Last updated: 2026-08-08
Privacy Policy
Buglyst is owned and operated by HARSH SRIVASTAVA.
What we collect
- Public-practice session data — a browser identifier, opened labs, workspace activity, check runs, submissions, timing, and completion state.
- Account and authentication data — name, email, provider identifier, and profile details supplied by a configured OAuth provider such as GitHub or Google.
- Challenge progress — which challenges you have opened, how many times you ran checks, and whether you submitted a solution.
- Submission and check results — pass/fail outcomes and timing information for visible and hidden validation checks.
- Learner and Pro data — profiles, plan status, saved workspace history, evidence reports, exports, notes, and recommendations used to provide features you request.
- Hiring data — recruiter and employer account details, organization membership, assessments, invitations, candidate consent, recorded assessment activity, reviewer notes, audit history, and candidate reports. Candidate reports are shared with the hiring organization that issued the assessment.
- Payment data — order, payment, entitlement, refund, and reconciliation identifiers. Cashfree processes payment credentials; Buglyst does not store complete card or bank credentials.
- Messages and requests — information you provide through pilot, waitlist, feedback, support, privacy, or security forms.
- Device and browser signals — Buglyst uses device and browser signals from Fingerprint for security, abuse prevention, and aggregate product analytics. This processing is optional and fail-open: if the service is blocked or unavailable, Buglyst continues to work normally. When you are signed in, a Fingerprint visitor identifier may be linked to your Buglyst account for first-party activity continuity; Buglyst does not infer that two people are the same person from a shared IP address, incognito mode, or device similarity alone.
- Operational and security data — IP address, user agent, request path, timestamps, rate-limit events, and service diagnostics. When configured, we use Microsoft Clarity for product analytics and private Telegram operator alerts for important account or product events. Operational alerts may include best-effort network or location context derived from an IP address; unavailable fields remain unavailable.
Code execution and private-code pilots
Buglyst runs checks in a controlled server-side environment. Workspace files are sent to Buglyst infrastructure and, when managed execution is enabled, to the configured managed sandbox provider (currently supported through E2B) to run challenge-defined validation commands and return results. Public workspaces are for Buglyst-provided practice content; do not paste private or proprietary code into them.
A private GitHub or private-code workflow is separate from public practice. It is available only through an approved, controlled pilot when enabled, with repository, commit, and path scope confirmed by the hiring organization. Approved custom or private assessment generation may send the authorized scope and requirements to an AI provider solely to produce a reviewable draft. Private-code generation is not public self-serve.
Accounts and service providers
Public practice can be used without account registration. Some features, including paid Pro, profiles, Hiring, billing, candidate access, and report flows, require sign-in. We use service providers for OAuth authentication, hosting, database and storage, managed sandbox execution, payments through Cashfree, email delivery, analytics, and operational alerts. They process data only as needed to provide those services or meet legal and security obligations. We do not sell personal data or serve behavioural advertising.
Data retention
Retention depends on the product surface. Free public-practice workspaces have a 24-hour active window. Pro workspace history can remain available for up to 30 days while the pass is active; evidence reports already earned may remain readable after expiry. Account progress is retained to provide profiles and history until deletion is requested or it is no longer needed.
Hiring organizations, candidate reports, consent records, reviewer notes, and audit logs are retained while needed to provide the assessment, support the organization, resolve disputes, or meet security and legal obligations. Private-repository snapshots and generated drafts follow the retention and deletion scope agreed for the approved pilot. Payment records may be retained for reconciliation, tax, fraud, refund, and legal requirements. Support, pilot, waitlist, and feedback submissions remain until fulfilled, closed, or deletion is requested, subject to required records.
Your rights
You may request deletion of any data associated with your session or email address by contacting us at privacy@buglyst.com. Include the account email, organization, session identifier, or report context needed to locate the record. We will verify the request and respond within 30 days; some billing, security, or legal records may need to be retained for a limited period.
Changes to this policy
We may update this policy as the product evolves. Material changes will be announced on the site. Continued use after a change constitutes acceptance.
← Back to Buglyst · Contact Us · Terms of Service · Security