Updated: 26 August 2026
This page lists what Bugzio stores in your browser and why. Analytics is only loaded after you accept it.
1. Strictly necessary
| Name | Purpose | Lifetime |
|---|---|---|
| PHPSESSID | Session — sign-in state and selected language | Until the browser closes |
| XSRF-TOKEN | CSRF protection in the panel | Session |
These are technically required — sign-in and form submission do not work without them, so no consent is needed.
2. Browser local storage
| Key | Purpose |
|---|---|
| bz_consent | Your choice in the cookie bar (granted / denied) |
| bz_lab_theme | Panel light/dark theme |
These stay on your device and are never sent to the server.
3. Analytics (consent only)
If you accept, we use Google Analytics 4 to see which pages are useful. There are two separate properties: one for this website (bugzio.com) and one for the panel (app.bugzio.com). They are different domains, so consent is asked for on each one separately — accepting on one does not carry to the other.
Until then gtag runs in Consent Mode v2 with analytics_storage denied, so no analytics cookie is written. After consent the _ga and _ga_* cookies are set (up to 24 months). IP addresses are anonymised.
You can withdraw consent by clearing site data in your browser or deleting the bz_consent entry — separately on each domain.
4. No third-party content
The website loads no ad networks, social plugins or external fonts — the Inter typeface is served from our own server, so no requests go to third-party domains (except analytics, if you accepted it).
5. The widget on your site
The Bugzio bug-reporting widget you embed on your own site sets no cookies in the visitor’s browser. It does write to the browser itself: a flag so a survey is shown once per visitor, and, while a screen recording is running, the recording chunks are held in the browser’s own database (IndexedDB). Console and network interceptors are installed the moment the script loads, which is how a report can include what happened before the widget was opened.
Nothing reaches a Bugzio server until the visitor presses send. One exception is worth knowing about: if session replay is switched on for your project, the widget loads the recording library from the public CDN cdn.jsdelivr.net, so that one request does leave the visitor's browser to a third party.
Questions? Write to [email protected].