a month ago
Hello Railway Support,
I'm writing about project "accomplished-patience" (services: pmtravel-platform and worker).
On 2026-07-31, a commit (originally eb536f9) was pushed to the connected
GitHub repository (pmtravel-platform) that accidentally included a CSV
file (backend/datos_clientes.csv) containing real personal data of our
customers: national ID numbers (DNI), email addresses, phone numbers,
and fiscal/billing addresses.
On 2026-08-22 we rewrote the Git history with git filter-repo to
permanently remove that file, and force-pushed the cleaned history to
GitHub. The file no longer exists in any reachable commit in the repo.
However, both the pmtravel-platform and worker services were built and
deployed multiple times between 2026-07-31 and 2026-08-22, while that
commit (and later commits that still contained the file) were live. So
Railway's build cache / Docker image layers for those deployments most
likely still contain that file baked into a cached layer, even though
it's gone from git history now.
Could you please help with the following:
-
Purge/invalidate all cached build layers and any stored build
images for the pmtravel-platform and worker services that were
built from any commit between 2026-07-31 and 2026-08-22 (i.e.
anything that could still contain backend/datos_clientes.csv).
-
Confirm whether Railway retains any other deployment artifacts
(build cache, old container images, snapshots) beyond what's
visible in the dashboard, and purge those too if so.
-
Confirm once this has been done, so we can close this out on our
end for data-protection purposes.
This involves real customer PII, so we'd appreciate a prompt response.
Happy to provide deployment IDs, timestamps, or anything else needed.
Thanks,
Andres Perez — PM Travel (project accomplished-patience)
1 Replies
Status changed to Awaiting Railway Response Railway • about 2 months ago
a month ago
Deployment images on the Hobby plan are retained for 72 hours after a deployment is removed, so images from builds older than that window have already been purged automatically. Build caches (dependency caches used to speed up builds) are not persisted in the final container image. The file you mentioned would have been part of the container image itself as application source, and any image whose deployment was removed more than 72 hours ago is no longer retained. For any remaining active or recently removed deployments that may still carry the affected file, a targeted purge of build artifacts is not something available as a self-serve action, and we cannot confirm or commit to a manual purge from here.
Status changed to Awaiting User Response brody • about 2 months ago
a month ago
This thread has been marked as solved automatically due to a lack of recent activity. Please re-open this thread or create a new one if you require further assistance. Thank you!
Status changed to Solved Railway • about 1 month ago