Data and privacy

Blipit stores whatever your application sends when it breaks, on your instructions. This page says what that is in practice, what the SDKs strip before sending, where the data lives, and what you can delete. The full policy is at blipit.io/legal/privacy.

1What an event contains

Typically the error type and message, the stack trace with a few lines of your code around each frame, the URL or job, release and environment, browser or server version, breadcrumbs, the user id or email you attached, tags, and the IP the report came from. Blipit does not filter this: if your code puts a customer's name in an error message, it arrives.

2What the SDKs scrub

The browser SDK redacts query parameters whose name contains token, key, password, secret, auth, session, passwd or api in URLs and breadcrumbs, and masks all text and inputs in replays. The Odoo module never sends query strings, request bodies, passwords, hashes, session tokens or cookies. Use beforeSend in the browser SDK (or your Sentry SDK's equivalent) to drop or edit anything else before it leaves.

3Where it lives

Singapore: the database is Neon on AWS Singapore, ingestion and processing run on Fly.io in Singapore, the queue is Upstash. The dashboard is served by Vercel, DNS by Cloudflare, alert email by Microsoft 365, payments by Stripe. Anthropic receives an issue's details only when someone runs an AI fix.

4How long

Raw events for your plan's retention (14, 30, 90 or 90 days), issue summaries while the workspace exists, logs 3 to 30 days, spans 7 or 30 days, replays and web vitals 30 days, sessions 90 days, audit rows 365 days. Account data is deleted within 30 days of closing a workspace.

5Terms and deletion

You accept the Terms (version dated 28 September 2026) on sign-up and again if they change; the acceptance is recorded with time and IP and appears in the audit log. The Odoo module records the same acceptance on Connect. Remove a project to delete all its data at once. For account deletion or a copy of your data, write to privacy@blipit.io; answers within 30 days.

Good to know

  • API keys, session tokens and sign-in links are stored only as SHA-256 hashes. Tracker tokens, GitHub tokens and TOTP secrets are encrypted with AES-256-GCM.
  • If a breach puts your data at risk, affected customers are emailed within 72 hours of Blipit becoming aware.
  • Blipit does not sell data, share it with advertisers or use event data to train models.

Stuck? Email support@blipit.io. Keys and the exact DSN for each project are under API keys in app.blipit.io.