---
title: "Data Collected"
description: "See what data is collected by the Sentry JavaScript SDK."
url: https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected/
---

# Data Collected for Electron

Sentry takes data privacy very seriously and has default settings in place that prioritize data safety, especially when it comes to personally identifiable information (PII) data. When you add the Sentry SDK to your application, you allow it to collect data and send it to Sentry during the runtime and build time of your application.

The category types and amount of data collected vary, depending on the integrations you've enabled in the Sentry SDK. This page lists data categories that the Sentry JavaScript SDK collects.

Options to control data collection

You can control many of the categories listed here with the [`dataCollection` option](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/options.md#dataCollection), which lets you opt in or out of each data category individually.

By default, the SDK collects all `dataCollection` categories and scrubs values whose keys match the built-in sensitive denylist. To collect less, opt out of a category or restrict it.

Regardless of these options, you can always scrub any data before it's sent to Sentry. See [Scrubbing Sensitive Data](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/sensitive-data.md) for details.

## [HTTP Headers](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#http-headers)

By default, the SDK sends HTTP request and response headers. It always keeps the header names and replaces the values of sensitive headers (names that match terms such as `auth`, `token`, or `password`) with `[Filtered]`.

Which headers are sent depends on the environment:

* In the browser, the SDK sends the request headers it gathers itself (`Referer` and `User-Agent`). The `httpClient` integration, which is not enabled by default, adds the request and response headers of failed requests.
* On the server, the headers of incoming requests are attached to error events and server spans. On some runtimes (such as Bun and Deno), the response headers of incoming requests are attached to server spans as well.
* The headers of outgoing requests are not collected by default.

Use the `dataCollection.httpHeaders` option to control header collection. Set `dataCollection: { httpHeaders: false }` to disable it, or use `{ allow: [...] }` or `{ deny: [...] }` to restrict which header values are sent. To control each direction separately, use the `{ request: ..., response: ... }` form, for example `{ request: true, response: false }`.

## [Cookies](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#cookies)

By default, cookie collection is enabled. On the server, the cookies of incoming requests are sent with error events and server spans. In the browser, the SDK doesn't send cookies unless you [enable the `httpClient` integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/httpclient.md), which captures the cookies of failed requests. The SDK replaces the values of sensitive cookies (like `token` or `key`) with `[Filtered]`.

To disable cookie collection, set `dataCollection: { cookies: false }`. You can also restrict which cookie values are sent using `{ allow: [...] }` or `{ deny: [...] }`.

## [Information About Logged-in User](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#information-about-logged-in-user)

The Sentry SDK doesn't fill the user identity fields `user.id`, `user.email`, and `user.username` automatically. Data that you set with [`Sentry.setUser()`](https://docs.sentry.io/platforms/javascript/guides/electron/apis.md#setUser) is always sent to Sentry. Some integrations (e.g. [User Feedback](https://docs.sentry.io/platforms/javascript/guides/electron/user-feedback.md)) may also send data like the user ID, username, and email address when explicitly configured.

The `dataCollection.userInfo` option controls the identity data the SDK infers on its own, such as the user's IP address (see the next section). It doesn't affect data set with `Sentry.setUser()`.

### [Local Device User](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#local-device-user)

By default, the Sentry SDK doesn't send any information about the user currently logged-in to the device where the app is running. However, you should exercise caution when logging file system errors as paths may contain the current username.

## [Users' IP Address and Location](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#users-ip-address-and-location)

By default, the SDK sends the user's IP address. To disable it, set [`dataCollection: { userInfo: false }`](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/options.md#dataCollection).

In some integrations such as [`handleRequest`](https://docs.sentry.io/platforms/javascript/guides/astro.md#customize-server-instrumentation) in Astro, the `trackClientIp` option also controls this. It defaults to the `dataCollection.userInfo` setting.

If sending the IP address is enabled we will try to infer the IP address or use the IP address provided by `ip_address` in [`Sentry.setUser()`](https://docs.sentry.io/platforms/javascript/guides/electron/apis.md#setUser). If you set `ip_address: null`, the IP address won't be inferred.

Even when this is disabled, IP addresses can still reach Sentry through collected HTTP headers, cookies, or query parameters (for example, the `X-Forwarded-For` header). Add these terms to the partially-matched deny lists for those categories so their values are filtered:

```JavaScript
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    httpHeaders: { deny: ["forwarded", "-ip", "remote-", "via", "-user"] },
    cookies: { deny: ["forwarded", "-ip", "remote-", "via", "-user"] },
    urlQueryParams: { deny: ["forwarded", "-ip", "remote-", "via", "-user"] },
  },
});
```

## [Request URL](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#request-url)

The request URL of outgoing and incoming HTTP requests is **always sent to Sentry**: the scheme, host, and path can't be turned off. Depending on your application, the path could contain PII data. For example, a URL like `/users/1234/details`, where `1234` is a user id (which may be considered PII).

The query string that's part of the URL is controlled by the `dataCollection.urlQueryParams` setting described in the next section.

## [Request Query String](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#request-query-string)

By default, the full request query string of outgoing and incoming HTTP requests is sent to Sentry. Depending on your application, this could contain PII data. For example, a query string like `?user_id=1234`, where `1234` is a user id (which may be considered PII).

Use the `dataCollection.urlQueryParams` option to control this. Set it to `false` to disable collection entirely, or use `{ allow: [...] }` / `{ deny: [...] }` to filter which values are sent. Values whose keys match the built-in sensitive denylist (terms like `auth`, `token`, `password`, and `secret`) are scrubbed automatically. The same rules apply to the query string inside the request URL: values are filtered in place, and `false` removes the query string from the URL entirely.

Sentry also has some additional [server-side data scrubbing](https://docs.sentry.io/security-legal-pii/scrubbing/server-side-scrubbing.md) in place to remove sensitive data from the query string.

## [Request Body](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#request-body)

By default, the SDK collects the bodies of incoming requests on the server side. This also covers data taken from the body, like tRPC input and Remix action form data.

Use the `dataCollection.httpBodies` option to control this. It takes a list of body types to collect: `"incomingRequest"`, `"outgoingRequest"`, `"incomingResponse"`, and `"outgoingResponse"`. All types are included by default, but the SDK currently only captures `"incomingRequest"` bodies and, for Next.js server actions, `"outgoingResponse"` bodies. Set the option to `[]` to disable body collection:

```js
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    httpBodies: [],
  },
});
```

The body size, taken from the `content-length` header, is always sent, even when body collection is disabled.

On the server-side, the incoming request body is captured by default. You can disable sending the incoming request body by configuring `ignoreRequestBody` in the [HTTP Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/http.md).

## [Response Body](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#response-body)

By default, the SDK doesn't capture response bodies, with one exception: the results of Next.js server actions are collected when `dataCollection.httpBodies` includes `"outgoingResponse"`, which is the default. To disable this, set `dataCollection: { httpBodies: [] }` or provide a subset that excludes `"outgoingResponse"`.

The SDK may still send the response body size, taken from the `content-length` header.

## [Source Context](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#source-context)

By default, SDKs set up by the Sentry CLI Wizard (`@sentry/wizard`) will enable uploading source maps to Sentry.

To disable source map upload, see [the Source Maps documentation](https://docs.sentry.io/platforms/javascript/guides/electron/sourcemaps.md).

## [Local Variables In Stack Trace](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#local-variables-in-stack-trace)

The Sentry SDK does not send local variables in the error stack trace in client-side JavaScript SDKs.

You can enable sending local variables by setting `includeLocalVariables: true` in the `Sentry.init()` call. This activates the [Local Variables Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/localvariables.md). The integration is added by default in Node.js-based runtimes.

## [Device, Browser, OS and Runtime Information](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#device-browser-os-and-runtime-information)

By default, the Sentry SDK sends information about the device and runtime to Sentry.

The Sentry Electron SDK collects information about the device, such as the platform, architecture, available memory and version and build of your operating system or Linux distribution.

By default, the [Additional Context Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/additionalcontext.md) collects dimensions and resolution of the device screen. It can optionally collect the device's manufacturer and model name if the `deviceModelManufacturer` option is enabled.

By default, the [GPU Context Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/gpucontext.md) collects GPU information. It can optionally collect more detailed information if the `infoLevel` option is set to `complete`.

## [Session Replay](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#session-replay)

By default, our Session Replay SDK masks all text content, images, web views, and user input. This helps ensure that no sensitive data is exposed. You can find [more details in the Session Replay documentation](https://docs.sentry.io/platforms/javascript/guides/electron/session-replay/privacy.md).

The `dataCollection` option doesn't affect Session Replay. Because Replay is opt-in by default (it masks everything unless you allow it), while `dataCollection` is opt-out, the two use opposite privacy models. To avoid changing behavior on a privacy-sensitive feature, Replay's masking and network capture are controlled exclusively by the Replay integration's own [privacy options](https://docs.sentry.io/platforms/javascript/guides/electron/session-replay/privacy.md), regardless of your `dataCollection` settings.

Session Replay also captures basic information about all outgoing fetch and XHR requests in your application. This includes the URL, request and response body size, method, and status code. If [`networkDetailAllowUrls`](https://docs.sentry.io/platforms/javascript/guides/electron/session-replay/configuration.md#network-details) are defined, the request and response body will be sent to Sentry as well. This can include PII data if the request or response body contains PII information.

Console messages are also captured by default in Session Replay. To scrub console messages, you can use the [`beforeAddRecordingEvent`](https://docs.sentry.io/platforms/javascript/guides/electron/session-replay/privacy.md#custom-scrubbing) option to filter console messages before they are sent to Sentry.

## [Console Logs](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#console-logs)

By default, the Sentry SDK sends JS console logs to Sentry as breadcrumbs which may contain PII data.

To disable sending console messages, remove the `Console` integration from your `integrations` config, see [the Console documentation](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/console.md).

## [Stack Trace Context Lines](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#stack-trace-context-lines)

By default, the [Context Lines Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/contextlines.md) is enabled. This integration sends the surrounding lines of code for each frame in the stack trace. This can include PII data if the code contains PII information.

## [Database Queries](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#database-queries)

By default, the Sentry SDK sends database queries to Sentry. The query text is parameterized: literal data values are replaced with placeholders. This applies to SQL and MongoDB queries.

Queries made with the [Supabase integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/supabase.md) also include the data inside the query by default, such as filter values and write payloads. This data can include PII. Use the `dataCollection.databaseQueryData` option to control it. Set it to `false` to redact this data:

```JavaScript
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    databaseQueryData: false,
  },
});
```

The parameterized query text and structural metadata, such as the database system, the operation, and the table, are always sent. If you turn this option off, you keep the query performance data.

## [Queue Message Data](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#queue-message-data)

By default, the Sentry SDK sends the data passed to tasks within queues. For Kafka, this is the message key. Producers often use a user ID or a tenant ID as the message key, so this value can include PII.

Use the `dataCollection.queues` option to control this. Set it to `false` to stop sending the message key:

```JavaScript
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    queues: false,
  },
});
```

Structural metadata, such as the messaging system, the topic, the partition, and the offset, is always sent. If you turn this option off, you keep the queue performance data.

## [tRPC Context](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#trpc-context)

By default, tRPC input is collected because `httpBodies` includes `"incomingRequest"` by default. To disable it, set `dataCollection: { httpBodies: [] }` or use a list that excludes `"incomingRequest"`.

If you exclude `"incomingRequest"`, tRPC input is not collected. You can still opt in per-middleware by setting `attachRpcInput: true` in the [`Sentry.trpcMiddleware()`](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/trpc.md) options, regardless of the global `dataCollection` setting.

## [GraphQL Operations](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#graphql-operations)

When you use a GraphQL integration, the Sentry SDK sends the operation name and the operation type to Sentry.

By default, the SDK also sends the GraphQL document (the query or mutation source text). Literal values inside the document are redacted, and the values of GraphQL variables are not collected. Use the `dataCollection.graphQL` option to turn off the document:

```JavaScript
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    graphQL: {
      document: false,
    },
  },
});
```

## [LLM Inputs And Responses](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#llm-inputs-and-responses)

When using AI integrations, metadata like model ID and used tokens is sent to Sentry.

The content of generative AI inputs (system instructions, prompt messages, tool definitions, and tool call arguments) and outputs (such as completion text and tool call results) might carry personal data. By default, the SDK records both inputs and outputs. Metadata like model ID and token counts is always collected.

The same setting applies to MCP servers instrumented with `wrapMcpServerWithSentry`. By default, the SDK records the inputs and outputs of tool calls, prompt retrievals, and resource reads. Use the wrapper's `recordInputs` and `recordOutputs` options to control recording per server.

Use the `dataCollection.genAI` option to control this. For example, opt out of recording AI message content while keeping the metadata:

```JavaScript
Sentry.init({
  dsn: "https://<key>@o<orgId>.ingest.sentry.io/<projectId>",
  dataCollection: {
    genAI: {
      inputs: false,
      outputs: false,
    },
  },
});
```

## [Window Titles](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#window-titles)

The [Electron Breadcrumbs Integration](https://docs.sentry.io/platforms/javascript/guides/electron/configuration/integrations/electronbreadcrumbs.md) can optionally capture the window titles for breadcrumbs related to windows events. These can potentially contain PII so are disabled by default but can be enabled via the `captureWindowTitles` option.

## [Native Crashes](https://docs.sentry.io/platforms/javascript/guides/electron/data-management/data-collected.md#native-crashes)

At the time of a native crash, the stack of each thread is collected and sent to Sentry as part of the Minidump snapshot. This information is sent to Sentry by default, but dropped after processing the event in the backend.

These files are not stored by default, but you can [enable Minidump Storage](https://docs.sentry.io/platforms/native/guides/minidumps/enriching-events/attachments.md#store-minidumps-as-attachments) in the Sentry [organization](https://sentry.io/orgredirect/organizations/:orgslug/settings/security-and-privacy/) or [project settings](https://sentry.io/orgredirect/organizations/:orgslug/settings/projects/:projectId/security-and-privacy/).
