14 hours ago
Hi, I run a mobile app backend on Railway (Hobby plan) and need written answers for my GDPR privacy policy.
I found this reply for another project: logs are kept 7 days on Hobby, not configurable, and no deletion on request. Is that the actual storage/deletion period for runtime, HTTP, deploy and build logs, or are logs stored longer and only hidden in the dashboard?
Which physical location does the "EU West" region correspond to (Amsterdam, Ireland, Frankfurt)?
Thank you.
BR!
3 Replies
14 hours ago
The 7-day figure on Hobby is how far back the dashboard lets you view logs (3 days on Free, 30 on Pro). It is not when logs are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically. Individual log entries cannot be deleted early or on request, and that 90-day expiry is the same for every plan.
EU West is Amsterdam, Netherlands. That region decides where your services and their attached volumes run, and volume backups stay in the same region. Logs are different: all logs are stored in US West, wherever the service is deployed.
For subprocessors and contract terms, see our DPA and the subprocessor list.
Status changed to Awaiting User Response Railway • about 14 hours ago
Railway
The 7-day figure on Hobby is how far back the dashboard lets you view logs (3 days on Free, 30 on Pro). It is not when logs are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically. Individual log entries cannot be deleted early or on request, and that 90-day expiry is the same for every plan. EU West is Amsterdam, Netherlands. That region decides where your services and their attached volumes run, and volume backups stay in the same region. Logs are different: all logs are stored in US West, wherever the service is deployed. For subprocessors and contract terms, see our [DPA](https://railway.com/legal/dpa) and the [subprocessor list](https://trust.railway.com/item/subprocessors).
14 hours ago
Thanks. Two automated answers contradict each other, so I need a confirmation from a human on the Railway team.
A reply in another thread ("Data protection questions — encryption at rest, log retention…") says logs are retained 7 days on Hobby. Your reply here says the 7 days is only dashboard visibility and that all logs are stored 90 days and then deleted. Which is correct?
You say logs are always stored in US West, even when the service runs in EU West. Does the DPA at railway.com/legal/dpa (with Standard Contractual Clauses) cover those logs, including IP addresses in the HTTP logs?
Can HTTP logs be configured so that client IP addresses are not stored?
I need a written answer for my GDPR privacy policy. Thank you.
Status changed to Awaiting Railway Response Railway • about 14 hours ago
9 hours ago
The 90-day figure is correct. On Hobby, 7 days is how far back you can view logs in the dashboard, not when they are deleted. Runtime, HTTP, deploy and build logs are all stored for 90 days and then deleted automatically, on every plan. Logs cannot be deleted earlier, individually or on request.
All of those logs are stored in US West, including for services deployed in EU West (Amsterdam, Netherlands). The published DPA is the only data processing agreement we offer, and it is not amended or supplemented for individual customers. The subprocessor list and our Trust Center cover the rest of the published material.
HTTP logs record the client source IP address for every request, and there is no setting to turn that off or anonymize it. Those entries follow the same 90-day expiry as other logs.
Status changed to Awaiting User Response sam-a • about 9 hours ago