app integrity, running purchase receipt verification
- Google Play: processing in-app purchases and verifying receipts
Beyond this, information may be transferred where required by law, where necessary to protect the operator's rights or safety, or in connection with a business transfer such as a merger or acquisition.
3.1. When you export a report yourself
When you use the export feature, an image file containing the report information is handed to an app you choose (a messenger, a file app, a cloud drive, an AI coding tool, and so on). That transfer is an action you direct, and handling after the transfer is governed by that app's or service's privacy policy. The operator is not involved and keeps no copy.
The exported image contains your report body and device context as metadata. Please keep this in mind when choosing where to share it.
4. Storage and Retention
Report data is stored in a database in app-private storage, inside the Android app sandbox where other apps cannot reach it. No separate database encryption is applied — the app relies on operating system app isolation and device lock-screen encryption. On a rooted or unlocked device, that protection is weaker.
Detected screenshots are left in your gallery as originals; only reduced thumbnails are cached in app storage. Deleting the app removes the report data and thumbnail cache, and the original screenshots in your gallery remain.
The app has no in-app trash, so deleting a report is immediate and permanent (the original screenshot moves to the system trash as described in 2.2). The operator does not retain reports, so there is no server-side retention period for them. Crash logs and purchase verification records are retained according to the policies of the respective services (Google Firebase, Google Play).
5. Security
External communication is encrypted with TLS/HTTPS, and server features such as purchase verification block abnormal requests using App Check. The ad-removal entitlement is stored in the operating system's secure storage (backed by the Android Keystore). Release builds are code-obfuscated. That said, no method of transmission over the internet can be guaranteed to be completely secure.
6. App Permissions
| Permission | Purpose | Required? |
|---|---|---|
| Photos and videos (photo access) | Checking whether a new screenshot was added; reading the original image of a report and writing metadata into it | Required for automatic screenshot detection |
| Notifications | Screenshot detection alerts and watching status | Required for detection alerts |
| Microphone | Only while you hold the button to describe a bug by voice | Optional |
| Manage media | Avoids a system confirmation dialog each time you save or delete | Optional (you turn it on yourself in settings) |
| Background execution (foreground service) | Keeps watching alive so screenshots are not missed while the screen is off | Needed for always-on watching |
| Ignore battery optimization | Prevents manufacturer power-saving policies from stopping the watch | Optional (recommended) |
| Receive boot completed | Restarts always-on watching after a reboot | Optional (can be turned off in settings) |
| Internet | Showing ads, sending crash logs, verifying purchases | Required |
The app does not record your screen. Always-on watching only checks whether a new image was added.
7. Your Rights
- Delete reports: You can delete one or many reports in the app; the app asks whether to move the original screenshots to the system trash.
- Restore originals: Originals in the system trash can be brought back from the "Restore" button on the report detail screen or from your gallery app.
- Refuse changes to originals: If you decline the system confirmation dialog, the gallery original is not modified. You can turn the "Manage Media" permission off at any time in settings.
- Advertising identifier: You can reset it or opt out of personalized ads in your device settings.
- Withdraw permissions: Photo, notification, and microphone permissions can be withdrawn at any time in Android settings.
- Delete everything: Uninstalling the app deletes all data the app kept.
The app has no accounts, so there is no separate account-closure procedure.
8. Children's Privacy
The app is intended for developers and testers and is not directed to children under 14. The operator does not knowingly collect personal information from children under 14.
9. International Data Transfers
Google (AdMob, Firebase, Play) and the operating system's speech recognition service may process data on servers outside your country. By agreeing to this policy and using the app, you are deemed to consent to those transfers. The operator takes reasonably necessary steps to see that data is handled securely.
10. Privacy Officer and Remedies
Please direct questions, complaints, and requests for remedy regarding the handling of personal information to the address below. The operator responds promptly and in good faith.
- Privacy officer: kukuDev operator
- Contact:
Users in Korea may also contact the following bodies to report or seek advice about privacy infringement:
- Privacy Infringement Report Center (KISA): privacy.kisa.or.kr / 118
- Personal Information Dispute Mediation Committee: www.kopico.go.kr / 1833-6972
- Supreme Prosecutors' Office Cyber Investigation Division: www.spo.go.kr / 1301
- National Police Agency Cyber Bureau: ecrm.police.go.kr / 182
11. Changes to This Policy
The operator may update this policy from time to time. For significant changes, notice will be given at least 30 days before the change takes effect, through an in-app notice or a similar method. Please check the "Last updated" date at the top periodically. If you need an earlier version, request it at the contact address below.
12. Contact
For questions about this privacy policy, please contact: