Does Bugsnag Work in China? Error-Data Residency, PIPL & Your Crash Reports
Bugsnag — now shipped by SmartBear as Insight Hub — operates no data center inside mainland China; its own Security Overview says its data centers are "based in the United States." So the crash and error reports it collects from your Chinese users, carrying client IPs, user IDs and breadcrumbs, come to rest offshore — a cross-border transfer of personal information under PIPL. A compliance-first look at where your error data lands.
Does Bugsnag work in China?
Yes — Bugsnag reaches mainland China and will happily ingest from it; that is the half that was never in doubt. Bugsnag, now shipped by SmartBear as Insight Hub, operates no data center inside the mainland — its own Security Overview says it uses data centers "based in the United States" — so every crash and error report you collect in China comes to rest on a US backend. That is a cross-border transfer of personal information, not a speed problem.
An error report is rarely anonymous. Bugsnag's browser SDK documentation says "The client's IP address is collected by default and used in both the user identifier and Request tab on the dashboard," it generates a user ID and device ID per report, "Breadcrumbs are stored and sent with each event report," and once you identify a user it carries the "user ID, email and name" you supply. Gathered from mainland users and sent offshore, that personal information is a cross-border transfer PIPL governs — notice, a separate consent and one transfer mechanism (Articles 38–40) — and for a CIIO or large-volume handler it must be stored in China (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). SmartBear's own sub-processor list hosts data only in the US and Ireland; none of it is in the mainland.
This is a risk map, not a ruling — what actually applies turns on what your error reports carry, your data volumes, and who your users are. Our China team can map your exposure with you →
What Bugsnag's own documentation says about China
| Fact | Primary source |
|---|---|
| Bugsnag operates no data center inside mainland China. Its own Security Overview states "We use data centers based in the United States," and that "BugSnag servers are hosted on the Google Cloud Platform (GCP) in facilities compliant with leading security standards." SmartBear's current sub-processor list names Amazon AWS (USA, Ireland) and Microsoft Azure (USA) as the vendors that host customer data. There is no mainland-China region to choose, so the crash and error reports you collect in China are stored on a backend outside the country. | Bugsnag — Security Overview (docs.bugsnag.com) and SmartBear Subprocessors (smartbear.com), retrieved 2026-10-09 |
| The crash reports Bugsnag collects are personal information. Bugsnag's browser SDK documentation says "The client's IP address is collected by default and used in both the user identifier and Request tab on the dashboard" (disable with collectUserIp: false); across platforms it generates a user ID and device ID per report, and "Breadcrumbs are stored and sent with each event report." Identify a user and the report carries the "user ID, email and name" you supply, alongside the failed request's URL, headers and body. Collected from mainland users and sent to a US backend, that is a cross-border transfer of personal information under PIPL — notice, separate consent and a transfer mechanism (Articles 38–40). | Bugsnag — Customizing error reports and App Store / Play Store privacy (docs.bugsnag.com), retrieved 2026-10-09; PIPL Articles 38–40 |
| Bugsnag offers no way to keep the data in the mainland. Every Bugsnag data center — and every data-hosting vendor on SmartBear's sub-processor list (AWS in the USA and Ireland, Azure in the USA) — sits outside mainland China. For a critical information infrastructure operator or a large-volume handler, personal information collected in China must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)) — a data-residency duty Bugsnag's offshore-only data centers cannot satisfy. | SmartBear Subprocessors (smartbear.com) and Bugsnag Security Overview (docs.bugsnag.com), retrieved 2026-10-09; PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) |
| Reachability is the easy half — Bugsnag is a backend, and you are the data handler. Bugsnag's docs identify each customer as "the data controller," so the PIPL duty rides with you, not the vendor. The dashboard loads from inside China; the exposure is where the reports are stored. The ICP filing (State Council Order No. 292; MIIT Order No. 33) attaches to the public mainland site or app you operate — and to any China-facing dashboard you host in the mainland — not to Bugsnag as a backend service. (Bugsnag is now shipped by SmartBear as Insight Hub.) | Bugsnag — App Store / Play Store privacy (docs.bugsnag.com), retrieved 2026-10-09; State Council Order No. 292; MIIT Order No. 33 |
Sources verified by the 21YunBox compliance team on 2026-10-09.
For a team shipping to mainland China, the question about Bugsnag is almost never whether the dashboard opens — it does. The question is where the crash and error reports it gathers are allowed to come to rest. Bugsnag — the error-monitoring tool SmartBear now ships as Insight Hub — answers that in its own security documentation: its data centers are in the United States. So the notifier embedded in your mainland app, and the browser SDK loaded for your mainland visitors, capture crashes, stack traces, breadcrumbs and user context in China and send them to a US backend. Because an error report routinely carries personal information — a client IP address, a generated user ID, an email you attached, the failed request itself — moving it offshore is a cross-border transfer China’s law governs. Connecting to Bugsnag is the simple part; what China’s law scrutinizes is the data those reports carry out of the country.
Bugsnag in China at a glance
| What decides it | In Bugsnag's own terms — and China's law |
|---|---|
| Where the reports come to rest | Bugsnag's Security Overview says “We use data centers based in the United States,” with servers “hosted on the Google Cloud Platform (GCP).” SmartBear's sub-processor list names the data-hosting vendors as Amazon AWS (USA, Ireland) and Microsoft Azure (USA). None is in mainland China. |
| What a report contains | For the browser SDK, “The client's IP address is collected by default and used in both the user identifier and Request tab on the dashboard.” Across platforms Bugsnag generates a user ID and device ID per report, “Breadcrumbs are stored and sent with each event report,” and set a user and it carries the “user ID, email and name” you supply. |
| Is that personal information? | A single mainland visitor's client IP already is. Request bodies and breadcrumbs can sweep in more — up to Article 28 sensitive personal information if left unscrubbed. Collected in China and sent to a US backend, it is a cross-border transfer PIPL governs. |
| Residency duty | For a critical information infrastructure operator or a large-volume handler, personal information collected in China must stay in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). Every Bugsnag data center is offshore, so there is nothing on Bugsnag to meet it. |
| Is it reachable? | Yes — the dashboard and the ingestion endpoints answer from inside China. What is at stake is where the reports come to rest, not whether they get through. |
Bugsnag operates no mainland data center, so your reports come to rest offshore
Bugsnag’s Security Overview states plainly that “We use data centers based in the United States,” and that “BugSnag servers are hosted on the Google Cloud Platform (GCP) in facilities compliant with leading security standards.” SmartBear — Bugsnag’s parent since the 2021 acquisition, and the company that now ships the product as Insight Hub — lists the sub-processors that host customer data as Amazon AWS (in the USA and Ireland) and Microsoft Azure (in the USA). The product page names Google Cloud and the corporate sub-processor list names AWS and Azure, but the thread that matters for China is identical: every one of those data centers sits outside the mainland, and Bugsnag offers no mainland region to pick. So the notifier on your mainland servers and the SDK in your mainland visitors’ browsers collect their data in China and ship it to a US backend. Getting through to Bugsnag was never the obstacle; keeping the error data it gathers inside the country is.
A crash report is personal information — and it crosses the border
An error report is rarely anonymous. For the browser SDK that runs in your mainland visitors’ browsers, Bugsnag’s documentation says “The client’s IP address is collected by default and used in both the user identifier and Request tab on the dashboard” — so a visitor’s IP is gathered unless you set collectUserIp: false. Across platforms Bugsnag generates a user ID and a device ID for every report, “Breadcrumbs are stored and sent with each event report,” and the moment you identify a user the report carries “the user ID, email and name” you supply, alongside the failed request’s URL, headers and body. A single mainland visitor’s client IP is already personal information, and under China’s Personal Information Protection Law sending it to a US backend is a cross-border transfer — the handler (you, not Bugsnag) must give notice, obtain a separate consent for the overseas transfer, and clear one transfer mechanism: a CAC data-export security assessment, the CAC standard contract, or certification (PIPL Articles 38–40). Where a failed request body or breadcrumb carries financial-account or other sensitive personal information, PIPL Article 28 raises the bar again, with its own consent and necessity test.
Scrubbing narrows what crosses — it does not close the door
Bugsnag gives you ways to reduce what leaves: you can switch off IP collection with collectUserIp: false, discard a whole event by returning false from an onError callback, and redact chosen metadata keys. Those are worth doing. But redaction changes what crosses the border, not the fact that it crosses, and it does nothing for residency. If you are a critical information infrastructure operator or a large-volume handler, personal information collected in China has to be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — China’s 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered this data-localization provision from 37 to 39, leaving the in-country storage duty unchanged). With every Bugsnag data center offshore, there is no in-country store to meet that duty on Bugsnag alone. The ICP filing (State Council Order No. 292; MIIT Order No. 33) is a separate door: it attaches to whatever public mainland site or app you serve from inside the country — and to any China-facing status or error dashboard you host in the mainland — not to Bugsnag as a backend service.
Read this as a risk map rather than a ruling: whether you owe a transfer mechanism, in-country storage, an ICP filing, or some combination turns on what your reports actually carry, your data volumes, and your role as handler — worth settling with counsel before you wire anything up.
The lawful path — map, localize, deliver
You do not have to drop Bugsnag to get right with China. There are three moves, in order.
Map. Our China compliance team charts the lawful path for your error pipeline: which PIPL cross-border duties attach to the IPs, user IDs and request data your reports carry, whether your volumes or your role as a critical information infrastructure operator trigger in-country storage, and where an ICP filing is owed for anything you serve to mainland users.
Localize. Where error telemetry cannot lawfully leave the mainland, we put a China-legal pattern in its place — consented collection and in-country processing and storage of the personal data those reports carry — so the sensitive context never has to cross the border in the first place. You keep Bugsnag for the telemetry that can lawfully leave.
Deliver. We stand up ICP-filed, in-country delivery with the 21YunBox Optimizer, set in front of the stack you already run — no rebuild, no second codebase, no move off Bugsnag. 21YunBox never uses or suggests circumvention of any kind; every node is lawful and inside the country.
The result: your error monitoring runs legally and compliantly for your users in China.
Related reading:
- How to get an ICP filing for China
- Cross-border data transfers under PIPL
- China’s data-export security assessment measures
- China’s Cybersecurity Law
