# PII scrubbing for analytics data

> How the PII scrubber redacts emails, tokens and other PII from URLs, referrers and event properties before storage, plus custom rules and a redaction log.

Personal data often leaks into analytics by accident: an email in a
confirmation URL, a password-reset token, a phone number in a search. The
PII scrubber replaces it **before anything is stored**. It's on by default
(Site settings → Privacy).

## What it checks

Paths, referrer paths and every string property, with these rules:

| Rule | Finds | Replacement |
|---|---|---|
| `email` | Email addresses | `[redacted-email]` |
| `jwt` | JWT-like tokens (three base64 segments starting with `eyJ`) | `[redacted-token]` |
| `secret` | Values of `token=`, `key=`, `secret=`, `password=`, `pass=`, `auth=` and `session=` parameters | `[redacted]` |
| `uuid` | UUIDs | `[redacted-id]` |
| `long_id` | Hexadecimal ids of 32 characters or more | `[redacted-id]` |
| `digits` | Runs of 10 or more digits (spaces and dashes allowed), such as phone and card numbers | `[redacted-number]` |

For example `/reset?token=abc123` becomes `/reset?token=[redacted]` (if
`token` were an allowed parameter at all), and
`/users/jane@example.com` becomes `/users/[redacted-email]`.

## Custom rules

Add your own regular expressions in **Site settings → Privacy → PII
scrubber**, for example customer numbers like `CUST-\d{6}`. Matches become
`[redacted]`.

## Redaction log

The same tab shows how often each rule fired over the last 30 days, so you
can find and fix the leak at its source. We count redactions but never
keep the redacted values.

## It's a safety net

Fix leaks where they start: don't put personal data in URLs, and don't
send it as event properties. Use [path masks](/docs/tracker/exclusions-and-masking)
for ids in paths.
