PII scrubbing for analytics data
How the PII scrubber redacts emails, tokens and other PII from URLs, referrers and event properties before storage, plus custom rules and a redaction log.
Personal data often leaks into analytics by accident: an email in a confirmation URL, a password-reset token, a phone number in a search. The PII scrubber replaces it before anything is stored. It's on by default (Site settings → Privacy).
What it checks#
Paths, referrer paths and every string property, with these rules:
| Rule | Finds | Replacement |
|---|---|---|
email |
Email addresses | [redacted-email] |
jwt |
JWT-like tokens (three base64 segments starting with eyJ) |
[redacted-token] |
secret |
Values of token=, key=, secret=, password=, pass=, auth= and session= parameters |
[redacted] |
uuid |
UUIDs | [redacted-id] |
long_id |
Hexadecimal ids of 32 characters or more | [redacted-id] |
digits |
Runs of 10 or more digits (spaces and dashes allowed), such as phone and card numbers | [redacted-number] |
For example /reset?token=abc123 becomes /reset?token=[redacted] (if
token were an allowed parameter at all), and
/users/[email protected] becomes /users/[redacted-email].
Custom rules#
Add your own regular expressions in Site settings → Privacy → PII
scrubber, for example customer numbers like CUST-\d{6}. Matches become
[redacted].
Redaction log#
The same tab shows how often each rule fired over the last 30 days, so you can find and fix the leak at its source. We count redactions but never keep the redacted values.
It's a safety net#
Fix leaks where they start: don't put personal data in URLs, and don't send it as event properties. Use path masks for ids in paths.