Telemetry
Privacy & opt-out#
Both telemetry paths are local-first with zero network egress by default, and store aggregate counts only — never your prompts, arguments, or results. Nothing leaves your machine unless you explicitly opt in (the calibration sampler is the only off-box path, and it is off by default).
The connector-free usage host-scan#
The usage command needs no connector and writes nothing. It reads each agent CLI's own native session logs / DBs read-only, reports counts only — never your prompts or results, writes zero host config (it never runs install), and is local-first: the scan stays entirely on your machine. It is a separate read-only subsystem (src/usage/) that never collides with the serve-proxy store below.
The serve-proxy per-tool numbers#
The per-MCP / per-tool telemetry comes from the serve proxy a connector developer's own wrapped server runs — it tokenizes the server's I/O locally and stores aggregate counts only.
Scope of the "estimate" label
Reported per-tool numbers are estimates from the server's own I/O, not host-billed usage — this caveat applies specifically to the serve-proxy per-tool counts (every row carries its confidence source so an estimate is never read as exact). It is not a statement that all telemetry is approximate: the connector-freeusage scan above reports the host's own logged counts.Opt-out switches#
| Switch | Effect |
|---|---|
AGENT_CONNECTOR_TELEMETRY=0 | Global kill switch (equivalent to telemetry: { enabled: false }). |
AGENT_CONNECTOR_HOST_NATIVE=1 | Forces the opt-in host-native turn capture on at install. |
calibration.anthropicCountTokens | Opt-in only — the calibration sampler sends content off-box; off by default. |
- Aggregate counts only — never raw arguments or results are stored.
- Per-layer opt-in for measure / calibrate / host-native; the hot path never makes a network call.
- Telemetry is keyed by stable project identity (
gitRemote || normalizedAbsPath, hashed), stored under the home data-root — survivesgit clean, isn't committed.