No cookies · No storage · Nothing before Send

The feedback button that files the issue for you

One script tag puts a quiet tab on the edge of your site. What a visitor writes arrives in GitHub or Jira as a structured issue — severity in the title, page and browser in the body, screenshot if they asked for one. Mark it resolved and they hear back.

Works on any site — plain HTML, Next.js, WordPress, Shopify. Nothing to install beyond the tag. Installation guide

one report, end to endlive
An illustration of a single report moving through BugLoop, from the visitor pressing the feedback tab to the reporter being emailed when it is fixed.
  1. a visitor presses the feedback tab

    type
    Something is broken
    severity
    S4 · Blocks me
    summary
    Checkout button does nothing
    attached
    screenshot — masked, previewed, confirmed
  2. POST /api/v1/feedback

    page
    /checkout
    title
    Checkout — your storefront
    viewport
    390x844
    browser
    Mobile Safari 17.5
  3. filed in github.com/your-org/storefront

    issue
    [Something is broken · S4] Checkout button does nothing
    labels
    bug, from-widget
    exactly
    once — idempotency key, retries included
  4. you mark it resolved

    email
    sent to the reporter — they asked to be told
9.2 kB

gzipped, deferred

Measured on every build against a 12 kB budget that fails it. The screenshot library is a second file, fetched only when someone presses the button.

1

request on page load

The widget fetches its own configuration and then waits. Nothing else leaves the browser until a person presses Send.

0

cookies, storage writes, trackers

No cookie, no localStorage, no sessionStorage, no beacon. Adding BugLoop does not change what your privacy policy has to disclose about passive tracking.

Six steps, and you only do the first one once

Paste the script tag. Everything after that happens without a person in the middle — right through to the reporter being told it is fixed.

  1. 01

    A visitor presses the tab

    No account, no navigating away, no contact page to find. The form opens inside a Shadow DOM, so your stylesheet and its stylesheet never meet.

  2. 02

    They pick a type and a severity

    Eight feedback types — bug, design, copy, content, performance, idea, question, other — and a 1-to-5 severity from Cosmetic to Critical. Both optional, because a required field is a reason to abandon a report half-written.

  3. 03

    They type it, dictate it, or show you

    Dictation puts a microphone on the description field, and is off unless you turn it on. The screenshot button takes one still frame of the page they are on, with every form field blanked, and shows it to them before it is attached.

  4. 04

    Context is attached on submit

    Page URL, page title, viewport size and user agent travel with the report. All of it is read at the moment Send is pressed — there is no phase before that in which the widget is watching.

  5. 05

    It becomes an issue — exactly once

    A GitHub issue or Jira ticket titled "[Something is broken · S4] Checkout button does nothing", with the description, your custom fields and the context block in the body, and your labels and assignees applied. A deterministic key with a unique index behind it means a retry after a timeout cannot file a second one.

  6. 06

    You resolve it, and the reporter is told

    If they left an email address and ticked "email me when this is fixed", marking the report resolved sends them a message saying so. That is the loop the product is named after, and it is the step most feedback tools never close.

The longer version, field by field →

The part that is hard to bolt on later

Most feedback widgets arrive attached to an analytics suite. You wanted the button; you also got a recorder on every page, a consent obligation, a masking policy that has to hold for every second of every session, and a store of behavioural data to secure.

BugLoop is the button on its own. The list below is not a roadmap of things not built yet — it is the product decision, and it is why this can go on a client site without a privacy conversation first.

  • No session recording
  • No heatmaps
  • No click, scroll or mouse tracking
  • No cookies
  • No localStorage or sessionStorage
  • No fingerprinting
  • No beacon, and nothing sent on page load
  • No raw IP addresses stored — a salted hash, for rate limiting
  • Nothing observed at all before Send is pressed

Dictation hands audio to the browser

It is off unless you switch it on for a project. When it is on, the microphone button uses the browser’s own Web Speech API — and in Chrome, that API streams the captured audio to Google for transcription. The widget says so the first time the button is pressed. Leave dictation off and the widget talks to nobody but BugLoop.

A screenshot re-reads what the page already shows

Drawing your page into an image means re-reading the images, stylesheets and webfonts it is already displaying, including any hosted elsewhere. Those are the same requests your page has already made, forced to carry no cookies and no referrer, so nothing about the visitor is disclosed that the asset host did not already have. It happens once, on a deliberate press, on a page the reporter is looking at.

Both happen only on a deliberate press. How screenshots work · Privacy and data

Reports land where the work already is

Feedback in a separate tool gets triaged twice. BugLoop files into the tracker your team opens every morning — and if the destination is down, the visitor still gets their confirmation and the delivery is retryable from the report.

Built for the moment something is wrong

Free while it is early access

There is no billing wired up, no plan tiers, and nobody is being charged. Everything the product currently does is available with no payment details and no trial clock.

The limits that apply are technical rather than commercial: 120 submissions per project per hour and 8 per submitter every 10 minutes, which exist to stop a flood reaching your issue tracker rather than to shape a tier.

What happens when paid plans arrive →

Early access

Free

  • Unlimited projects, each with its own origins, theme and destination
  • Opt-in screenshots and optional dictation, both off until you turn them on
  • Custom fields — text, long text, dropdown, checkbox, email, URL, number
  • GitHub Issues and Jira Cloud, with delivery retry when a destination is down
  • No session recording, no cookies, no behavioural tracking — ever, on any plan
Create an account

Common questions

How is BugLoop different from a full analytics suite?
BugLoop does one job: collect a report and route it to your issue tracker. It has no session recording, no heatmaps, and no behavioural tracking, so it sets no cookies and collects nothing passively — there is no phase in which it is watching.
What does the visitor report actually contain?
What the visitor wrote — type, severity from 1 to 5, summary, description, and any custom fields you configured — plus the page URL, page title, viewport size, and browser user agent captured automatically. If they pressed the screenshot button and confirmed the preview, the image comes too.
Does it take a screenshot?
Only when a reporter presses the button, and only of the page they are on. Every input and textarea is blanked and anything you marked with data-bugloop-mask is left undrawn before the image is rendered, and the reporter sees the result and confirms it before it is attached. There is no screen-sharing prompt, so it can never see another tab or anything else on their desktop.
Does the reporter ever hear back?
If they left an email address and ticked the opt-in box, yes. Marking their report resolved in the dashboard emails them to say it is fixed, once, with the title they wrote and the page they wrote it from. If they did not opt in, nothing is sent and no address is asked for.
Does it need a cookie banner?
The widget sets no cookies and writes nothing to the visitor's device, so it does not itself trigger consent requirements. Confirm your own obligations with your counsel.
Is it true that the widget makes no third-party requests?
Almost, and the two exceptions are both on a deliberate press. Dictation puts a microphone button on the description field using the browser's speech API, and in Chrome that API sends the audio to Google; it is off unless you turn it on for a project. Attaching a screenshot re-reads the images, stylesheets and fonts your page already displays, wherever they are hosted, with cookies and referrer stripped. Nothing else in the widget talks to anyone but BugLoop.
What credential does the GitHub integration need?
A fine-grained personal access token scoped to a single repository with the Issues permission set to Read and write. It cannot read your source or push code.
How big is the script?
The always-on entry is 9.2 kB gzipped, loaded deferred, making one request on page load. The screenshot library is a separate file fetched only when someone presses the button, so a visitor who never does downloads nothing extra. The build measures both on every run and fails if either exceeds its budget.

Put it on a page and send yourself a report

Paste the tag, open the site, press the tab. The round trip from a visitor pressing a button to an issue in your tracker takes about as long as reading this sentence.

index.html

<script
  src="https://bugloop.ai/w.js"
  data-bugloop-key="bl_pk_your_project_key"
  defer
></script>