Privacy Policy
How AppLogger collects, protects and retains data — and the rights you have over it.
Effective June 6, 2026
AppLogger is a privacy-first, EU-hosted error tracking and log monitoring platform. This policy explains what we collect, how we protect it, how long we keep it, and your rights. We act as a data controller for your account information and as a data processor for the error, log and session data your applications send us (“Customer Data”).
1. Data we collect
Account data (we are the controller)
- Your name and email address, a securely hashed password, and email-verification status.
- Teams you belong to, your role, and projects you own or can access.
Customer Data your applications send us (we are the processor)
- Errors: exception type and message, file and line, stack traces, contextual data, breadcrumbs, request data, environment, release, URL, HTTP method and status, user agent, and an anonymised IP address.
- Logs: hostname, application name, the raw log message, structured fields, and the source IP of the sending host.
- Sessions & session replays: a hashed session identifier, anonymised IP, parsed browser/device information, interacted element text, and rrweb-style DOM and input snapshots used to reconstruct what led to an error.
Technical data
- Standard request metadata needed to operate the dashboard, and a session cookie plus CSRF protection tokens (see Cookies below).
2. How we protect personal data
Because Customer Data comes from your applications, it can contain personal data. We apply several automated protections before storage:
- Secret & field scrubbing. Error context, stack traces, breadcrumbs and request data are scanned and values for sensitive keys (passwords, tokens, API keys, secrets, authorization, cookies, card numbers, and similar) are replaced with
[REDACTED]. Common sensitive patterns — credit-card numbers, email addresses, IPv4 addresses and JSON web tokens — are also scrubbed from values. - IP anonymisation by default. IP addresses on error and session records are anonymised before storage (IPv4 has its host portion masked; IPv6 has its lower bits zeroed). Storing the full IP is an explicit, per-project opt-in that is off by default; when enabled it is stored encrypted with AES-256-GCM using a per-project key.
- Session-replay redaction. Password, hidden and other sensitive form inputs (by type, name, id or CSS class) are redacted in captured replays so their values are not stored.
Honest limitations. We want you to make informed choices:
- Aggregated logs are stored as sent, including the source IP of the sending host, so they are not automatically scrubbed the way error data is. Avoid logging secrets or personal data you do not intend to retain.
- Automated scrubbing is best-effort pattern matching; it cannot guarantee removal of every piece of personal data your applications transmit. You remain the controller of Customer Data and are responsible for what you send.
3. How long we keep data
Customer Data is retained according to your plan tier and then deleted automatically:
- Errors: BASIC 10 days · STANDARD 20 days · PREMIUM 30 days · VIP 60 days.
- Logs: BASIC 1 day · STANDARD 3 days · PREMIUM 7 days · VIP 14 days.
Account data is kept while your account is active and removed when you delete your account.
4. Hosting & sub-processors
AppLogger is hosted on EU infrastructure. Data is stored in a PostgreSQL database (accounts, projects, errors) and a ClickHouse store (aggregated logs), with Redis used for sessions, caching and queues. Bot-protection challenges on our sign-in, registration and password-reset forms are provided by Cloudflare Turnstile. Transactional emails (such as verification, password reset and team invitations) are delivered through an email provider. We do not sell your data or share it with advertising networks.
5. Legal bases
- Contract: to create your account and provide the Service.
- Legitimate interests: to secure the platform (including bot protection), prevent abuse and improve reliability.
- For Customer Data we process on your instructions as a processor, the lawful basis is determined by you as the controller.
6. Your rights & controls
Subject to applicable law (including the GDPR), you may request access to, correction of, deletion of, or a copy of your account data, and object to or restrict certain processing. In-product you can already:
- edit your profile and change your password in account settings;
- control whether full IP addresses are stored per project (off by default);
- delete individual projects, which removes their associated data; and
- delete your account, which removes your account and associated data.
Where AppLogger processes Customer Data on your behalf, requests from your end users should be directed to you as the controller; we will assist you as your processor.
7. Cookies
We use a small number of strictly necessary cookies: a session cookie to keep you signed in, CSRF tokens to protect forms, and an optional “remember me” cookie if you choose it at sign-in. We do not use advertising or cross-site tracking cookies.
8. Children
The Service is intended for developers and organisations and is not directed to children. We do not knowingly collect personal data from children.
9. Changes
We may update this policy as the Service evolves. Material changes will be reflected in the “Effective” date above and, where appropriate, communicated to you.
10. Contact
For privacy questions or to exercise your rights, contact privacy@applogger.eu.