Skip to content

Privacy

The instrumentation sits in front of every tool on a server, so it can see everything the server sees. Its defaults keep what it stores to what is needed to measure and debug calls, and each step toward storing content is a choice you make in code.

In the default meta mode a call record holds the tool name, timing, outcome, error type and a redacted error message, session and request ids, the identity your resolver returns, and the sizes of the arguments and result. The arguments and result themselves are not stored.

The feedback tools store what a submitter types into a report, which is the point of them. Their tool description asks models to include only information already shared in the session and to ask the person before adding anything new.

SettingStoresDefault
mode="full"Tool arguments and results, redactedoff
meta_only_toolsExempts tools from fullnone
capture_llm_text=TruePrompts and completions passed to record_llm_call, redacted and truncatedoff
identity_resolverWhatever identity you returnnone
enricherWhatever fields you returnnone
EmbeddingSinkError, event and feedback text, plus LLM text if captured, sent to an embedding endpoint and stored with its vectornot added
FeedbackInsights(enabled=True)Usage metadata for the feedback tools, in memoryoff

capture_llm_text is separate from mode on purpose: chat text can hold anything a user typed, so recording tool payloads does not imply recording conversations.

Every path into a sink goes through the Redactor: arguments and results, exception and soft-error messages, hook output, event attributes, LLM errors and text, and text sent to an embedder. It removes values under secret-looking keys at any depth and secret-shaped strings anywhere in text. The rules are in the redaction reference.

Redaction is pattern matching, and it errs toward the formats it knows. A secret in an unfamiliar format, or personal data that is not a credential at all, passes through. For tools that handle data you must never store, keep them at meta, or exclude them from recording entirely.

Nothing is sent anywhere unless you configure a sink that sends it. The only outbound network traffic the package makes is OpenAIEmbedder’s requests, to the endpoint you give it, carrying redacted text cut to max_chars.

With DatabaseSink(retention=...), call, event and embedding rows older than the period are deleted, except calls linked to feedback and embeddings of feedback, which are kept as the evidence for a report. Feedback items themselves, in the feedback table, are kept until someone calls delete_feedback.