Concepts

Privacy & data

Session replay, input traces, and console logs are sensitive by nature — and Fixback additionally feeds them into agent prompts. So the SDKs are private by default: sensitive data is masked and scrubbed before anything leaves the browser or server.

Masking, before capture

On the web, input values are masked before the screenshot is taken and before the replay is recorded — so private text never enters the captured image or the DOM recording in the first place. You can explicitly unmask an element where full fidelity matters (an internal or beta project can loosen this globally).

Scrubbing, before transport

Every report — human-sent or auto-captured — passes through the same client-side scrubbers:

  • URLs lose query strings and PII in path segments.
  • Console and error text loses emails, bearer tokens, and long digit runs — seven digits or more, the shape of a phone, card or account number. A digit run inside an identifier is left alone: a token that mixes letters and digits, or a UUID, keeps its shape, so the ids in your URLs and messages stay usable.
  • Network crumbs are metadata by default — method, scrubbed URL, status, timing, sizes, content-type, and a failure classification. Never a header value — the one header the SDK touches is the Correlation id it minted itself and sent with the request, which the crumb records: a random id that identifies the request, never a person.
  • Request and response bodies are opt-in. The web SDK records them only when a Project turns on Capture request and response bodies in its capture settings (off by default), and only as text — JSON, XML, text, URL-encoded forms; never a file, a multipart form, or binary data — up to 4 KiB each, with emails, bearer tokens, and long digit runs redacted before they leave the browser. A bigger body is dropped whole, never cut short. Ingest redacts bodies again, and strips them from any Project that has not opted in. The Expo SDK never records a body.

On the backend

@fixback/node captures the route pattern (never the concrete path with values), the method, status, a correlation id, and an app-supplied user reference. It never sends Authorization/Cookie headers, environment variables, or query-string values — and it sends request/response bodies only when your backend opts in with captureBodies: each up to 16 KiB by default, dropped whole when bigger, and PII-redacted before it leaves the process and again at ingest.

The beforeSend hook

Every SDK exposes a beforeSend choke point — the last chance to redact further, or to drop a report entirely by returning null. It runs on both human reports and automatic error captures.

ts
init({  key: "pk_live_…",  beforeSend(report) {    // Drop anything from an internal admin path entirely.    if (report.url?.includes("/admin")) return null;    return report;  },});