> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apsio.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and security

> What Apsio collects, where it is stored, how tenants are kept apart, and how keys and tokens work.

## What is collected

The SDK sends diagnostics about your app: crashes, hangs, sessions, performance and network
timings, plus the logs, errors and attributes your code adds. It leaves request bodies, query
strings and advertising or vendor identifiers on the phone. The full list is in
[Privacy and consent](/concepts/privacy).

Apsio does not store the IP address of the devices that send data.

## Where it is stored

During early access, everything is stored in one region, US East: the application servers,
the telemetry store and object storage, including uploaded symbols. The EU comes next, when
the first customer needs it. Apps send to a host of their own (`<app key>.ingest.apsio.cloud`),
so moving an app to another region needs no app release.

## Tenants kept apart

* Each organization reads the telemetry store as its own database user, limited by row
  policies to its own data. A query for one organization cannot return another's rows, even if
  Apsio's application code is wrong.
* Symbols are stored per project. One project never uses another project's symbols.

## Keys and tokens

| | What it is | Secret |
| - | - | - |
| App key | Routes an app's data to its project. It ships inside the app | No. It can only send data, and you can rotate and revoke it |
| Project token | Reads one project through the [read API](/read-api) | Yes. Keep it in your CI's secrets, never in the app or the repository |
| Upload token | Uploads symbols for one project and reads nothing | Yes. Keep it in your CI's secrets or in `apsio login`, never in the app or the repository |

A project token reads exactly one project, expires after at most 7 days, and can be revoked.
Project tokens are issued by the console, which is not available yet. The upload token will
become a project token from the console when it ships.

## Retention

Each plan sets how long detail (spans, logs, screens) and crashes with release health are
kept. See [Pricing](/pricing).

## Policies

* [Privacy policy](https://apsio.io/privacy) (draft)
* [Data processing agreement](https://apsio.io/dpa) (draft)
* [Security](https://apsio.io/security), including how to report a vulnerability


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.