01
Operational diagnostics
CERES uses a deployment-scoped US or EU PostHog project to understand whether the public site, capture surface, monitor and hosted export operations are working.
Browser events contain the CERES surface, Solo or Duet mode, build version, the name of a public page, fixed website interactions and coarse transitions for pairing, connection profile selection, invitation pickup, WebRTC, export and recorder finalisation. Website interactions distinguish only capture-menu opens, capture or workflow mode selections, printing the instructions and opening the CERES GitHub page. Recorder finalisation diagnostics contain only a fixed lifecycle state and stage together with bucketed sequence progress, queue depth and elapsed duration. Export media diagnostics contain only fixed encoder backend, remux decision and hardware-attempt categories together with a bucketed elapsed duration. A failure can contain a fixed diagnostic code or a sanitised JavaScript error type, allowlisted normalised technical message, normalised cause, operation stage, worker name, episode count and same-origin script coordinates. Unknown free text becomes "JavaScript error". This privacy page is excluded from page-view and website-interaction events. Hosted export logs contain a fixed operation name, outcome, HTTP status, route template, request method, deployment environment and service version together with sanitised JavaScript error details.
PostHog's cookieless server mode derives a privacy-preserving identifier during ingestion rather than using an account, session or browser-device identifier. The service may use the request IP address to derive that identifier, then discards the address before the event is processed. CERES also disables GeoIP enrichment and does not add an IP address to event properties. PostHog adds a fresh non-personal event UUID for transport de-duplication.