Dokumentation
Gennemse dokumentationen

PII scrubbing for analytics data

How the PII scrubber redacts emails, tokens and other PII from URLs, referrers and event properties before storage, plus custom rules and a redaction log.

Vis som Markdown

Personal data often leaks into analytics by accident: an email in a confirmation URL, a password-reset token, a phone number in a search. The PII scrubber replaces it before anything is stored. It's on by default (Site settings → Privacy).

What it checks#

Paths, referrer paths and every string property, with these rules:

Rule Finds Replacement
email Email addresses [redacted-email]
jwt JWT-like tokens (three base64 segments starting with eyJ) [redacted-token]
secret Values of token=, key=, secret=, password=, pass=, auth= and session= parameters [redacted]
uuid UUIDs [redacted-id]
long_id Hexadecimal ids of 32 characters or more [redacted-id]
digits Runs of 10 or more digits (spaces and dashes allowed), such as phone and card numbers [redacted-number]

For example /reset?token=abc123 becomes /reset?token=[redacted] (if token were an allowed parameter at all), and /users/[email protected] becomes /users/[redacted-email].

Custom rules#

Add your own regular expressions in Site settings → Privacy → PII scrubber, for example customer numbers like CUST-\d{6}. Matches become [redacted].

Redaction log#

The same tab shows how often each rule fired over the last 30 days, so you can find and fix the leak at its source. We count redactions but never keep the redacted values.

It's a safety net#

Fix leaks where they start: don't put personal data in URLs, and don't send it as event properties. Use path masks for ids in paths.