From f8a9d524be5e1db738c6514ae07ab61d8b3a0bef Mon Sep 17 00:00:00 2001 From: Saket Aryan Date: Tue, 15 Sep 2026 22:44:17 +0530 Subject: [PATCH] docs(openclaw): correct the anonymity claim to match how it identifies events The sweep in aa770aa6 deliberately left this page alone, reasoning that hashing the email is materially different from sending it. Reading integrations/openclaw/telemetry.ts does not support that: distinctId() is an unsalted sha256 of the account email, and Mem0 holds the emails it is derived from, so recovering the account is a table join. resolveEmail() also rewrites already-queued events onto that id, and identifyAnonymous() fires a PostHog $identify that merges the prior random id into it for good. That is pseudonymous, not anonymous, and it is the same mismatch between the stated privacy posture and the wire format that this stack exists to close. The opt-out is unchanged and still correct. Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb --- docs/integrations/openclaw.mdx | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/integrations/openclaw.mdx b/docs/integrations/openclaw.mdx index a9642d444..fd7d449d9 100644 --- a/docs/integrations/openclaw.mdx +++ b/docs/integrations/openclaw.mdx @@ -481,7 +481,9 @@ Plugin config is stored in `~/.openclaw/openclaw.json` with file permissions `0o ### Telemetry -Anonymous usage telemetry (PostHog) is enabled by default to help improve the plugin. No conversation content or memory values are included, only event counts (recall, capture, tool usage, CLI commands). +Usage telemetry (PostHog) is enabled by default to help improve the plugin. No conversation content or memory values are included, only event counts (recall, capture, tool usage, CLI commands). + +These events are **not anonymous**. OpenClaw does not send your account email the way the SDK does, but it does send an unsalted SHA-256 hash of it, falling back to a hash of the API key and then to a random per-machine id. Mem0 holds the email the hash is derived from, so the hash identifies your account rather than concealing it. The first run that resolves an account also emits a PostHog `$identify`, which permanently merges any earlier random id into that identity. To opt out, set the environment variable: