From 45b72f72803b359906192cf073b8e5be2f04bcfa Mon Sep 17 00:00:00 2001 From: Matthew Podwysocki Date: Tue, 15 Sep 2026 13:00:02 -0400 Subject: [PATCH] README: make the collected-data list match what is sent MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three mismatches between the Privacy section's list and `telemetry::telemetry_markers`, which is the whole of what goes out: let mut markers = vec![os_marker(), arch_marker()]; markers.extend(ci_marker()); markers.extend(agent_detect::detect_agent().map(|a| format!("agent/{a}"))); markers.push(terminal_marker()); if let Some(group) = command_group { markers.push(format!("command/{group}")); } **Terminal state was collected and not disclosed**, which is the direction that matters. `terminal_marker()` sends `stdin_tty/… stdout_tty/…` on every request and the list did not mention it. Added. **Exit codes are not collected.** Removed. The User-Agent is assembled before a command runs, so there is no exit code in existence to send — nothing in `telemetry.rs` or `http.rs` reads one. **It is the service, not the command name.** The marker is set in one place, `http::client_for(Some(op.service.as_str()))` in `executor::dispatch`, so the value is `styles` or `geocoder` — never `styles list`. The old example was `auth login`, which is the one thing that cannot appear: `auth` is hand-written rather than generated, never reaches `dispatch`, and uses `client_for(None)`. The corrected phrasing keeps the distinction rather than just deleting the wrong words, because the distinction is the reassuring part: which service was used, never the operation or its arguments. Nothing else in the section is touched. Retention, third-party access, what we do not collect and the opt-out are byte-identical — checked by comparing the section sentence by sentence with whitespace collapsed, not by eye. Some lines rewrap around the edit; no other wording moves. --- README.md | 21 +++++++++++---------- 1 file changed, 11 insertions(+), 10 deletions(-) diff --git a/README.md b/README.md index 56e42b5..6442c5a 100644 --- a/README.md +++ b/README.md @@ -343,16 +343,17 @@ never checks at all. Mapbox collects telemetry data from our CLIs to better understand how our tools are used and how to improve our products. -- **What Telemetry Data We Collect:** Usage metrics include installs, - Mapbox API-related command names (e.g. `auth login`), exit codes, CLI - version, OS/architecture, an identifier for the detected AI coding agent - (if any) running the command (based on signals such as the presence of - the `CLAUDECODE` or `COPILOT_MODEL` environment variable; see - [`agent_detect.rs`](./src/agent_detect.rs) for the complete, versioned - list), and a boolean flag indicating whether the command was run in a CI - environment. IP addresses necessarily accompany any request made to our - server, but will not be retained and analyzed together with telemetry - data. +- **What Telemetry Data We Collect:** Usage metrics include installs, the + service a Mapbox API command belongs to (e.g. `styles` or `geocoder`, + never the operation or its arguments), CLI version, OS/architecture, + whether stdin and stdout are attached to a terminal, an identifier for + the detected AI coding agent (if any) running the command (based on + signals such as the presence of the `CLAUDECODE` or `COPILOT_MODEL` + environment variable; see [`agent_detect.rs`](./src/agent_detect.rs) for + the complete, versioned list), and a boolean flag indicating whether the + command was run in a CI environment. IP addresses necessarily accompany + any request made to our server, but will not be retained and analyzed + together with telemetry data. - **Why We Collect It:** For internal analytics by Mapbox to understand adoption, prioritize investments, and improve the reliability, performance, and developer experience of our CLIs.