Home

How-to guide · chapter 6 of 10

Privacy and masking

What is captured, what is masked and how to check it.

BugTape records page activity in the browser so a report can show what happened. This chapter explains what is recorded and how to keep private data out.

What is recorded

  • The page: changes to the page, rebuilt later as a replay. It is not a screen video.
  • Requests: method, URL, status and timing. Request and response bodies are not recorded.
  • The console and errors: console output and stack traces.

The recording stays in the browser's memory, covering about the last ten minutes, and is only sent with a report.

What is hidden by default

  • Typed values in inputs, text areas, selects and editable areas are masked.
  • Emails, card numbers, tokens and similar patterns are scrubbed from recorded text.
  • The bug-report form itself is never recorded.

Hide parts of your page

Add data-bugtape-ignore to any element that holds private information. The element and everything inside it are left out of the replay:

<table data-bugtape-ignore>
  <!-- customer names, balances, anything private -->
</table>

The class bugtape-ignore works the same way.

Strict mode: hide all page text

For pages that show client names, amounts or health data, turn on strict mode:

init({
  apiKey: 'bt_live_your_key_here',
  privacy: 'strict',
});

The replay keeps the layout, clicks and scrolls, but every character of page text in the replay becomes a solid block in the browser before it is sent (so “Anna Smith” is recorded as “▇▇▇▇ ▇▇▇▇▇”). The activity signal that shows who is live carries only the page path. Titles, labels, alt text and placeholders are masked too. URLs lose their query strings, request bodies are never kept, and console objects are dropped. Error messages and stack traces are still sent, after the usual scrub, because they are what you need to fix the bug.

You can pick strict mode in the Privacy step of Setup. The install snippet in the next step carries it.

Seal client details your team still needs to read

Strict mode hides text for good. When your team needs to see a client's name while fixing a bug, but BugTape should not, seal it instead.

  1. In the console, open Settings → Client details and select Make a key pair. The key pair is made in your browser. Download the private key file and keep it safe: BugTape has no copy, and without it the details cannot be read.
  2. Add the public key to your setup, and mark the elements that show client details:
<td data-bugtape-token>Anna Smith</td>

import { init, identify, token } from 'https://app.bugtape.ai/bugtape.mjs';

init({
  apiKey: 'bt_live_your_key_here',
  tokenize: { publicKey: 'btpk1_your_public_key' },
});

// Values you pass yourself, for example in context:
identify({ userId: 'u_123', name: token(customer.name) });

Seal names and other details people read. Do not pass userId or an email through token(): BugTape uses them to count who a bug reached and to notify people, and a placeholder changes on every page load.

In the browser, marked text becomes a placeholder such as ⟦bt:1⟧. When a report is sent, the values it uses are sealed with your public key. BugTape stores the sealed values and cannot open them.

  1. On the issue page, select Unlock and paste the private key or choose the key file. The replay and events show the real values in that browser tab only. The key is never sent to BugTape and is forgotten when you close the tab.

What it does not cover: text outside marked elements, error messages, URLs and console output. Keep client details out of those, or use strict mode. Without a public key, marked text is masked instead, so it never leaves as plain text. Anyone who can run code on your page can already read these details; the key protects them inside BugTape.

Turn recording off

init({
  apiKey: 'bt_live_your_key_here',
  disableDomRecording: true,     // no page replay
  disableNetworkRecording: true, // no request list
});

Errors are still reported with their stack.

Check it on your own screens

Before you go live on pages with customer data, follow the privacy checklist: mark private areas, send one report, and search the replay for the private text. There should be no matches.

Next

Send bugs from your iOS app, React Native app or servers.