# Claude Code Data usage and privacy

> Claude Code: Training policy, retention, local plaintext, telemetry, feedback, WebFetch checks, cloud execution and gateway boundaries.

URL: https://docs.passion8.cc/en/docs/claude-code/data-usage
Language: en
Publisher: Passion8

This page describes local, cloud, account, provider and Passion8 data flows. Formal Anthropic, provider and Passion8 policies govern legal terms.




Any tool result, terminal output, MCP response, file excerpt, screenshot or log added to a session may enter model requests. Avoid raw secrets, bulk customer data and production logs.




## Training policy

| User type | Official default | Consideration |
| --- | --- | --- |
| Free/Pro/Max | Users choose model-improvement participation | Applies to Code using those accounts |
| Team/Enterprise | No generative-model training under commercial terms by default | Explicit organizational opt-in exceptions |
| Anthropic API | No training by default | Explicit programs can opt in |
| Bedrock/Vertex/Foundry | Provider and commercial terms | Check cloud logs and encryption too |
| Passion8/custom gateway | Depends on gateway and upstream chain | Review provider, gateway and your logging together |

## Retention

| Data | Official explanation | Action |
| --- | --- | --- |
| Consumer improvement enabled | May be kept longer for improvement/safety | Manage account privacy settings |
| Consumer improvement disabled | Generally shorter retention | Does not clear local transcripts |
| Commercial/API | Generally shorter commercial retention | Ask about ZDR eligibility |
| Feedback submissions | Feedback/transcripts may be retained longer | Submit only when needed and redact |
| Session ratings | Rating alone is not transcript upload | Transcript sharing is a separate choice |
| Local transcripts | Plaintext under ~/.claude/projects/ | Configure cleanupPeriodDays; clean sensitive projects |




Local and server retention are separate. Even strict server policy leaves recoverable sessions, logs, configuration and state locally.




## Local data flows

Code runs locally but sends model requests to the selected provider.

| Data | Sent when | Control |
| --- | --- | --- |
| User prompt | Each model request | Avoid sensitive raw input |
| Assistant output | Included as continuing history | Clear or start a new session |
| Read excerpts | Tool results enter context | Deny rules, hooks and bounded reads |
| Bash output | Added to context | Filter secrets and lengthy logs |
| MCP output | Returned into context | Server filtering and MAX_MCP_OUTPUT_TOKENS |
| Images/PDFs | Request inputs | Crop/compress and avoid sensitive captures |
| WebFetch content | After retrieval | Permissions and domain allowlists |

Passion8 requests pass through the gateway to an upstream. Inspect client output, gateway console and provider status for costs, caches, logs and errors.

## Cloud execution

Web Code, Routines and cloud sessions run in hosted environments, not your local shell.

| Item | Local | Cloud |
| --- | --- | --- |
| Code | Local repository | Clone in an isolated VM |
| Credentials | Local environment/files | Cloud connectors and authorization proxies |
| Network | Local network | Cloud proxy/allowlists |
| Local files | Permission-controlled access | No automatic access to unuploaded files |
| Passion8 variables | Available in local shell | Not automatically inherited |

Use local Code for LAN services, private databases or uncommitted files unless cloud access is explicitly configured.

## Telemetry, Sentry and feedback

| Mechanism | Default behavior | Disable with |
| --- | --- | --- |
| Telemetry | Official paths collect reliability/usage signals | DISABLE_TELEMETRY=1 |
| Sentry | Error reporting may be enabled | DISABLE_ERROR_REPORTING=1 |
| /feedback | User submission may include history/code | DISABLE_FEEDBACK_COMMAND=1 |
| Quality survey | Rating; transcript sharing separate | CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1 |
| Nonessential traffic | Broad optional-egress control | CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 |

Defaults can differ on cloud providers or proxies. Deliver enterprise variables/policy consistently rather than relying on individual memory.

## WebFetch domain checks

Preflight sends the hostname, not the complete URL, path or page content, and briefly caches the result by hostname.

| Need | Configuration |
| --- | --- |
| Default checks | Keep defaults |
| Cannot reach api.anthropic.com | Allow access or configure skipWebFetchPreflight |
| Restrict external domains | WebFetch(domain:...) permissions |
| Prevent shell bypass | Restrict curl/wget or use hooks/sandbox |

Disabling preflight causes direct URL access attempts; domain permissions become more important.

## Local plaintext data

Code stores resume, project and diagnostic state locally:

| Location | Content |
| --- | --- |
| ~/.claude/projects/ | Transcripts, state and resumable sessions |
| ~/.claude.json | Application/project/login/MCP-related state |
| ~/.claude/feedback-bundles/ | Local third-party-provider feedback bundles |
| Project .claude/ | Team settings, commands, skills, agents and styles |

Cleanup recommendations:

```bash
claude project purge
```

Shorten cleanup periods for sensitive projects:

```json title="~/.claude/settings.json"
{
  "cleanupPeriodDays": 7
}
```

Do not commit ~/.claude/ or settings.local.json.

## Passion8 recommendations

| Risk | Recommendation |
| --- | --- |
| Key exposure | User environment, not project settings |
| Gateway logs | Keep secrets, customer originals and large logs out of requests |
| Cache fields | Verify forwarding; see [gateway](https://docs.passion8.cc/en/docs/claude-code/gateway) |
| MCP data | Read-only databases with bounded fields/rows |
| Team governance | Permissions/hooks for sensitive paths |
| External pages | Explicit WebFetch allowlist |

## Caching and privacy

Cache TTL is a reuse window, not a privacy or transcript-retention boundary. Five minutes or one hour does not describe all server/local retention.

| Concept | Meaning |
| --- | --- |
| Prompt cache | Provider prefix-reuse window |
| Local transcript | Plaintext resume history |
| Server retention | Account/policy-dependent request retention |
| Gateway logs | Passion8/custom gateway records |

See [prompt caching](https://docs.passion8.cc/en/docs/claude-code/prompt-caching).
For enterprise retention evaluation, see [ZDR](https://docs.passion8.cc/en/docs/claude-code/zero-data-retention).

## Official references

- [Data usage](https://code.claude.com/docs/en/data-usage.md)
- [Zero data retention](https://code.claude.com/docs/en/zero-data-retention.md)
- [Explore the .claude directory](https://code.claude.com/docs/en/claude-directory.md)
- [Monitoring with OpenTelemetry](https://code.claude.com/docs/en/monitoring-usage.md)
- [Permissions](https://code.claude.com/docs/en/permissions.md)
- [Prompt caching](https://code.claude.com/docs/en/prompt-caching.md)
