Privacy Policy

Last updated: August 31, 2026

Who we are

Bundle Cop ("we") provides a Next.js build adapter (bundle-cop-vercel-plugin) and a Vercel integration app hosted at bundle-cop.vercel.app.

What we collect

  • Bundle reports — module names, sizes, routes, and commit SHA metadata uploaded to private Vercel Blob when you enable the adapter and Blob token. We do not upload source maps or full source code.
  • Deployment webhooks — event payloads from Vercel (deployment IDs, project IDs, commit SHAs) needed to diff and post Checks.
  • Integration OAuth — when you connect the integration, Vercel may send install codes and configuration IDs so we can obtain scoped API access you authorize.

How we use data

Data is used only to generate bundle reports, enforce budgets, show the dashboard, and create deployment Checks or comments you enable. We do not sell personal data.

Storage & retention

Reports live in a private Vercel Blob store tied to the project. You can delete the store or revoke tokens at any time via Vercel. Local builds write bundle-report.json only on your machine or CI.

Third parties

Hosting and storage run on Vercel. Optional GitHub App features send Check Run data to GitHub under your installation. See their privacy policies for platform-level processing.

Contact

Questions: ebox.nadeem@gmail.com or open a GitHub issue.