3 ms·
We have a few ways to ensure you don't send us PII. Sending identifiers like user name or email exist as an option in the SDK, but it is an opt-in integration s
by efutoran 7y ago
We have a few ways to ensure you don't send us PII. Sending identifiers like user name or email exist as an option in the SDK, but it is an opt-in integration step and not done automatically. We also have an option to capture screenshots, but again this is something that customers have full control over so that sensitive parts of the app are not captured. And we built a remote kill-switch for screenshots if a customer didn't get their integration quite right or something unforeseen happened. If you have sensitive data in URLs we allow specific URL patterns to not be captured. Was there any specific type of PII you were primarily interested in seeing masked?
- jefflinwood 7y agoSure - I'm more concerned about inadvertent leakage of email addresses or passwords than passing along an identifier to the API as part of the implementation, especially if it's capturing network traffic.
- efutoran 7y agoWe do support network traffic capture, but this is not enabled by default and is typically only used on specific endpoints with specific status codes that customers are having problems with. We do not capture request and response bodies both for privacy and data usage reasons. We don't want to double the bandwidth usage when somebody integrates us nor do we want them to accidentally send us sensitive data.