ADR 0009: A built-in error log instead of a hosted tracker
Status: accepted
Decision
Unexpected server errors (5xx) and failed background jobs are written to app_errors, sanitized (emails, keys and long tokens masked; route patterns only, never ids or bodies) and purged after ERROR_LOG_RETENTION_DAYS. Admins see them in Settings → Recent errors. Structured logs (pino) remain the full record.
Why not Sentry
No third party ever receives users' data, and self-hosters get error visibility without creating an account anywhere.