Telemetry and privacy
What the cua SDK, the cua CLI, cua daemon, cua-spacesd and the Cua Spaces app collect, what they never collect, and how to turn it off.
What the cua SDK, the cua CLI, cua daemon, cua-spacesd and the Cua Spaces app collect, what they never collect, and how to turn it off.
Cua sends anonymous usage data so we can see which features are used and where things break. It never contains your content. You can see every event before or after it is sent, and turn it off with one switch.
Any of these turns usage telemetry off for every Cua program on the machine
(SDK in any language, cua CLI, cua daemon, the Spaces app, and Cua Driver):
| Switch | Scope |
|---|---|
DO_NOT_TRACK=1 | This environment. Wins over everything. |
CUA_TELEMETRY=0 | This environment. CUA_TELEMETRY=1 turns it back on. |
cua telemetry off or cua config set telemetry off | This machine ([telemetry] enabled = "off" in $CUA_HOME/config.toml). |
| Spaces app: "Share anonymous usage data" on the first run's Welcome page, or Settings, Privacy | Same setting as above. |
SDK: cua.telemetry.disable() (Python), telemetrySetEnabled(false) (TypeScript, Swift, Kotlin) | Same setting as above. |
CI environments (CI, GITHUB_ACTIONS, BUILDKITE, ...) are off by default.
CUA_TELEMETRY=1 turns them on, and their events are marked is_ci.
The older CUA_TELEMETRY_ENABLED=false and CUA_DRIVER_RS_TELEMETRY_ENABLED=false
still work.
cua telemetry status # on or off, why, and the properties every event carries
cua telemetry show-last # the last events, exactly as sent
cua telemetry schema # every event and property, with its allowed values
cua telemetry reset-id # a new anonymous install idNothing is sent from a machine until the first-run notice has been shown there once (in the terminal, or in the Spaces app's onboarding or Settings). The process that shows it sends nothing. In the Spaces app the notice is on the first run's Welcome page, next to a "Share anonymous usage data" switch: nothing is queued or sent until you leave that page, and if you turn the switch off there, nothing is sent at all (the setting is saved for every Cua program on the machine).
$CUA_HOME/telemetry/install_id, created
on the first event actually sent, never while telemetry is off. It is not
derived from your machine or account. reset-id deletes it.$process_person_profile: false
and $geoip_disable: true. Like any HTTPS request, the upload reaches
PostHog (EU) from your IP address; it is never an event property and is
not used for location.custom; an app outside the public teleport catalog
as other; an error as its category (not_found, timeout), never its message.
An event with any other property or value is dropped before it is queued.A fixed set of events with closed-vocabulary properties. The full list, each property and why it is collected: Telemetry events.
These are the questions the events answer, and nothing else:
The activation funnel joins events on the anonymous install id, in order:
app launched (cua_onboarding_step app_launched), first run completed
(onboarding_completed), signed in (signed_in), first Space created
(first_space_created), first Space ready (first_space_ready), first
teleport (first_teleport) and first agent run (first_agent_run). The
first_* steps are sent once per install. Retention counts installs with a
cua_app_active event on day 1, 7 and 30 after their first one.
File paths, file names, usernames, hostnames, IP addresses, emails, window titles, URLs, clipboard, keystrokes or typed text, screenshots, screen or accessibility content, prompts, model output, sandbox or Space names, error messages, and anything stored in the Keyvault (only consent decisions are counted). Tests enforce this: every event builder is fed paths, emails, hostnames and window titles, and none may appear in a payload.