Privacy
What Duct sends
Duct can send one small anonymous report a day, so Tensflare knows which versions, features and file types are used. This page lists every field. Your documents never leave your computer.
Your choice
- Turn it on or off in Settings › General, or run
duct telemetry onorduct telemetry off. Off means no request is made at all. DO_NOT_TRACK=1orDUCT_TELEMETRY=0turn it off whatever the setting. It never runs in CI or tests.- In the EU and EEA, nothing is sent unless you turn it on.
- See the exact report before it’s sent: Settings › General › What Duct sends, or
duct telemetry show.
Every field
Every number is a range, not an exact count. The install id is random and never linked to an account, even when you’re signed in.
| Field | Example | Why we need it |
|---|---|---|
schema | 1 | Lets the format change safely |
install_id | a random id made on your device | Counts active installs without knowing who they are. A new one is made if you turn usage counts off and on again |
day | 2026-10-08 (UTC date, no time) | Daily and weekly active installs |
event | install or daily | New installs versus returning ones |
app_version, channel | 0.3.0, desktop (or cli, server, docker) | Which releases and surfaces are used |
os, os_version, arch | macos, 15, arm64 | Where to test and package |
language | en (interface language only) | Which translations to add |
plan | free, pro, team or enterprise | Conversion between plans |
documents | 101-1000 (ranges: 0, 1-10, 11-100, 101-1000, 1001-10000, 10000+) | How big real libraries are |
formats | ["pdf", "docx", "xlsx"] (format names present, no counts) | Which readers matter |
sources | { "watched": "2-5", "library": true, "web": false } | How people add documents |
activity | { "searches": "11-100", "opens": "1-10", "ask": "0", "ocr": "0" } (ranges, previous day) | Whether Duct is used, and which features |
settings | { "search_mode": "hybrid", "embeddings": "local", "island": true, "sounds": false } | Which defaults to keep. Embeddings are only none, local or cloud |
errors | { "extract_failed.pdf": "1-10" } (codes from a fixed list, no messages) | Which formats fail most often |
days_since_install | 8-30 | Retention |
Never sent
Document text or snippets, file or folder names, paths, search queries or questions, document metadata (titles, authors, email subjects or addresses), web addresses you indexed, account or organisation ids, hardware serials, or exact counts and times.
How it’s handled
- At most one report a day, sent a few minutes after Duct starts, never at launch. If it fails, it is dropped, not retried.
- IP addresses are used only to limit abuse and are never stored or logged.
- Raw reports are deleted after 90 days; daily totals after 13 months. They are kept apart from account data.
- The report is built in one open-source file, src/telemetry.ts, and a test fails if any file name, path or word from your documents appears in it.