docs(plugins): finish the telemetry sweep across the remaining surfaces
The first pass fixed the plugin README and the module docstring but left the same claim standing everywhere else. - docs/integrations/deepseek-plugin.mdx still said "Anonymous usage events". The TS SDK's telemetryId is the raw account email, so it is not anonymous. - The pause skill told users a "minimal anonymous telemetry ping" fires while paused. Same ping, same email. Corrected in the template, which regenerates into all six hosts. - integrations/zapier-mem0/README.md advertised telemetry the app does not have: there is no telemetry code in it at all. It now says what is actually true, that its requests carry source="ZAPIER". - The data directory listing is presented as exhaustive and had gone stale against this stack's two new files, telemetry-salt and install-state.json. Also replaced the property enumeration in both the README and the docs page. Review pointed out it omitted the configured model name among others — writing a fresh exhaustive list in a PR whose whole purpose is making docs match code reproduces the defect being fixed. It now describes the shape and points at where the rule is actually enforced, so it cannot drift again. Deliberately unchanged: docs/integrations/openclaw.mdx. OpenClaw hashes the email rather than sending it, which is materially different from the plugin and the SDK, so its claim is not wrong in the same way. Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
This commit is contained in:
@@ -137,6 +137,8 @@ Local data lives in `${CLAUDE_PLUGIN_DATA}`:
|
||||
- `flush-worker.log`: whether memory creation succeeded
|
||||
- `plugin-errors.log`: hook errors (no credentials)
|
||||
- `telemetry.jsonl` / `telemetry-identity.json`: usage events and the id they are sent under
|
||||
- `telemetry-salt`: random per-install salt for the repo and session hashes
|
||||
- `install-state.json`: records that install has been counted once on this machine
|
||||
|
||||
Mem0 receives captured user messages, Claude's answers, sidekick assignments and completed responses, and changed file paths. When a failed command is recorded, extraction can also include bounded command details and results. Complete files and general tool output stay on your machine. Values that look like credentials are redacted before anything is sent.
|
||||
|
||||
@@ -146,7 +148,9 @@ Usage events (which hook ran, timing, result counts, failure types) so Mem0 can
|
||||
|
||||
**These events are not anonymous.** When an API key is configured — which installing the plugin requires — events are sent under your Mem0 account email, the same way the Python SDK and the CLI attribute theirs. Without a key they are sent under a random per-machine id.
|
||||
|
||||
What each event carries: the event name, the plugin version, the harness it ran in, your OS and Python version, timings, counts, and a coarse failure label. Repository and session identifiers are hashed with a random salt generated on your machine and never sent, so they cannot be linked back to a repository name or path.
|
||||
What each event carries: the event name, the plugin version, the harness it ran in, your OS and Python version, and per-event properties describing what happened — timings, counts, coarse outcome and failure labels, and which model was configured. Repository and session identifiers are hashed with a random salt generated on your machine, so they cannot be linked back to a repository name or path.
|
||||
|
||||
Rather than restate a list that drifts, the exact set is enforced in code: `telemetry.record` filters every property through a denylist of sensitive keys and redacts credential-shaped values. See `_PRIVATE_KEYS` in `core/telemetry.py`.
|
||||
|
||||
Prompts, memory text, queries, file paths, repository names, and API keys are never sent.
|
||||
|
||||
|
||||
@@ -7,8 +7,8 @@ disable-model-invocation: true
|
||||
# Pause memory capture
|
||||
|
||||
To pause (hooks stop capturing and sending session content; a minimal
|
||||
anonymous telemetry ping still fires at session start unless
|
||||
`MEM0_TELEMETRY=false`):
|
||||
telemetry ping still fires at session start, under your Mem0 account email,
|
||||
unless `MEM0_TELEMETRY=false`):
|
||||
|
||||
```bash
|
||||
python3 "${CLAUDE_PLUGIN_ROOT}/core/memory_cli.py" --harness "claude-code" --plugin-data-dir "${CLAUDE_PLUGIN_DATA}" pause
|
||||
|
||||
Reference in New Issue
Block a user