Terms of Service
Last updated: October 1, 2026 · OhMyBug is operated by Explyt (Explicit Insights, LLC) · questions: ohmybug@explyt.com · Privacy Policy
1. What OhMyBug is
OhMyBug reviews code diffs you submit through your coding agent and returns possible bugs. Your agent checks each finding against your codebase and reports a verdict. You approve the verdicts.
2. What you pay
- $10 per review that finds real bugs: flat, no matter how many confirmed bugs that review contains.
- Minor findings (small edge cases) are never billed.
- Review runs, false positives, unclear findings: $0.
- Your first bug-finding review is free. No card required until it is used. A promo code can raise that allowance; the figure is set per code.
- New reviews stop when your credit runs out. Reviews already started can still be billed when your agent submits their verdicts, even if that pushes your balance below zero. There is no cap on this: every started review is billed once its verdicts arrive. Your agent shows the balance at each step; topping up clears a negative balance. We may suspend new reviews while the balance is negative, and the next purchase first settles that amount. A chargeback removes the disputed amount from your balance while it is open. If we win the dispute, the amount returns to your balance; if you win, your card is refunded and the credit stays removed.
- You can buy packs of 1, 10, or 25 catches. Pack credit expires 12 months after your last pack purchase. A new pack purchase extends the remaining balance to 12 months from that day. A subscription does not extend pack credit. Your agent shows the exact date as
credits_expire_at; expiry is recorded in the billing ledger. - A per-thread subscription is billed monthly and gives unlimited catches on the threads it covers. We bill on the 1st of each calendar month; the first charge covers only the rest of the month and is proportionally smaller. It stays active while paid and is not affected by pack expiry.
Your agent shows you the verdicts before submitting them. Marking a real bug NOT_REAL to avoid a fee and then silently fixing it violates these terms; we audit later diffs for that pattern.
3. Refunds
- A billed review you dispute. Email ohmybug@explyt.com within 14 days of the charge with the review id. If the finding was not a real bug, we return the charge to your balance ($10 or the catch it consumed). If you paid by card within the last 60 days, you can ask us to refund the card instead.
- Prepaid packs. Unused pack credit is refundable within 14 days of purchase if no catch from that pack has been billed. After that, or once used, it is not refundable and stays on your balance under the expiry rules above.
- Subscriptions. No partial-month refunds; see section 4.
4. Subscription cancellation
Cancel any time from the billing portal link your agent shows you (also available from get_balance). Access continues through the paid period, then stops. We do not give partial-month refunds. Cancelling a subscription does not affect pack credit.
5. Where your code runs
- Each review runs in its own isolated VM sandbox on Sprites (Fly.io).
- Network access is deny-all except for allow-listed model-inference endpoints and our API. The network layer enforces this.
- The VM is destroyed when the review ends. Each attempt is capped at 6.5 hours. If a worker is replaced mid-run, the next worker continues in the same sandbox under a fresh cap. Your diff and files are deleted from our database once the sandbox receives them; a retry stores them again until its sandbox receives them. Files requested mid-review are deleted when the worker reads them or when the review ends. For a full-repository review, the repository snapshot stays on our API for up to 10 minutes so parallel reviews of one commit can share it, and until the last finishes seeding (seeding is capped at 60 minutes). We keep no repository copy after that. The run transcript stays 7 days after a completed review or 30 days after a failed one, then is deleted.
- For some reviews, before the sandbox starts, our API asks a classifier (TypeSafe, through OpenRouter; United States) which known bug types fit the change. It receives the changed file paths and how many lines changed in each, never lines of code.
- Your submissions are never used to train models.
6. What leaves your machine
By default, your agent uploads the diff and the context files it selects and shows you in a manifest. If the fast pass finds nothing, we may offer a full-repository review through the read-only OhMyBug GitHub App. You install it for one repository; the repository copy stays in the sandbox and the short-lived API snapshot described in section 5. The bug-type classifier described in section 5 receives only metadata about the change, never its code.
7. Accounts
Sign-in uses GitHub OAuth. We store your GitHub login and id, hashed API keys, review metadata, findings, verdicts, and the billing ledger—the minimum needed to run the service and show your history. Email ohmybug@explyt.com to delete your account and data. The Privacy Policy explains what we collect, who processes it, and how long we keep it.
8. No warranty
Reviews are best-effort. A clean review does not mean your code has no bugs, and a finding remains a candidate until your agent confirms it. The service is provided as-is. Our total liability is capped at what you paid us in the last 3 months.
9. Governing law and venue
These terms are governed by Delaware law, without regard to conflict-of-law rules. Any dispute we cannot settle by email goes to a federal or state court in Delaware, and both sides accept that jurisdiction.
10. Legal entity
OhMyBug is provided by Explicit Insights, LLC, 16192 Coastal Hwy, Lewes, DE 19958, United States. Legal notices go to ohmybug@explyt.com.
11. Changes
We may update these terms. We will post material changes here with a new “last updated” date. Continuing to use the service after a change means you accept them.