Skip to content

feat(settings): add anonymous analytics opt-out - #16763

Draft
wukko wants to merge 1 commit into
pingdotgg:mainfrom
wukko:analytics-toggle
Draft

wukko wants to merge 1 commit into
pingdotgg:mainfrom
wukko:analytics-toggle

Conversation

@wukko

@wukko wukko commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Problem

Anonymous analytics could only be disabled through an environment variable. Users should also be able to opt out from desktop, web, and mobile settings without restarting the server.

Change

Adds an Anonymous analytics toggle under Privacy in desktop/web General settings and mobile Maintenance settings.

The setting persists per environment and disables both server analytics and client usage events sent through the server. Buffered events and retries are discarded while disabled. Re-enabling resumes collection without replaying discarded events.

T3CODE_TELEMETRY_ENABLED=false still takes precedence. When it forces analytics off, the toggle is disabled and shows a notice. Selecting environments with different override states shows a disabled mixed control.

Analytics remain enabled by default.

Scope and approval

This configures the existing analytics capability, which already supports an environment-variable opt-out. The setting controls that same collection and delivery behavior without adding new collection, changing which events are collected, or changing the default.

Closes #4123.

Follow-up to the analytics disclosure fixes in #16563, #16564, and #16565.

Verification

176 tests passed, covering persistence, settings sharing, opt-out, discarded queues and retries, and re-enabling. Server, web, and mobile typechecks passed. Formatting and targeted lint passed with existing lint warnings.

Tested the toggle in the web client and iOS simulator. Mobile changes persisted on the server and appeared immediately in the web client. Checked enabled, disabled, mixed, and overridden states, including the disabled controls and override notices.

Desktop and native iOS builds passed, along with iOS/Android JavaScript exports. Android was not built natively or tested on a device.

Screenshots

Desktop

Before

desktop-web-before

Enabled

desktop-web-enabled

Overridden by an environment variable

desktop-web-environment-override

Mixed override across environments

desktop-web-mixed
Mobile

Before

mobile-ios-before

Enabled

mobile-ios-enabled

Overridden by an environment variable

mobile-ios-environment-override

Mixed override across environments

mobile-ios-mixed

Model and harness

Implemented with GPT-6 Astra and GPT-6.1-Sol. Both used the Codex harness.

@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Oct 7, 2026
Comment thread apps/server/src/telemetry/AnalyticsService.ts Outdated
@macroscopeapp

macroscopeapp Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR adds a cross-platform anonymous-analytics opt-out that changes persisted settings, environment synchronization, and server telemetry buffering and delivery behavior. An unresolved Medium-severity finding also indicates queued events may survive an opt-out and be sent after re-enabling telemetry.

Not approved because:

  • 1 blocking correctness issue found at or above your repo's Minimum Blocking Severity

Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more.

@wukko
wukko force-pushed the analytics-toggle branch from 4b7275e to 67426a9 Compare October 7, 2026 07:44
@wukko
wukko marked this pull request as draft October 7, 2026 07:53

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Why promise no opt-out telemetry while telemetry has been on the whole time? Without even a button to turn it off.

1 participant