Data and privacy

What Epure stores, retention TTL, ingest scrubbing, and operator responsibilities for GDPR-style teams.

Epure is self-host exception monitoring. You control the Postgres volume, backups, and network path. This page describes default product behavior — not legal advice.

What lands in Postgres

DataSourceNotes
Exception type, message, stackSDK event payloadJS/TS frames demangled when maps exist
BreadcrumbsSDKHTTP, console, navigation context
Tags (environment, release, …)SDKHeader filters in UI
Optional user.id / user.emailSDKUsed for unique-user counts
Request headers / extrasSDKScrubbed at ingest (below)
Issue aggregatesDerivedSurvive raw event TTL

Epure is not a generic log warehouse. There is no arbitrary log product — only crash context.

Retention and deletion

Per-project retention_days: 14, 30 (default), or 90. Raw events live in monthly partitions; TTL drops old partitions. Issue rows and counts remain for triage history.

Configure in Project settings or PATCH /api/v1/projects/{id}: Projects.

Ingest scrubbing (secrets and patterns)

Before persist, the worker runs regex scrubbing on headers, breadcrumbs, and extra fields. Examples of patterns redacted to [REDACTED]:

  • Bearer tokens and common api_key / secret / password shapes
  • Credit-card-like number runs
  • AWS AKIA… access keys
  • Stripe sk_live_ / sk_test_ keys

Sensitive header names (authorization, cookie, etc.) are replaced wholesale. User feedback email fields use the same rules: Ingest.

You still own instrumentation

Scrubbing reduces accidental secret leakage; it does not audit your SDK beforeSend hooks. Do not attach full PII blobs in extra if your policy forbids it.

Tenancy isolation

Dashboard queries use PostgreSQL RLS with app.current_org_id from the session. Ingest authenticates by DSN and writes only for that project’s org. Three database roles (migrate, ingest, app) — Settings, Configuration.

Cloud vs self-host

Self-host: data stays on your disk. Cloud (Pro $24 / Plus $79/mo) runs the same binary path on managed infrastructure — choose based on ops appetite, not a different feature matrix for core ingest.

Operator checklist (compliance-friendly)

  • Pick retention per project (minimize raw event age)
  • Restrict dashboard access via RBAC
  • Use HTTPS and secure session cookies in production
  • Encrypt Postgres volumes and backups at rest (your platform)
  • Document subprocessors: you for self-host; Epure for Cloud when you subscribe
  • Rotate leaked DSN keys from the UI
Can I disable scrubbing?

Scrubbing is built into the ingest worker for all events. There is no per-project off switch in Phase 1. Adjust SDK payloads if you need fields preserved intentionally.

Does Epure sell or share my exception data?

Self-host: no — it never leaves your infrastructure except what you forward (webhooks, exports). Cloud: governed by your agreement with Epure when that product is active for your workspace.

Where is the DPA?

Legal pages live on epure.sh (privacy / terms). Self-host operators typically act as their own controller for stack traces on their VPS.