A bug-reporting tool that records nothing until your customer hits the button. Ninety-second consent-gated reports, redacted in their browser, sent only when they click Send.
// the trigger bottom-right of this page is real. click it.
What we don't do
Session-replay vendors sell you on what they capture. We open with what we won't, because the data you don't collect is the data you can't lose, leak, or be subpoenaed for.
The SDK is dormant. Nothing records, beacons, or pings until your user clicks the trigger. An auditable boundary, not a 'we promise.'
Sensitive patterns are masked in your customer's browser before upload. The raw data never crosses the network. Not even to us.
Replay + audio: architecturally invisible to us. The metadata we DO see to operate the product (page URL, console, network paths) is governed by contract — no training, no sale, no third parties.
No analytics, no telemetry, no anonymized usage tracking. A pixel from us means a pixel from someone we can't audit on your behalf.
Not because we don't want healthcare customers. BAAs require operational discipline we haven't built yet. Out of ICP, on purpose.
Our admin panel hard-rejects requests for blob content. Every attempt is logged to your audit trail — visible to you, not just to us.
Yes — this means you miss the bugs no one bothered to file. That's the trade. How we compare to LogRocket & FullStory →
What makes it different
BugJar sits dormant on your page. When a user clicks the trigger, it records what they choose to share, and scrubs sensitive patterns before any byte leaves their browser.
Nothing records, beacons, or pings until your user clicks the bug-report button. For solo devs and small teams shipping to privacy-sensitive customers — fintech, legal, HR, anywhere PII in a bug report would be a problem.
rrweb input masks, regex scrubbing of 17 sensitive categories, and strict-mode "mask all text". All applied client-side before upload.
Recordings PUT straight to Cloudflare R2 via presigned URLs. Our Laravel server never sees blob content. Admin can't view it either.
Hard-to-reproduce bug? Send a one-time signed link. The customer opens it in their own session, records on demand, and the link expires after use. Fully audited. No SDK install on your customer's side, no lingering access.
Install
Drop into the <head> of any page where you want bug reporting available.
<script> window.addEventListener('bugjar:ready', () => { BugJar.init({ /* your config + hooks */ }); }); </script> <script src="https://console.bugjar.app/sdk/proj_live_yourkey.js" type="module" async></script> // That's it. The trigger button mounts itself bottom-right. // Redaction + URL allowlist + verification mode come from your // BugJar dashboard — change a setting, refresh the page.
Dormant until consent
SDK is mounted but captures nothing — no DOM events, no microphone, no network beacons — until your user clicks Record.
No analytics beacons
SDK talks to your BugJar dashboard for config + presigned URLs; submitted blobs upload direct to Cloudflare R2. No analytics pings, no third-party telemetry, no shadow network.
Typed
Ships TypeScript types. Customer DX is part of the product.
Privacy by design
Recordings upload directly to Cloudflare R2 via presigned URLs. Our backend never touches blob content. Report metadata (page URL, console logs, network entries) is stored for your dashboard. Even our own admin panel can't pull a recording — the endpoint that would issue the URL hard-rejects admin sessions, and every attempt is logged to your audit trail.
Pricing
Or skip the subscription. $15 buys a 50-report credit pack you can use over the next year.
See pricing and plansIt's wired to a sandbox project. Click it, record yourself for 30 seconds, send — then sign up to see exactly what landed on the other side.