From 0d37619f24ef94f5f9cfbe3bbc18e04e1c53f0e4 Mon Sep 17 00:00:00 2001 From: Saket Aryan Date: Tue, 15 Sep 2026 00:17:26 +0530 Subject: [PATCH] fix(plugins): say what telemetry actually sends, and salt the hashes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The plugin README promises "anonymous usage events" and the telemetry module's docstring says it sends only "salted hashes". Neither is true. resolve_distinct_id() exchanges the API key for the account email and sends that as the distinct_id on every event. Installing the plugin requires an API key, so this is nearly every user. That is probably the behaviour we want — the Python SDK and the CLI attribute the same way — but the description has to match it. repo_hash and session_hash were unsalted SHA-256 cut to 16 hex characters. repo.identity is a git remote URL, or `local:` when there is no remote, which normally contains the account username. Sixteen unsalted hex characters over that input space is enumerable, so the hash was not a privacy control at all. Salted per install, with the salt kept in the identity file. That preserves every within-account join the analytics actually use and gives up only cross-machine joins on the same repository, which nothing computes. Since the distinct_id is already the email, the hash was never buying privacy from us — only from whoever obtains the data later, which is exactly what the salt fixes. Also corrects deepseek-plugin's README and source comment, which told readers ZAPIER and STRANDS were already in the backend's KNOWN_EVENT_SOURCES allowlist. Neither was. Adds a Telemetry section to docs/integrations/claude-code.mdx, which had none. Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb --- docs/integrations/claude-code.mdx | 25 ++++++++++++ .../agent-plugin-core/python/telemetry.py | 40 +++++++++++++++++-- .../antigravity-plugin/core/telemetry.py | 40 +++++++++++++++++-- integrations/claude-code-plugin/README.md | 10 ++++- .../claude-code-plugin/core/telemetry.py | 40 +++++++++++++++++-- integrations/codex-plugin/core/telemetry.py | 40 +++++++++++++++++-- integrations/cursor-plugin/core/telemetry.py | 40 +++++++++++++++++-- integrations/deepseek-plugin/README.md | 4 +- integrations/deepseek-plugin/src/index.ts | 6 +-- integrations/kimi-plugin/core/telemetry.py | 40 +++++++++++++++++-- .../mem0-agent-plugin/core/telemetry.py | 40 +++++++++++++++++-- integrations/mem0-strands/README.md | 8 ++-- 12 files changed, 294 insertions(+), 39 deletions(-) diff --git a/docs/integrations/claude-code.mdx b/docs/integrations/claude-code.mdx index 0b8e5a328..c4b5a2c35 100644 --- a/docs/integrations/claude-code.mdx +++ b/docs/integrations/claude-code.mdx @@ -172,6 +172,31 @@ claude plugin update mem0@mem0-plugins --scope user | Sidekick won't start | Must be in a Git repo. Check that your Claude Code version supports plugin agents and worktrees. | | Remove the plugin | `claude plugin uninstall mem0@mem0-plugins` | +## Telemetry + +The plugin sends usage events (which hook ran, timing, result counts, failure +types) so Mem0 can see what's used and what's breaking. + +These events are **not anonymous**. When an API key is configured, which +installing the plugin requires, they are sent under your Mem0 account email, +the same way the Python SDK and the CLI attribute theirs. Without a key they +are sent under a random per-machine id. + +Each event carries the event name, the plugin version, the harness it ran in, +your OS and Python version, timings, counts, and a coarse failure label. +Repository and session identifiers are hashed with a random salt generated on +your machine and never sent, so they cannot be linked back to a repository name +or path. + +Prompts, memory text, queries, file paths, repository names, and API keys are +never sent. + +Turn it off: + +```bash +export MEM0_TELEMETRY=false +``` + Detailed MCP configuration for all clients diff --git a/integrations/agent-plugin-core/python/telemetry.py b/integrations/agent-plugin-core/python/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/agent-plugin-core/python/telemetry.py +++ b/integrations/agent-plugin-core/python/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/antigravity-plugin/core/telemetry.py b/integrations/antigravity-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/antigravity-plugin/core/telemetry.py +++ b/integrations/antigravity-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/claude-code-plugin/README.md b/integrations/claude-code-plugin/README.md index 130460b17..872071abe 100644 --- a/integrations/claude-code-plugin/README.md +++ b/integrations/claude-code-plugin/README.md @@ -136,13 +136,19 @@ Local data lives in `${CLAUDE_PLUGIN_DATA}`: - `pending/`: sessions waiting to be sent to Mem0 (retried after interruption) - `flush-worker.log`: whether memory creation succeeded - `plugin-errors.log`: hook errors (no credentials) -- `telemetry.jsonl` / `telemetry-identity.json`: anonymous usage events +- `telemetry.jsonl` / `telemetry-identity.json`: usage events and the id they are sent under Mem0 receives captured user messages, Claude's answers, sidekick assignments and completed responses, and changed file paths. When a failed command is recorded, extraction can also include bounded command details and results. Complete files and general tool output stay on your machine. Values that look like credentials are redacted before anything is sent. ## Telemetry -Anonymous usage events (which hook ran, timing, result counts, failure types) so Mem0 can identify what's used and what's breaking. Repo and session IDs are hashed before leaving your machine. Prompts, memory text, file paths, tool output, and API keys are never sent. +Usage events (which hook ran, timing, result counts, failure types) so Mem0 can identify what's used and what's breaking. + +**These events are not anonymous.** When an API key is configured — which installing the plugin requires — events are sent under your Mem0 account email, the same way the Python SDK and the CLI attribute theirs. Without a key they are sent under a random per-machine id. + +What each event carries: the event name, the plugin version, the harness it ran in, your OS and Python version, timings, counts, and a coarse failure label. Repository and session identifiers are hashed with a random salt generated on your machine and never sent, so they cannot be linked back to a repository name or path. + +Prompts, memory text, queries, file paths, repository names, and API keys are never sent. Turn it off: diff --git a/integrations/claude-code-plugin/core/telemetry.py b/integrations/claude-code-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/claude-code-plugin/core/telemetry.py +++ b/integrations/claude-code-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/codex-plugin/core/telemetry.py b/integrations/codex-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/codex-plugin/core/telemetry.py +++ b/integrations/codex-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/cursor-plugin/core/telemetry.py b/integrations/cursor-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/cursor-plugin/core/telemetry.py +++ b/integrations/cursor-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/deepseek-plugin/README.md b/integrations/deepseek-plugin/README.md index 93e5f563f..bcd333311 100644 --- a/integrations/deepseek-plugin/README.md +++ b/integrations/deepseek-plugin/README.md @@ -86,9 +86,9 @@ Per-call `userId` overrides are rejected unless the operator enables `allowUserO ## Telemetry -Writes are tagged `source="DEEPSEEK_HARNESS"` so Mem0's backend can attribute usage to this integration. For it to surface by name (rather than bucketing into `OTHERS`), `DEEPSEEK_HARNESS` must be present in the backend's `KNOWN_EVENT_SOURCES` allowlist, a one-line platform change matching the existing `ZAPIER` / `STRANDS` sources. +Writes are tagged `source="DEEPSEEK_HARNESS"`, which the Mem0 backend recognizes so usage surfaces by name rather than bucketing into `OTHERS`. -The plugin also sends anonymous usage events (which tool ran, duration, result counts, coarse failure kind) so Mem0 can tell how the plugin is used and where it breaks. Queries, memory text, and entity ids are never sent. Turn it off with `MEM0_TELEMETRY=false`. +The plugin also sends usage events (which tool ran, duration, result counts, coarse failure kind) so Mem0 can tell how the plugin is used and where it breaks. These are **not anonymous**: when an API key is configured they are sent under your Mem0 account email, the same way the SDK attributes its own. Queries, memory text, and entity ids are never sent. Turn it off with `MEM0_TELEMETRY=false`. ## Status diff --git a/integrations/deepseek-plugin/src/index.ts b/integrations/deepseek-plugin/src/index.ts index bea70c02c..2d24b498a 100644 --- a/integrations/deepseek-plugin/src/index.ts +++ b/integrations/deepseek-plugin/src/index.ts @@ -26,10 +26,8 @@ export const name = "mem0"; export const inject = ["tools", "systemPrompt"]; // Tags writes so Mem0's backend attributes them to this integration in -// telemetry. The backend keeps recognized values via its KNOWN_EVENT_SOURCES -// allowlist; unknown values bucket into "OTHERS", so "DEEPSEEK_HARNESS" must be -// added to that allowlist for usage to surface by name (a one-line backend PR, -// same pattern as the ZAPIER / STRANDS sources). +// telemetry. The backend's KNOWN_EVENT_SOURCES allowlist recognizes this value; +// anything outside it buckets into "OTHERS". const SOURCE = "DEEPSEEK_HARNESS"; const DEFAULT_SEARCH_LIMIT = 10; diff --git a/integrations/kimi-plugin/core/telemetry.py b/integrations/kimi-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/kimi-plugin/core/telemetry.py +++ b/integrations/kimi-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/mem0-agent-plugin/core/telemetry.py b/integrations/mem0-agent-plugin/core/telemetry.py index 249595475..1b6bd854e 100644 --- a/integrations/mem0-agent-plugin/core/telemetry.py +++ b/integrations/mem0-agent-plugin/core/telemetry.py @@ -1,5 +1,9 @@ #!/usr/bin/env python3 -"""Anonymous usage telemetry for Mem0 agent plugins. +"""Usage telemetry for Mem0 agent plugins. + +Events are linked to your Mem0 account email when an API key is configured, and +to a random per-machine id otherwise. Not anonymous — the Python SDK and CLI +attribute the same way. Hooks run on a 3-6 second budget and fire on every tool call, so recording never touches the network: `record` appends one JSON line to a local spool and returns. @@ -9,7 +13,8 @@ started once per session and again from the flush worker that is already detache Pure stdlib, matching the rest of the plugin. Opt out with MEM0_TELEMETRY=false. Never sends prompts, memory text, queries, file paths, repository names, or API -keys: only event names, durations, counts, coarse outcomes, and salted hashes. +keys: only event names, durations, counts, coarse outcomes, and repo/session +identifiers hashed with a random per-install salt. """ from __future__ import annotations @@ -83,9 +88,36 @@ def is_enabled() -> bool: def _digest(value: str, length: int = 16) -> str: + """Unsalted digest. Only for values that are already secrets (API keys).""" return hashlib.sha256(value.encode("utf-8")).hexdigest()[:length] +def _install_salt() -> str: + """Random per-install salt, created on first use and kept in the identity file.""" + identity = _read_identity() + salt = identity.get("salt") + if not salt: + salt = uuid.uuid4().hex + identity["salt"] = salt + _write_identity(identity) + return salt + + +def _scoped_digest(value: str, length: int = 16) -> str: + """Salted digest for values drawn from a guessable space. + + repo.identity is a git remote URL, or ``local:`` when there is + no remote — which normally contains the account username. Sixteen unsalted + hex characters over that input space is enumerable, so this is not a + privacy control without the salt. Salting per install keeps every + within-account join the analytics actually use and gives up only + cross-machine joins on the same repository, which nothing computes. + """ + if not value: + return "" + return hashlib.sha256(f"{_install_salt()}:{value}".encode("utf-8")).hexdigest()[:length] + + def _safe_value(value: Any) -> Any: if isinstance(value, str): return memory_core.redact(value) @@ -175,9 +207,9 @@ def record( python_version=platform.python_version(), ) if repo is not None: - properties["repo_hash"] = _digest(getattr(repo, "identity", "")) + properties["repo_hash"] = _scoped_digest(getattr(repo, "identity", "")) if session_id: - properties["session_hash"] = _digest(session_id) + properties["session_hash"] = _scoped_digest(session_id) line = json.dumps( { "event": f"{EVENT_PREFIX}.{event}", diff --git a/integrations/mem0-strands/README.md b/integrations/mem0-strands/README.md index f45d98e44..8ea4ecacc 100644 --- a/integrations/mem0-strands/README.md +++ b/integrations/mem0-strands/README.md @@ -79,9 +79,11 @@ the tool share one Mem0 backend and namespace. ## Telemetry -The store sends anonymous usage events (store configuration, operation, duration, -result counts, coarse failure kind) over the Mem0 SDK's existing telemetry client, -tagged `source="STRANDS"`. Queries, memory text, message content, entity ids, and +The store sends usage events (store configuration, operation, duration, result +counts, coarse failure kind) over the Mem0 SDK's existing telemetry client, +tagged `source="STRANDS"`. These are **not anonymous**: when an API key is +configured they are sent under your Mem0 account email, the same way the SDK +attributes its own. Queries, memory text, message content, entity ids, and metadata are never sent. Turn it off with `MEM0_TELEMETRY=false`. ## Development