REC · IDLE

See the bug.
Not the user.

A bug-reporting tool that records nothing until your customer hits the button. Ninety-second consent-gated reports, redacted in their browser, sent only when they click Send.

// the trigger bottom-right of this page is real. click it.

What we don't do

Most of this product is what we refused to ship.

Session-replay vendors sell you on what they capture. We open with what we won't, because the data you don't collect is the data you can't lose, leak, or be subpoenaed for.

×

No always-on capture.

The SDK is dormant. Nothing records, beacons, or pings until your user clicks the trigger. An auditable boundary, not a 'we promise.'

×

No server-side redaction.

Sensitive patterns are masked in your customer's browser before upload. The raw data never crosses the network. Not even to us.

×

No AI training on your reports.

Replay + audio: architecturally invisible to us. The metadata we DO see to operate the product (page URL, console, network paths) is governed by contract — no training, no sale, no third parties.

×

No third-party pixels.

No analytics, no telemetry, no anonymized usage tracking. A pixel from us means a pixel from someone we can't audit on your behalf.

×

No HIPAA / healthcare workloads.

Not because we don't want healthcare customers. BAAs require operational discipline we haven't built yet. Out of ICP, on purpose.

×

No admin access to your reports.

Our admin panel hard-rejects requests for blob content. Every attempt is logged to your audit trail — visible to you, not just to us.

Yes — this means you miss the bugs no one bothered to file. That's the trade. How we compare to LogRocket & FullStory →

What makes it different

One snippet. Three layers of redaction.

BugJar sits dormant on your page. When a user clicks the trigger, it records what they choose to share, and scrubs sensitive patterns before any byte leaves their browser.

01

Consent-gated capture

Nothing records, beacons, or pings until your user clicks the bug-report button. For solo devs and small teams shipping to privacy-sensitive customers — fintech, legal, HR, anywhere PII in a bug report would be a problem.

02

Three-layer redaction

rrweb input masks, regex scrubbing of 17 sensitive categories, and strict-mode "mask all text". All applied client-side before upload.

03

Direct-to-storage uploads

Recordings PUT straight to Cloudflare R2 via presigned URLs. Our Laravel server never sees blob content. Admin can't view it either.

04

Invite-driven capture

Hard-to-reproduce bug? Send a one-time signed link. The customer opens it in their own session, records on demand, and the link expires after use. Fully audited. No SDK install on your customer's side, no lingering access.

Install

Two tags. No build step.

Drop into the <head> of any page where you want bug reporting available.

<script>
  window.addEventListener('bugjar:ready', () => {
    BugJar.init({ /* your config + hooks */ });
  });
</script>
<script src="https://console.bugjar.app/sdk/proj_live_yourkey.js" type="module" async></script>
// That's it. The trigger button mounts itself bottom-right.
// Redaction + URL allowlist + verification mode come from your
// BugJar dashboard — change a setting, refresh the page.

Dormant until consent

SDK is mounted but captures nothing — no DOM events, no microphone, no network beacons — until your user clicks Record.

No analytics beacons

SDK talks to your BugJar dashboard for config + presigned URLs; submitted blobs upload direct to Cloudflare R2. No analytics pings, no third-party telemetry, no shadow network.

Typed

Ships TypeScript types. Customer DX is part of the product.

Privacy by design

Replay video and audio never pass through our servers.

Recordings upload directly to Cloudflare R2 via presigned URLs. Our backend never touches blob content. Report metadata (page URL, console logs, network entries) is stored for your dashboard. Even our own admin panel can't pull a recording — the endpoint that would issue the URL hard-rejects admin sessions, and every attempt is logged to your audit trail.

Consent-first
No analytics cookies
Deletion + export built in
Read the privacy model →

Pricing

Free for solo. $9 Solo. $39 Team.

Or skip the subscription. $15 buys a 50-report credit pack you can use over the next year.

See pricing and plans
Try the trigger on this page

The button bottom-right is a real BugJar trigger.

It's wired to a sandbox project. Click it, record yourself for 30 seconds, send — then sign up to see exactly what landed on the other side.