Data and privacy
What Epure stores, retention TTL, ingest scrubbing, and operator responsibilities for GDPR-style teams.
Epure is self-host exception monitoring. You control the Postgres volume, backups, and network path. This page describes default product behavior — not legal advice.
What lands in Postgres
| Data | Source | Notes |
|---|---|---|
| Exception type, message, stack | SDK event payload | JS/TS frames demangled when maps exist |
| Breadcrumbs | SDK | HTTP, console, navigation context |
Tags (environment, release, …) | SDK | Header filters in UI |
Optional user.id / user.email | SDK | Used for unique-user counts |
| Request headers / extras | SDK | Scrubbed at ingest (below) |
| Issue aggregates | Derived | Survive raw event TTL |
Epure is not a generic log warehouse. There is no arbitrary log product — only crash context.
Retention and deletion
Per-project retention_days: 14, 30 (default), or 90. Raw events live in monthly partitions; TTL drops old partitions. Issue rows and counts remain for triage history.
Configure in Project settings or PATCH /api/v1/projects/{id}: Projects.
Ingest scrubbing (secrets and patterns)
Before persist, the worker runs regex scrubbing on headers, breadcrumbs, and extra fields. Examples of patterns redacted to [REDACTED]:
- Bearer tokens and common
api_key/secret/passwordshapes - Credit-card-like number runs
- AWS
AKIA…access keys - Stripe
sk_live_/sk_test_keys
Sensitive header names (authorization, cookie, etc.) are replaced wholesale. User feedback email fields use the same rules: Ingest.
You still own instrumentation
Scrubbing reduces accidental secret leakage; it does not audit your SDK beforeSend hooks. Do not attach full PII blobs in extra if your policy forbids it.
Tenancy isolation
Dashboard queries use PostgreSQL RLS with app.current_org_id from the session. Ingest authenticates by DSN and writes only for that project’s org. Three database roles (migrate, ingest, app) — Settings, Configuration.
Cloud vs self-host
Self-host: data stays on your disk. Cloud (Pro $24 / Plus $79/mo) runs the same binary path on managed infrastructure — choose based on ops appetite, not a different feature matrix for core ingest.
Operator checklist (compliance-friendly)
- Pick retention per project (minimize raw event age)
- Restrict dashboard access via RBAC
- Use HTTPS and secure session cookies in production
- Encrypt Postgres volumes and backups at rest (your platform)
- Document subprocessors: you for self-host; Epure for Cloud when you subscribe
- Rotate leaked DSN keys from the UI
FAQ
Can I disable scrubbing?
Scrubbing is built into the ingest worker for all events. There is no per-project off switch in Phase 1. Adjust SDK payloads if you need fields preserved intentionally.
Does Epure sell or share my exception data?
Self-host: no — it never leaves your infrastructure except what you forward (webhooks, exports). Cloud: governed by your agreement with Epure when that product is active for your workspace.
Where is the DPA?
Legal pages live on epure.sh (privacy / terms). Self-host operators typically act as their own controller for stack traces on their VPS.
Next
Production checklist
HTTPS, production compose overlay, env secrets, CORS, backups, and health checks before you point production SDKs at Epure.
Installation
Install Epure with Docker Compose on a VPS or import one-click deploy templates for Render, Railway, Coolify, and Dokploy. Two containers, PostgreSQL 16, GET /health, then point your Sentry SDK DSN.