Skip to the text
ErrorHub
Why ErrorHub How it works Features Pricing FAQ
Sign in Start free
Menu
Why ErrorHub How it works Features Pricing FAQ Sign in
ErrorHub / Privacy Policy

Legal

Privacy Policy

ErrorHub collects what it needs to run your account and to show you your errors, and nothing for advertising. This page says what that is, where it is kept, and what you can do about it.

In force from 29 September 2026 · Privacy · Terms · Data processing

On this page

  1. The short version
  2. Who is responsible
  3. Two kinds of data, two roles
  4. What we collect about you
  5. Why we use it, and on what legal basis
  6. The error events you send
  7. Where the data is
  8. Who receives data
  9. Transfers outside the European Economic Area
  10. How long we keep it
  11. Cookies and storage in your browser
  12. Your rights
  13. How we protect it
  14. Children
  15. Changes to this policy

The short version

  • We sell error tracking. We do not sell data, show advertising or build profiles of anyone.
  • The website and the dashboard load no third-party scripts and use no analytics or tracking cookies.
  • ErrorHub runs on a server rented from Hetzner Online GmbH in Germany, in the European Union.
  • You can close your account yourself at any time. Its projects, errors, keys and users are deleted at once.
  • Questions and requests go to hello@errorhub.dev. A person answers.

Who is responsible

ErrorHub is a product of Autrady EOOD, a company registered in the Bulgarian Commercial Register under UIC 206828616, VAT number BG206828616, with its registered office at Geo Milev St., bl. 83, fl. 14, apt. 67, 9009 Varna, Bulgaria. In this policy "we" means Autrady EOOD.

Contact for everything about personal data: hello@errorhub.dev.

Two kinds of data, two roles

ErrorHub handles personal data in two different roles, and the difference decides who answers for what.

Data Our role What applies
Your account: login, team, billing, messages to us Controller This policy
The error events your applications send Processor, on your behalf The Data Processing Agreement, and your own privacy policy towards your users

If you are a user of an application that reports its errors to ErrorHub, the company behind that application decides what is sent and is the one to ask about it. We help them answer you.

What we collect about you

When you create a login

  • Your email address, the name you give, and the name of your account or company.
  • Your password, stored only as a salted hash (PBKDF2). We cannot read it and cannot send it to you.
  • Your role in the account, when the login was created and when you last signed in.
  • When you agreed to the Terms of Service, and which version.

When you use the dashboard

  • One session cookie that keeps you signed in. See Cookies and storage in your browser.
  • If you turn on alerts on a device: the address and the public keys your browser hands out for push notifications, and a label such as "Chrome on Windows". They let us send that device a notification and nothing else.
  • What you do with issues, such as which user resolved one.

When you pay

Payments are handled by Stripe. Card numbers and bank details are entered on pages hosted by Stripe and never reach our server. We store the identifiers Stripe gives us for your customer record and subscription, the state of the subscription and its billing period. Stripe collects your billing name, address and, for businesses, your VAT number, because invoices and VAT require them.

How much you use

Per account and billing period we count the events the API accepted and the events it refused because a limit was reached. These counts decide what your plan allows and what an invoice says.

When you write to us

The messages you send to hello@errorhub.dev and our replies.

Technical data

Every request reaches us with an IP address and the usual browser headers. We use the IP address in memory to limit how often one address may try to sign in or sign up. Our server logs record warnings and errors of the service itself; they contain account identifiers and, rarely, an IP address or an email address.

Why we use it, and on what legal basis

Purpose Data Legal basis (GDPR)
Providing the service you signed up for Login, team, usage counts, alert devices Contract, Art. 6(1)(b)
Billing, invoices and VAT Billing details, subscription, usage counts Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c)
Messages about your account: confirming your email, password resets, invitations, usage warnings, changes to these documents Email address, account name Contract, Art. 6(1)(b)
Keeping the service secure and preventing abuse IP address, server logs, sign-in times Legitimate interest, Art. 6(1)(f): a service that is safe for everyone who uses it
Answering you Your messages Contract or steps before a contract, Art. 6(1)(b); otherwise legitimate interest, Art. 6(1)(f)

We send no marketing mail to the address of your login. We make no automated decisions about you that have legal or similarly significant effects.

The error events you send

An error event is what your application posts to the API: a message, an exception type, a stack trace, the environment and release, the method and path of the request, and any tags or context you add. You decide what goes into it. It can contain personal data of your users, for example a user identifier.

Before an event is stored, ErrorHub:

  • removes the query string from request paths,
  • replaces the values of fields whose names say they hold a secret (password, token, API key, card number and the like), and credentials it recognises inside text, with a marker,
  • cuts every field to a maximum length and the whole event to a maximum size.

This scrubbing is a safety net, not a guarantee. Do not send passwords, payment card data, health data or other special categories of personal data in error events.

Events are kept for as long as your plan says: 7 days on Free, 30 days on Indie, and as agreed on Scale. After that they are deleted automatically. The issue they belonged to, with its title and counters, stays until you delete the project or close the account.

Where the data is

The application and its database run on a server we rent from Hetzner Online GmbH, in a data centre in Germany. Hetzner provides the machine and the data centre and does not access what runs on it. The data of different accounts is kept apart in every query the application makes, and automated tests check that one account cannot read the data of another.

Who receives data

We use three companies to run ErrorHub. Each gets only what its task needs.

Company Task Data Where
Hetzner Online GmbH Provides the server and the data centre the application and its database run on Everything ErrorHub stores, as data on the disk of that server; Hetzner does not access it Germany
Cloudflare, Inc. Runs the DNS of errorhub.dev and forwards mail sent to us DNS queries for our host names; mail you send to us Worldwide network, based in the USA
Stripe Payments Europe, Limited Checkout, subscriptions, invoices, VAT Billing name, address, VAT number, email, payment details, what you bought Ireland, with processing in the USA

Outgoing account mail is sent from our own domain. If we start using a mail delivery service for it, it is added to this list before it is used.

If you turn on alerts, notifications travel through the push service of your browser's maker (Google, Mozilla or Apple). Their content is encrypted for your device, so the push service cannot read it.

We give data to authorities only when the law obliges us to. We do not sell or rent personal data to anyone.

Transfers outside the European Economic Area

Cloudflare and Stripe can process data in the USA. Both are certified under the EU-US Data Privacy Framework, and our agreements with them include the standard contractual clauses of the European Commission. You can ask us for a copy of the safeguards.

How long we keep it

Data Kept
Login, team, projects, keys, issues Until you delete them or close the account
Error events 7 days on Free, 30 days on Indie, as agreed on Scale
Links sent by mail (confirmation, password reset, invitation) They stop working after 48 hours, 1 hour and 7 days. Their records are deleted 30 days later.
Session cookie 12 hours after your last request
Invoices and accounting records 10 years, as Bulgarian accounting law requires
Messages you sent us Up to 3 years after the last message, to be able to follow up and to defend legal claims
Server logs Overwritten on a rolling basis as the log fills up

Closing the account in the dashboard deletes its projects, errors, keys, usage counts and users from the database at once. Copies in backups disappear as the backups are overwritten.

Cookies and storage in your browser

The public website sets no cookies. The dashboard sets one, and only after you sign in:

Name Purpose Lifetime
errorhub.session Keeps you signed in. Cannot be read by scripts and is only sent to ErrorHub. 12 hours after your last request, or until you sign out

The dashboard also keeps small settings in the storage of your browser, such as a hint you dismissed and whether alerts are on for this device. They never leave your browser.

Both are strictly necessary for a service you asked for, so they need no consent banner.

Your rights

Under the GDPR you have the right to:

  • know what we hold about you and get a copy of it,
  • have wrong data corrected,
  • have your data deleted,
  • have its use restricted,
  • object to uses that rest on our legitimate interest,
  • receive the data you gave us in a common format, to take it elsewhere.

Much of this you can do yourself in the dashboard: change your name and password, remove people, delete projects and close the account. For everything else write to hello@errorhub.dev. We answer within one month and ask for nothing but what we need to be sure it is you.

You can complain to a supervisory authority. Ours is the Commission for Personal Data Protection of Bulgaria, 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, cpdp.bg. You can also turn to the authority of the country you live or work in.

How we protect it

  • Every connection to the website, the dashboard and the API is encrypted.
  • Passwords and secret server keys are stored as hashes. Links in mail are stored as hashes too.
  • Changing or resetting a password signs out every other device.
  • Sign-in, sign-up and password reset are limited per address to slow down guessing.
  • Roles limit who in your team can manage projects, keys, people and the plan.

If a breach affects your personal data and is likely to put you at risk, we tell you and the supervisory authority without undue delay.

Children

ErrorHub is a tool for people who build and run software. It is not meant for children, and we do not knowingly collect data of anyone under 16.

Changes to this policy

When we change this policy, the date at the top changes. If a change affects how we use the data of your account in a way that matters, we write to the address of your login before it takes effect.

ErrorHub

Error tracking for every app you run. Nothing else.

Product

Why ErrorHub How it works Features Pricing FAQ

Developers

OpenAPI document Pricing as Markdown llms.txt

Account

Sign in Start free hello@errorhub.dev

Legal

Privacy Policy Terms of Service Data Processing Agreement

© 2026 Autrady EOOD, Varna, Bulgaria. UIC 206828616. This page sets no cookies and loads no third-party scripts.

Page updated 29 September 2026