Concepts
Privacy & data
Masking, before capture
On the web, input values are masked before the screenshot is taken and before the replay is recorded — so private text never enters the captured image or the DOM recording in the first place. You can explicitly unmask an element where full fidelity matters (an internal or beta project can loosen this globally).
Scrubbing, before transport
Every report — human-sent or auto-captured — passes through the same client-side scrubbers:
- URLs lose query strings and PII in path segments.
- Console and error text loses emails, bearer tokens, and long digit runs — seven digits or more, the shape of a phone, card or account number. A digit run inside an identifier is left alone: a token that mixes letters and digits, or a UUID, keeps its shape, so the ids in your URLs and messages stay usable.
- Network crumbs are metadata by default — method, scrubbed URL, status, timing, sizes, content-type, and a failure classification. Never a header value — the one header the SDK touches is the Correlation id it minted itself and sent with the request, which the crumb records: a random id that identifies the request, never a person.
- Request and response bodies are opt-in. The web SDK records them only when a Project turns on Capture request and response bodies in its capture settings (off by default), and only as text — JSON, XML, text, URL-encoded forms; never a file, a multipart form, or binary data — up to 4 KiB each, with emails, bearer tokens, and long digit runs redacted before they leave the browser. A bigger body is dropped whole, never cut short. Ingest redacts bodies again, and strips them from any Project that has not opted in. The Expo SDK never records a body.
On the backend
@fixback/node captures the route pattern (never the concrete path
with values), the method, status, a correlation id, and an app-supplied user reference. It never
sends Authorization/Cookie headers, environment variables, or
query-string values — and it sends request/response bodies only when your backend opts in with captureBodies: each up to 16 KiB
by default, dropped whole when bigger, and PII-redacted before it leaves the process and again
at ingest.
The beforeSend hook
Every SDK exposes a beforeSend choke point — the last chance to redact further, or to
drop a report entirely by returning null. It runs on both human reports and
automatic error captures.
init({ key: "pk_live_…", beforeSend(report) { // Drop anything from an internal admin path entirely. if (report.url?.includes("/admin")) return null; return report; },});