Log retention and data processing agreement (GDPR)
maralina1x1
HOBBYOP

14 hours ago

Hi, I run a mobile app backend on Railway (Hobby plan) and need written answers for my GDPR privacy policy.

I found this reply for another project: logs are kept 7 days on Hobby, not configurable, and no deletion on request. Is that the actual storage/deletion period for runtime, HTTP, deploy and build logs, or are logs stored longer and only hidden in the dashboard?

Which physical location does the "EU West" region correspond to (Amsterdam, Ireland, Frankfurt)?

Thank you.

BR!

Awaiting User Response

3 Replies

Railway
BOT

14 hours ago

The 7-day figure on Hobby is how far back the dashboard lets you view logs (3 days on Free, 30 on Pro). It is not when logs are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically. Individual log entries cannot be deleted early or on request, and that 90-day expiry is the same for every plan.

EU West is Amsterdam, Netherlands. That region decides where your services and their attached volumes run, and volume backups stay in the same region. Logs are different: all logs are stored in US West, wherever the service is deployed.

For subprocessors and contract terms, see our DPA and the subprocessor list.


Status changed to Awaiting User Response Railway • about 14 hours ago


Railway

The 7-day figure on Hobby is how far back the dashboard lets you view logs (3 days on Free, 30 on Pro). It is not when logs are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically. Individual log entries cannot be deleted early or on request, and that 90-day expiry is the same for every plan. EU West is Amsterdam, Netherlands. That region decides where your services and their attached volumes run, and volume backups stay in the same region. Logs are different: all logs are stored in US West, wherever the service is deployed. For subprocessors and contract terms, see our [DPA](https://railway.com/legal/dpa) and the [subprocessor list](https://trust.railway.com/item/subprocessors).

maralina1x1
HOBBYOP

14 hours ago

Thanks. Two automated answers contradict each other, so I need a confirmation from a human on the Railway team.

A reply in another thread ("Data protection questions — encryption at rest, log retention…") says logs are retained 7 days on Hobby. Your reply here says the 7 days is only dashboard visibility and that all logs are stored 90 days and then deleted. Which is correct?

You say logs are always stored in US West, even when the service runs in EU West. Does the DPA at railway.com/legal/dpa (with Standard Contractual Clauses) cover those logs, including IP addresses in the HTTP logs?

Can HTTP logs be configured so that client IP addresses are not stored?

I need a written answer for my GDPR privacy policy. Thank you.


Status changed to Awaiting Railway Response Railway • about 14 hours ago


sam-a
EMPLOYEE

9 hours ago

The 90-day figure is correct. On Hobby, 7 days is how far back you can view logs in the dashboard, not when they are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically, on every plan. Logs cannot be deleted earlier, individually or on request.

All of those logs are stored in US West, including for services deployed in EU West (Amsterdam, Netherlands). The published DPA is the only data processing agreement we offer, and it is not amended or supplemented for individual customers. The subprocessor list and our Trust Center cover the rest of the published material.

HTTP logs record the client source IP address for every request, and there is no setting to turn that off or anonymize it. Those entries follow the same 90-day expiry as other logs.


Status changed to Awaiting User Response sam-a • about 9 hours ago


Welcome!

Sign in to your Railway account to join the conversation.

Loading...