> ## Documentation Index
> Fetch the complete documentation index at: https://docs.open4rena.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Telemetry and privacy

> What o4 sends, what it never sends, and how to turn telemetry off.

o4 runs on your machine. Your code, prompts and the model's replies go to the model provider you use, and to other services only through tools, MCP servers and hooks (see [Other network requests](#other-network-requests)). o4 doesn't send them to Open4rena. o4 also has anonymous telemetry, which is on by default: it records usage events in a file on your machine and sends one small daily ping. This page lists exactly what that covers, the other network requests o4 makes, and how to turn telemetry off.

## Turn telemetry off

Any one of these turns off both the local events and the daily ping:

<Tabs>
  <Tab title="Settings file">
    Set `telemetry_enabled` to `false` in `~/.o4/settings.json`:

    ```json theme={null}
    {
      "telemetry_enabled": false
    }
    ```

    This keeps it off for every session. A project's `.o4/settings.json` can set it too, and the project value wins in a [trusted workspace](/safety/workspace-trust), so a trusted project can turn telemetry back on for sessions started there. The environment variables below turn it off whatever either file says.

    <Warning>
      If `settings.json` isn't valid JSON, or any value in it has the wrong type or an unknown choice, o4 ignores the whole file without a message, and telemetry is back on. Check the file after you edit it by hand, or use `O4_TELEMETRY=0` as well. See the [configuration reference](/reference/configuration#settings-json).
    </Warning>
  </Tab>

  <Tab title="Environment variable">
    Set `O4_TELEMETRY=0` to turn telemetry off for that process:

    ```bash theme={null}
    export O4_TELEMETRY=0
    ```

    `O4_TELEMETRY` also accepts `false`, `off`, `no` and `disabled`. `O4_TELEMETRY_DISABLED=1` does the same (it also accepts `true`, `on`, `yes` and `enabled`). Either variable turns telemetry off even if your settings turn it on.
  </Tab>
</Tabs>

There's no telemetry switch in `/config` and no command-line flag for it; use one of the methods above.

## What o4 records locally

While telemetry is on, each session in the terminal interface appends events to `~/.o4/telemetry/events.jsonl`, one JSON object per line. Print mode (`o4 -p`) and the other subcommands don't record events. This file stays on your machine unless you set `O4_TELEMETRY_ENDPOINT` (see [Sending events to your own endpoint](#sending-events-to-your-own-endpoint)).

| Event | Fields |
| - | - |
| `session_start` | The provider and model ID. |
| `tool_use` | The tool name, and whether the call succeeded. For an MCP tool, the name includes the server name, such as `docs__search`. |
| `error` | An error category: `timeout`, `network`, `auth`, `rate_limit`, `permission`, `tool_error` or `unknown`. Not the error message. |
| `retry` | The attempt number, the maximum number of attempts, and the error category. |
| `session_end` | The session's duration in seconds and its number of turns. Written when you quit o4. |

Every event also has a `timestamp` and the `session_id` of the o4 session it came from. For example:

```json theme={null}
{"event":"session_start","provider":"anthropic","model":"claude-haiku-4-5-20251001","timestamp":"2026-09-25T05:59:21.921214+00:00","session_id":"e8650f72-d1d7-4af5-82cb-e9b7dd2497bd"}
{"event":"tool_use","tool":"read","success":true,"timestamp":"2026-09-25T06:00:03.114502+00:00","session_id":"e8650f72-d1d7-4af5-82cb-e9b7dd2497bd"}
```

The **Session** tab of `/stats` totals the events in this file across all your sessions. With telemetry off, nothing new is added to it, so `/stats` shows only what was recorded before, or `No telemetry data recorded yet.` See [Context and cost](/guides/context-and-cost).

## The daily ping

At most once every 20 hours, when a session starts in the terminal interface, o4 sends one HTTPS request to `https://t.open4rena.ai/p` with exactly these four fields:

| Field | Value |
| - | - |
| `id` | A random install ID, created the first time o4 sends a ping. It isn't derived from your machine. |
| `version` | The o4 version, for example `0.2.74`. |
| `os` | Your operating system, for example `macos` or `linux`. |
| `arch` | Your CPU architecture, for example `aarch64` or `x86_64`. |

The install ID is stored in `~/.o4/telemetry/install_id`. Delete that file to get a new one. The time of the last ping is stored in `~/.o4/telemetry/last_ping`. o4 records the time before it sends, and the ping is fire-and-forget: if it fails, for example because you're offline, o4 doesn't show an error and doesn't try again for another 20 hours.

## What o4 never collects

Telemetry never includes your code or file contents, prompts, the model's replies, file paths or file names, API keys, or error messages.

## Sending events to your own endpoint

If you set `O4_TELEMETRY_ENDPOINT` to a URL, o4 also uploads the local events to it. Every 5 minutes, and once more when the session ends, o4 sends the contents of `events.jsonl` as a JSON POST with the body `{"events": [...]}`. After a successful upload, it empties the file. If the upload fails, the events stay in the file for the next attempt. o4 doesn't wait for the upload at the end of a session, so if o4 exits before it finishes, those events go out with a later upload.

```bash theme={null}
export O4_TELEMETRY_ENDPOINT=https://telemetry.example.com/o4
```

Nothing is uploaded when `O4_TELEMETRY_ENDPOINT` is unset, which is the default, or when telemetry is off.

`O4_PING_ENDPOINT` changes where the daily ping goes, for example to a mirror on a network without internet access.

## Other network requests

Apart from telemetry and your model providers, o4 connects to these services. None of them receive your code or prompts.

| When | Destination | What for |
| - | - | - |
| When a session starts in the terminal interface and the model catalog hasn't been refreshed for 7 days, and when you choose **Refresh catalog** in `/config model` or run `/models-update` | `raw.githubusercontent.com` (the `Open4rena/o4-models` repository) | Downloads the model catalog, the list of models and their details, into `~/.o4/catalog/`. |
| The first time you run a session or a print-mode prompt, if you have no plugin marketplaces yet | `github.com` (`Open4rena/o4-marketplace`) | Registers the official plugin marketplace. o4 tries once and doesn't retry. |
| When you search for or add an MCP server with `o4 mcp search`, `o4 mcp add` or `/mcp` | `registry.modelcontextprotocol.io` | Looks up servers in the MCP registry. |
| When the model runs a package install command such as `npm install <package>` or `cargo add <crate>` | `api.osv.dev`, and `registry.npmjs.org` for npm packages | Checks the packages for known vulnerabilities before the command runs. Results are cached. |
| When you install a plugin or add or refresh a marketplace | The Git host you name | Clones or updates the plugin or marketplace. |

The model's own tools also make requests when it uses them: `fetch` and `web_fetch` download the URLs it asks for, `web_search` queries Brave Search, Tavily or DuckDuckGo depending on which keys you've set, and `remote_trigger` posts a prompt, with your o4 session ID in an `X-O4-Session` header, to the URL the model names. o4 asks you before every `remote_trigger` call. MCP servers and [hooks](/extend/hooks) you configure can make their own requests. See [Tools](/reference/tools).

o4 doesn't check for updates. To update, reinstall it; see [Install o4](/installation).

## Model providers

Your prompts, the conversation, file contents the model reads, and tool results are sent to the provider of the model you're using, such as Anthropic, OpenAI or a local Ollama server. o4 also sends some requests to that same provider in the background, for example to summarize a session when it ends. What the provider does with that data is covered by your agreement with that provider. o4 sends model traffic only to providers you've configured. See [Providers and API keys](/models/providers).
