Skip to content

Privacy and Permissions

Privacy rules must take effect before data enters the RUM or Log queues. Both C# and Native C/C++ support redaction of URL Query, HTTP request headers, and response headers, and can handle business-sensitive fields through the generic Modifier.

Permission Configuration

The Windows SDK does not proactively apply for system permissions. The application must ensure that the process can access the configured reporting endpoint and cache directory; WebView2, window handles, and network components still follow the host application's own permission and security policies.

Default Behavior

Data .NET / C# Native C/C++
URL Query Non-sensitive values are retained; default sensitive parameters are replaced with <redacted> Same
HTTP Header Authentication-related headers are collected and redacted by default Same
User and custom attributes Can be redacted via DataModifier or LineDataModifier Same
Log content and attributes Can be redacted via DataModifier or LineDataModifier Same
Trace Header Only sent to targets allowed by ShouldTrace/should_trace Same

Default sensitive Query names include token, access_token, refresh_token, client_secret, password, passwd, secret, api_key, apikey, auth, and authorization. Default sensitive Header names include Authorization, Cookie, Set-Cookie, Proxy-Authorization, X-Api-Key, X-Auth-Token, and X-Datakit-Token.

Unified Processing Order

RUM, Log, WebView, and Native Browser Bridge data use the same processing order before being written to the disk cache:

  1. DataModifier: Processes existing Tags and Fields one by one; when it returns null, or the Native callback returns 0, the original value is retained.
  2. LineDataModifier: Views the entire data line by Measurement and updates existing fields; new fields are ignored.
  3. HTTP privacy rules: URL Query, request headers, and response headers are processed last, preventing custom Modifiers from bypassing the configured network redaction rules.
  4. Format and write to the cache.

Modifiers may run concurrently on multiple collection threads; avoid time-consuming operations in callbacks. Callback exceptions do not interrupt data collection, and the corresponding fields retain their original values.

Privacy Configuration

TrueWatchSdk.Init(new TrueWatchConfig
{
    DatawayUrl = "https://openway.truewatch.com",
    ClientToken = "<client-token>",
    RumAppId = "<rum-app-id>",
    DataModifier = (key, value) =>
    {
        return key switch
        {
            "user_email" => "<redacted>",
            "phone" => "<redacted>",
            _ => null
        };
    },
    LineDataModifier = (measurement, data) =>
    {
        if (measurement == "error" && data.ContainsKey("error_message"))
        {
            return new Dictionary<string, object?>
            {
                ["error_message"] = "<redacted-error>"
            };
        }
        return null;
    },
    Privacy = new RumPrivacyConfig
    {
        CaptureHttpHeaders = true,
        CaptureUrlQueryString = true,
        RedactAllUrlQueryValues = false,
        RedactedValue = "<redacted>",
        RedactedHeaderNames = new[]
        {
            "Authorization",
            "Cookie",
            "Set-Cookie",
            "X-Api-Key"
        },
        RedactedQueryParameterNames = new[]
        {
            "token",
            "password",
            "secret"
        }
    }
});
Parameter Default Description
CaptureHttpHeaders true Whether to record redacted request and response headers.
CaptureUrlQueryString true Whether to keep the URL Query. When disabled, the entire Query is removed.
RedactAllUrlQueryValues false Whether to hide all Query values.
RedactedValue <redacted> Redaction replacement text.
RedactedHeaderNames Authentication-related headers Header name list, case-insensitive.
RedactedQueryParameterNames Sensitive parameter name list Query parameter name list, case-insensitive.

Both DataModifier and LineDataModifier are optional configurations. If you only need default HTTP redaction, configure Privacy alone.

#include <cstring>

static int modify_data(
    const char* key,
    const truewatch_data_value*,
    truewatch_data_value* replacement,
    void*) {
    if (std::strcmp(key, "user_email") != 0) {
        return 0;
    }
    replacement->type = TRUEWATCH_DATA_VALUE_STRING;
    replacement->value.string_value = "<redacted>";
    return 1;
}

static void modify_line(
    const char* measurement,
    truewatch_data_item* data,
    uint32_t data_count,
    void*) {
    if (std::strcmp(measurement, "error") != 0) {
        return;
    }
    for (uint32_t index = 0; index < data_count; ++index) {
        if (std::strcmp(data[index].key, "error_message") == 0) {
            data[index].value.type = TRUEWATCH_DATA_VALUE_STRING;
            data[index].value.value.string_value = "<redacted-error>";
        }
    }
}

truewatch_sdk_config sdk_config;
truewatch_sdk_config_init(&sdk_config);
sdk_config.dataway_url = "https://openway.truewatch.com";
sdk_config.client_token = "<client-token>";
sdk_config.rum_app_id = "<rum-app-id>";
truewatch_sdk_handle rum = truewatch_sdk_init(&sdk_config);

truewatch_data_modifier_config modifiers;
truewatch_data_modifier_config_init(&modifiers);
modifiers.data_modifier = modify_data;
modifiers.line_data_modifier = modify_line;
truewatch_configure_data_modifiers(rum, &modifiers);

const char* redacted_query_names[] = {
    "token",
    "password",
    "secret"
};
const char* redacted_header_names[] = {
    "Authorization",
    "Cookie",
    "Set-Cookie",
    "X-Api-Key"
};

truewatch_rum_resource_collection_config privacy;
truewatch_rum_resource_collection_config_init(&privacy);
privacy.capture_http_headers = 1;
privacy.capture_url_query = 1;
privacy.redact_all_url_query_values = 0;
privacy.redacted_value = "<redacted>";
privacy.redacted_query_parameter_names = redacted_query_names;
privacy.redacted_query_parameter_name_count = 3;
privacy.redacted_header_names = redacted_header_names;
privacy.redacted_header_name_count = 4;

truewatch_rum_configure_resource_collection(rum, &privacy);

All Native configuration structures must first call the corresponding *_init(). HTTP privacy configuration copies the Header and Query name lists; Modifiers retain the function pointers and user_data, which must remain valid until reconfiguration or truewatch_sdk_shutdown(). Modifiers may run concurrently and must not call the same SDK Handle again.

Data Redaction

Disabling Network Data Collection

TrueWatchSdk.EnableAutomaticInstrumentation(new AutomaticInstrumentationOptions
{
    EnableHttpClient = false,
    EnableWebView = false
});

To disable only Header or Query:

Privacy = new RumPrivacyConfig
{
    CaptureHttpHeaders = false,
    CaptureUrlQueryString = false
}
truewatch_rum_resource_collection_config resource_config;
truewatch_rum_resource_collection_config_init(&resource_config);
resource_config.enabled = 0;
truewatch_rum_configure_resource_collection(rum, &resource_config);

Target Filtering

Native Resources can filter collection targets via should_collect; in C#, apply equivalent filtering in business handlers or at manual Resource boundaries. Trace Headers must be restricted to trusted services through the target allowlist in Trace Configuration.

Users, Logs, and Custom Fields

  • Do not write passwords, tokens, identity documents, payment information, or complete authentication headers.
  • User IDs should use stable identifiers or hash values permitted by your business.
  • Log content and attributes are not automatically interpreted for business-sensitive fields; redact them via Modifier or before calling AddLog().
  • Custom attributes cannot override SDK reserved fields; conflicting fields are ignored.

Session Replay Privacy

Experimental Capability

Session Replay is disabled by default and can be explicitly enabled for verification, but it remains an experimental capability. Before enabling it, you must confirm that the default policy and element-level overrides meet your business privacy requirements.

Session Replay's global privacy level, element-level overrides, and WebView2/Electron privacy boundaries are consolidated in Windows Session Replay Privacy Configuration and Privacy Overrides.