What is sent
What dlogify receives, what it redacts and what it does not do.
This page lists what leaves your application, what dlogify removes on arrival, and who else sees it.
What clients send
The dlogify clients send only log records: the message, level and time, the attributes you add, the error's type, message and stack trace, and the service name, environment, release, host name and client version. They make no other network calls, open no ports and collect nothing else about the machine.
Personal data
dlogify redacts the message, the stack trace and every attribute value when it processes a batch, before anything is written to its database or sent to a third party. Until then, incoming batches wait briefly, unredacted, in an internal queue; a batch that cannot be processed is kept there for at most 14 days for investigation. Redaction replaces:
| Found | Replaced with |
|---|---|
| JSON Web Tokens | <jwt> |
Bearer tokens | Bearer <token> |
Keys with well-known prefixes (sk_live_, sk_test_, rk_live_, ghp_, gho_, ghs_, github_pat_, glpat-, xoxb-, xoxp-, AKIA…, AIza…) | <secret> |
Values after password, passwd, secret, token, api_key, apikey or access_key followed by = or : | <secret> (the key name is kept) |
| Email addresses | <email> |
| Card numbers (13–19 digits that pass the Luhn check) | <card> |
| IPv4 and IPv6 addresses | <ip> |
Redaction is a safety net, not a guarantee: avoid logging personal data you do not need. To keep data from leaving your process at all, redact it in the client: see Redaction.
AI providers
To classify an error and write its ticket, dlogify sends AI providers the redacted information about the error group: the message, the stack trace, the surrounding log lines and counts. INFO summaries use counts and a few redacted examples. Providers are used with settings that exclude your data from training. The list of providers is in the privacy policy.
Retention
Error samples, tickets and INFO summaries are deleted after your plan's retention period (see Plans and usage).
What dlogify does not do
- It does not store every
INFOevent: they are counted and summarized. - It does not process
traceanddebugevents: they are dropped on arrival (see Level mapping). - It does not call your systems, except the webhooks you configure.