Skip to content

Analytics and privacy

Weaver keeps your sessions, files, and agents on the machine that runs the daemon. This page lists what Weaver itself sends off that machine, what each thing contains, and how to control it.

Read this first. Weaver starts every agent in its most permissive mode today. Agents edit files and run shell commands without asking you:

  • Claude Code runs with permissionMode: "bypassPermissions".
  • Codex runs with approval policy never and sandbox danger-full-access.
  • Pi has no permission system.
  • Copilot and OpenCode (both off in production builds) approve tool requests automatically.

For Claude Code, Pi, Copilot, and OpenCode, Weaver refuses shell commands that would stop or restart its own daemon. Nothing else is blocked. Use projects you are willing to let an agent change, and review its work in the Changes tab.

Each agent talks to its own provider (Anthropic, OpenAI, and so on) with your own login. That traffic is between the agent and its provider. Weaver does not proxy it.

On by default. Turn it off in Settings (see below).

The daemon sends anonymous product events to PostHog (us.i.posthog.com). Clients never talk to PostHog directly. They report an interaction to the daemon, the daemon checks it against a closed list, and only then sends it.

Every event carries the same envelope and nothing else:

FieldValue
distinct_idA random ID created for this daemon installation. Not tied to you, your account, or your device.
uuid, timestampEvent ID and when it happened.
pix_environmentproduction, development, or test.
pix_platformweb, desktop, or mobile.
release_channelalpha or prod for packaged builds.
pix_schema_version2.
pix_activation_kindOnly on app-start events: initial or resume.
pix_sourceOnly on fork and review buttons: where you clicked (turn_pill or session_more_options).

PostHog is told not to build a person profile ($process_person_profile: false) and not to look up location from the IP address (GeoIP is disabled).

The events are names of actions, such as “a prompt was sent”, “Settings was opened”, or “the model was changed”. An event never says which model, which file, or what you typed.

The full event list

The authoritative list is PRODUCT_ANALYTICS_EVENT_NAMES in packages/protocol. The daemon drops any event not on it.

  • App starts: app_cold_started, app_warm_started
  • Work: prompt_sent, agent_work_completed
  • References: file_annotation_used (you picked an @ file), session_annotation_used (you picked a # session)
  • Buttons and tabs: fork_cta_clicked, review_cta_clicked, settings_opened, settings_closed, files_tab_opened, search_cta_clicked, new_task_cta_clicked, new_chat_cta_clicked, agent_cta_clicked, changes_tab_opened, simulator_tab_opened, terminal_tab_opened
  • Continue with another agent: continue_with_another_agent_selected, continue_with_another_agent_option_changed, continue_with_another_agent_submitted, continue_with_another_agent_navigated
  • Sessions: session_opened, session_refreshed, session_created, chat_created, latest_agent_session_opened, session_todo_changed, session_renamed, session_pinned_changed, session_archived_changed, session_done_changed, session_deleted, transcript_requested
  • Turns and queue: queued_prompt_removed, queued_prompt_copied, queued_prompt_sent, queued_prompt_steered, background_task_cancelled, agent_question_answered, turn_stop_requested, turn_force_started, force_stop_requested, stop_failure_dismissed, recovery_started, turn_retry_requested
  • Composer and settings changes: model_changed, thinking_mode_changed, thinking_level_changed, context_mode_changed, speed_mode_changed, agent_environment_changed, feature_preview_changed, attachment_limit_changed, attachment_count_limit_changed, preferred_agent_changed, new_session_worktree_changed, execution_default_changed, busy_send_default_changed, agent_history_import_changed, native_history_retention_changed, legacy_models_changed, history_refresh_requested
  • Diff summaries: diff_summary_agent_changed, diff_summary_chain_changed, diff_summary_configuration_changed, diff_summary_requested, turn_file_diff_summary_requested, diff_summary_toggled
  • MCP, sign-in, onboarding: mcp_action_started, mcp_oauth_started, mcp_oauth_redirect_submitted, mcp_oauth_cancelled, agent_logged_out, agent_setup_started, agent_provider_logged_out, onboarding_completed, onboarding_preference_changed, onboarding_readiness_requested
  • Projects and devices: project_added, project_created, path_revealed, pairing_created, remote_pairing_started, device_revoked, branch_switched
  • Browser, simulator, terminal, updates: desktop_update_requested, browser_tab_opened, browser_navigation_submitted, browser_history_navigated, browser_reloaded, browser_tab_created, browser_tab_selected, browser_tab_closed, simulator_started, simulator_quality_changed, simulator_stopped, android_emulator_install_requested, terminal_created, terminal_closed
  • Interface: sessions_panel_toggled, inspector_panel_toggled, connection_switcher_opened, daemon_connection_selected, connection_retry_requested, slash_command_selected, slash_command_submitted, attachment_picker_opened, attachment_added, attachment_preview_opened, attachment_removed, session_search_result_opened, session_filter_menu_opened, session_filter_changed, session_list_view_changed, session_group_toggled, project_folder_actions_opened, project_catalog_changed, project_browser_navigated, session_page_requested, worktree_path_copied, session_id_copied, project_selected, scratch_workspace_selected, project_folder_selected, settings_section_opened, workspace_menu_opened, session_actions_opened, composer_settings_opened, composer_agent_changed, busy_delivery_changed, context_usage_opened, notice_dismissed, session_reference_removed, session_preference_changed
  • Content: message_copied, file_reference_opened, session_reference_opened, external_link_opened, artifact_opened, artifact_download_clicked, tool_details_toggled, diff_details_toggled, diff_fullscreen_opened, feedback_opened, feedback_submitted, changed_file_opened, changes_projection_changed, changes_refreshed, changes_view_preference_changed, changes_disclosure_toggled, file_view_changed, file_view_closed, project_file_opened, file_tree_toggled, diff_view_preference_changed, simulator_fullscreen_opened, simulator_fullscreen_closed, simulator_platform_changed, simulator_device_selected, terminal_tab_selected, support_link_opened, licenses_opened, license_source_opened
  • Usage and debug panes: quota_view_changed, quota_refresh_requested, quota_reset_requested, usage_range_changed, usage_chart_metric_changed, debug_processes_refreshed, debug_process_kill_requested, debug_cleanup_requested

If you use the Pix relay and analytics are on, the daemon also sends a relay_usage_sampled event. It goes out at widening usage milestones or after 24 more hours of use, not on every connection. It carries the month and four counts: estimated request units, connection requests, WebSocket messages, and bytes transferred. It has no route ID, device ID, session ID, IP address, or message content.

Separately from analytics, the daemon asks PostHog which features are switched on (for example, which agents are enabled). This request uses a different random ID from the analytics one, plus the environment and platform. It runs even when analytics are off, because it controls what the app shows.

Release builds of the daemon, the desktop app, and the mobile app send crash and error reports to Sentry. There is no setting for this, and the analytics switch does not affect it.

Before a report leaves the machine, Weaver:

  • drops breadcrumbs, request data, user data, extra data, the server name, and performance traces
  • keeps only app, OS, device, and runtime context
  • does not attach local variables or screenshots
  • replaces your home directory with <home> and any /Users/<name> or /home/<name> with <user>
  • replaces URLs with [redacted-url]
  • redacts bearer tokens, anything assigned to a key named like token, secret, password, api_key, or authorization, and provider keys that start with sk-, ghp_, github_pat_, xox?-, or sntrys_

Type /feedback (also /bug, /bug-report, or /pix-feedback) to open the feedback dialog. Nothing is sent until you click Send feedback.

A report contains:

  • your message and whether it is a bug or a feature request
  • a screenshot of the window (on by default; untick it to leave it out)
  • up to four images or videos you attach, 10 MB each
  • if you send it from a session: the session transcript as Markdown (up to 4 MB) and the session’s raw log file (up to 8 MB)
  • the last 512 KB of the daemon log
  • app and device info: daemon and client versions and build IDs, OS and CPU, Node version, client kind and name, device ID, session ID, agent, and model

The whole report is capped at 18 MiB. Media that does not fit is dropped and the report says so.

The daemon log is scrubbed with the same rules as crash reports. The transcript and raw log are sent as they are. They can contain your prompts, the agent’s output, file paths, and code from that session. Review the session before you send.

Reports go to the Weaver team’s private storage: a private Cloudflare R2 bucket, linked from an issue in a private GitHub repository. Download links for the evidence are unguessable and expire.

If a device reaches your daemon through the Pix relay, the relay forwards encrypted frames it cannot read. It sees IP addresses, connection timing, a route identifier, and traffic sizes. It stores no messages. See Pairing and remote access.

The daemon listens on all network interfaces and announces itself on the local network over Bonjour with its version, an instance ID, and your machine’s host name. Connections still need a paired device’s credential or the local owner token.

No analytics event or crash report contains your prompts, transcripts, agent output, file contents, file paths, diffs, tool arguments, command lines, agent name, model ID, device name, app version, or location. The only path that sends session content is a feedback report you choose to submit.

  • Desktop: Settings → General → Privacy & analytics → turn off Anonymous analytics.
  • iPhone or iPad: Settings → Privacy & Analytics → turn off Anonymous analytics.

The setting belongs to the daemon, not the device. Turning it off from any client stops product events and relay usage checkpoints for every client of that daemon, at once. It does not stop feature-flag requests or crash reports.

The daemon keeps everything in one data directory. Set PIX_DATA_DIR to move it.

macOSLinux
Data~/.pix${XDG_DATA_HOME:-~/.local/share}/pix
Owner token~/.pix/tokeninside the data directory
Service logs~/Library/Logs/PIX${XDG_STATE_HOME:-~/.local/state}/pix
Cache~/Library/Caches/pix${XDG_CACHE_HOME:-~/.cache}/pix
Daemon runtimes${XDG_DATA_HOME:-~/.local/share}/pix-runtime
Service definition~/Library/LaunchAgents/com.ritesh.pix.daemon.plist~/.config/systemd/user/pix-daemon.service

Inside the data directory:

PathWhat it holds
sessions/<id>.jsonlThe log of each session: every prompt, message, tool call, and result. This is the source of truth.
index.dbA SQLite index of sessions for the list and search.
blobs/Attachments and large payloads referenced from logs.
worktrees/Git worktrees Weaver creates for tasks.
logs/daemon.logThe daemon’s own log (rotated to daemon.log.1).
projects.json, settings.json, settings-profile.json, diff-summary-settings.jsonYour projects and settings.
agent-env.jsonEnvironment variables you set per agent. Often holds tokens. Owner-only file.
devices.json, device-verifier.keyPaired devices. Their credentials are encrypted with the key.
telemetry.jsonThe random analytics and feature-flag IDs and your analytics choice. Owner-only file.
remote-relay-identity.json, remote-relay-usage.jsonThe daemon’s relay identity and the local relay usage meter.
feedback-identity.jsonThe key the daemon uses to sign feedback uploads.
daemon-idThis daemon’s identity.

Treat the data directory, the token file, and agent-env.json as secrets. Each agent also keeps its own files in its own directory (for example ~/.claude, ~/.codex, ~/.pi). Weaver does not move them.