From 2874e396d506e4c4a83d8270cd88cec961ecf0dc Mon Sep 17 00:00:00 2001 From: Mofei Zhu <13761509829@163.com> Date: Tue, 15 Sep 2026 07:04:08 +0300 Subject: [PATCH 1/3] Tell the user we collect telemetry when install finishes Points to the CLI's README for the full explanation and how to opt out with MAPBOX_CLI_NO_TELEMETRY=1. Skipped when telemetry is already off. --- scripts/install.ps1 | 12 ++++++++++++ scripts/install.sh | 13 +++++++++++++ 2 files changed, 25 insertions(+) diff --git a/scripts/install.ps1 b/scripts/install.ps1 index 0ef900b..75d6ac0 100644 --- a/scripts/install.ps1 +++ b/scripts/install.ps1 @@ -546,6 +546,18 @@ Windows 11 on Arm has and Windows 10 on Arm does not. Write-Host " note the copy it replaced is still running; $asideNote is deleted next time" } + # Said once, here, rather than on every future command: someone piping + # this into `iex` is not going to read the man page before their first + # run. Skipped when telemetry is already off, since there's nothing to + # opt out of. + if ($TelemetryAllowed) { + Write-Host '' + Write-Host 'mapbox collects telemetry - installs, command names, exit codes, CLI' + Write-Host 'version, OS/architecture, and more. Turn it off any time:' + Write-Host '$env:MAPBOX_CLI_NO_TELEMETRY = "1"' + Write-Host "Details: $Repo#telemetry" + } + # --- PATH ---------------------------------------------------------- # Resolved before this session's PATH is touched below, so what it diff --git a/scripts/install.sh b/scripts/install.sh index 17627ef..fbaad14 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -426,6 +426,19 @@ if [ -n "$previous_version" ] && [ "$previous_version" != "$installed_version" ] echo " replaced ${previous_version}" fi +# Said once, here, rather than on every future command: someone piping this +# into `sh` is not going to read the man page before their first run. +# Skipped when telemetry is already off, since there's nothing to opt out of. +if telemetry_allowed; then + cat < Date: Tue, 15 Sep 2026 07:17:33 +0300 Subject: [PATCH 2/3] Point the install-time telemetry notice at the oss repo's Privacy section Shorten the message and link straight to https://github.com/mapbox/mapbox-cli#privacy instead of $REPO/$Repo, since that variable's placeholder value doesn't point at the real repo. --- README.md | 46 +++++++++++++++++++++++++++++++++++---------- scripts/install.ps1 | 5 ++--- scripts/install.sh | 5 ++--- 3 files changed, 40 insertions(+), 16 deletions(-) diff --git a/README.md b/README.md index 7d272fc..56e42b5 100644 --- a/README.md +++ b/README.md @@ -338,18 +338,44 @@ never checks at all. ### Privacy -Mapbox collects telemetry from this CLI, on by default, to understand -adoption and improve reliability, performance and developer experience: +**YOUR PRIVACY - COLLECTION OF TELEMETRY** + +Mapbox collects telemetry data from our CLIs to better understand how our +tools are used and how to improve our products. + +- **What Telemetry Data We Collect:** Usage metrics include installs, + Mapbox API-related command names (e.g. `auth login`), exit codes, CLI + version, OS/architecture, an identifier for the detected AI coding agent + (if any) running the command (based on signals such as the presence of + the `CLAUDECODE` or `COPILOT_MODEL` environment variable; see + [`agent_detect.rs`](./src/agent_detect.rs) for the complete, versioned + list), and a boolean flag indicating whether the command was run in a CI + environment. IP addresses necessarily accompany any request made to our + server, but will not be retained and analyzed together with telemetry + data. +- **Why We Collect It:** For internal analytics by Mapbox to understand + adoption, prioritize investments, and improve the reliability, + performance, and developer experience of our CLIs. +- **What We Do Not Collect:** Code completion outputs, source code, project + file names, directory contents, non-Mapbox API keys, or credentials. +- **Who has Access:** Telemetry data will not be disclosed to, or accessed + by, third parties other than Mapbox affiliates and passive cloud storage + and hosting providers necessary to maintain our infrastructure. + +This also covers [update notices](#update-notices) above, since that check +rides the same opt-out. + +**How to Opt Out:** The collection of telemetry data is enabled by default. +You can disable it at any time and without affecting the functionality of +our CLIs by setting -| | | -| --- | --- | -| What | Added to the `User-Agent` every request already carries: `os/`, `arch/`, `env/ci` when running in CI, `agent/` when a known coding-agent environment is detected, whether stdin/stdout are attached to a terminal, and — for a generated API command — `command/` (e.g. `styles`, `geocoder`), never the operation or its arguments. Every request also carries the IP address it's sent from, which is not retained alongside telemetry. | -| What it never includes | AI prompts, code completion output, source code, project or directory names, command arguments, non-Mapbox API keys or credentials. | -| Who sees it | Mapbox only — never disclosed to third parties, aside from the cloud storage and hosting providers that keep the infrastructure running. | -| Off | `MAPBOX_CLI_NO_TELEMETRY=1` — also silences [update notices](#update-notices) above, since that check rides the same opt-out. | +```sh +MAPBOX_CLI_NO_TELEMETRY=1 +``` -See the [Mapbox Privacy Policy](https://www.mapbox.com/legal/privacy) for -how this fits into data processing generally, and your rights over it. +For additional information on our data processing activities and your +related rights, please see our Mapbox +[Privacy Policy](https://www.mapbox.com/legal/privacy). ## Uninstall diff --git a/scripts/install.ps1 b/scripts/install.ps1 index 75d6ac0..e0c8d13 100644 --- a/scripts/install.ps1 +++ b/scripts/install.ps1 @@ -552,10 +552,9 @@ Windows 11 on Arm has and Windows 10 on Arm does not. # opt out of. if ($TelemetryAllowed) { Write-Host '' - Write-Host 'mapbox collects telemetry - installs, command names, exit codes, CLI' - Write-Host 'version, OS/architecture, and more. Turn it off any time:' + Write-Host 'mapbox collects telemetry. Turn it off any time:' Write-Host '$env:MAPBOX_CLI_NO_TELEMETRY = "1"' - Write-Host "Details: $Repo#telemetry" + Write-Host 'Details: https://github.com/mapbox/mapbox-cli#privacy' } # --- PATH ---------------------------------------------------------- diff --git a/scripts/install.sh b/scripts/install.sh index fbaad14..9ad71a3 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -432,10 +432,9 @@ fi if telemetry_allowed; then cat < Date: Tue, 15 Sep 2026 10:09:26 +0300 Subject: [PATCH 3/3] Rewrite the install-time telemetry notice for accuracy Matches the wording review feedback asked for: states the default plainly, names the exact env var and when to set it, and separates the pointer to more detail rather than bundling it with the opt-out line. --- scripts/install.ps1 | 7 ++++--- scripts/install.sh | 7 ++++--- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/scripts/install.ps1 b/scripts/install.ps1 index e0c8d13..69fbf21 100644 --- a/scripts/install.ps1 +++ b/scripts/install.ps1 @@ -552,9 +552,10 @@ Windows 11 on Arm has and Windows 10 on Arm does not. # opt out of. if ($TelemetryAllowed) { Write-Host '' - Write-Host 'mapbox collects telemetry. Turn it off any time:' - Write-Host '$env:MAPBOX_CLI_NO_TELEMETRY = "1"' - Write-Host 'Details: https://github.com/mapbox/mapbox-cli#privacy' + Write-Host 'Mapbox CLI collects telemetry by default. To disable it, set' + Write-Host 'MAPBOX_CLI_NO_TELEMETRY=1 before running CLI commands.' + Write-Host '' + Write-Host 'Learn more: https://github.com/mapbox/mapbox-cli#privacy' } # --- PATH ---------------------------------------------------------- diff --git a/scripts/install.sh b/scripts/install.sh index 9ad71a3..2ebda94 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -432,9 +432,10 @@ fi if telemetry_allowed; then cat <