Browse documentationData collection

Data collection

Collection is controlled per source. This lets the same product use different rules for its app and website while keeping both under one product name.

Products and sources

A product groups related software. An App source measures installations, releases, app activity, and app errors. A Website source measures visitors, sessions, page views, and the actions you explicitly track.

Each source keeps its own key, history, settings, events, and analytics. Adding a website to an existing product does not mix website visitors into app retention. Moving a source to another product keeps its source ID, key, history, and collection settings.

Collection settings

New sources start with usage and errors or reports enabled. Country and device details start disabled. An organization owner can change these settings or turn all collection off.

SettingWhat it controls
Usage eventsPage views, app activity, custom events, and their properties.
Errors and reportsError events and submitted reports, including manual reports and their attachments.
CountryVital's inferred country field. It is not GPS or a home address.
Device detailsOptional OS and version, device or model, browser and version, locale, and time zone.

Platform, app version, build, and release or debug channel remain available when optional device details are off. Policy changes can take up to one minute to reach every key cache. They apply to future ingestion and do not erase records that Vital already accepted.

Server policy and client consent

A source policy decides what Vital accepts and stores. Disabled categories are discarded before their events or reports are written. This protects the source even if an older client keeps sending requests.

Consent in the client decides what leaves the device or browser. Vital's website client can start disabled, can be turned off later, and honors Global Privacy Control and Do Not Track. The supported Rust app client has separate controls for usage and automatic errors. Your app still owns the consent screen and when those controls change.

Custom data needs its own rules

Country and device switches cover Vital's standard fields. They do not inspect every custom property, error message, report description, screenshot, or attachment for similar details. Do not put information in custom content when your product has chosen not to collect it.

The website client rejects common sensitive property names and some obviously private value formats, but a filter cannot understand the meaning of every field. Keep custom events small and deliberate. Never send passwords, tokens, contact details, form contents, private URLs, or account identifiers.

Website identity

The website client sets no cookies and uses no local storage, session storage, or persistent browser identifier. Vital uses the request IP and user agent transiently to make a daily salted visitor identifier and assign website sessions. The raw connection IP is not stored in website analytics.

Country and device switches do not change that daily identity step because network headers still exist on a web request. If collection must stop in the browser, disable the client through the consent flow as well as changing the source policy.