Data usage
What Claude Code sends where: training policy by plan, retention periods, local transcripts, encryption, telemetry streams and the defaults per provider.
When a client's security team asks "where does our code go?", this is the page I send them. It covers whether your data trains models, how long it is kept, what lives on your own disk, and every background stream Claude Code can send, with the switch for each.
Training
| Who you are | Is your Claude Code data used for training? |
|---|---|
| Consumer: Free, Pro and Max | Only if you leave the model improvement setting on. Usage through Claude Code counts |
| Commercial: Team, Enterprise, API, third-party platforms, Claude Gov | No. Code and prompts sent under commercial terms are not used to train generative models unless the customer chooses to share them |
The way a commercial customer opts in is the Development Partner Program. An organisation admin can enrol the organisation explicitly, and the materials it provides may then be used for training. It is only offered on Anthropic's first-party API, not on Amazon Bedrock or Google Cloud's Agent Platform.
Feedback and surveys
/feedback, /bug and /share
All three send through the same path. Whatever you submit, including the transcript, may be used to improve Anthropic's products and is retained for five years. In the feedback dialog you choose how much history goes with it: the current session (the default), or other sessions from the same project over the past 24 hours or 7 days.
Claude can also draft a feedback report for you (see Tools reference). The draft waits on your machine and nothing is sent until you choose to send it, at which point it follows the same path and retention.
The data travels over TLS and lands in Google Cloud Storage, encrypted at rest; optionally a GitHub issue is opened in the public repository. Set DISABLE_FEEDBACK_COMMAND=1 to turn the command off.
On Bedrock, Agent Platform, or with no Anthropic credentials at all, /feedback instead writes a local archive under ~/.claude/feedback-bundles/ with known key and token patterns redacted. Nothing leaves until you send that file to your account representative or attach it to a support ticket.
Session quality survey
The "How is Claude doing this session?" prompt records only your rating, even if you choose Dismiss. No transcript or session content is attached.
It may be followed by a separate optional question asking whether Anthropic can look at the transcript:
- Yes uploads the conversation, any subagent transcripts and the raw session log. Known key and token patterns are redacted, but code and other content go as-is. Kept for up to six months. On Bedrock, Agent Platform, Microsoft Foundry and signed-in Claude apps gateway sessions, Yes writes a local archive under
~/.claude/feedback-bundles/instead of uploading. - No sends nothing.
- Don't ask again sends nothing and suppresses the question in future.
Organisations with zero data retention, with product feedback disabled by policy, or with CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC set never see the follow-up. Survey responses and shared transcripts do not change your training preference and cannot be used for training.
Survey controls:
CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1turns it off. So doDISABLE_TELEMETRY,DO_NOT_TRACKandCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC.CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL=1brings it back for organisations that block nonessential traffic but collect responses through their own OpenTelemetry collector. Ratings then go only to the collector, and the transcript question stays off.feedbackSurveyRatein settings (a probability from0to1) tunes how often it appears. See the settings reference.
Retention
Consumer plans
- Model improvement on: retained for five years.
- Model improvement off: retained for 30 days.
- Change it any time in your claude.ai privacy settings.
Commercial plans
- Standard retention is 30 days.
- Zero data retention is available to qualifying Claude for Enterprise accounts. It is not part of the standard plan; your account team enables it per organisation after checking eligibility.
On your machine
Claude Code keeps session transcripts in plain text under ~/.claude/projects/ for 30 days so you can resume sessions. Change that with cleanupPeriodDays. Sessions last started or continued in Claude Desktop or Cowork are exempt from that clean-up by default. The .claude directory lists what is stored and how to clear it.
Cloud sessions can be deleted at any time, which permanently removes their event data; see Claude Code on the web.
Where data goes
Local sessions
Claude Code runs on your machine and sends your prompts and the model's output over the network, encrypted in transit with TLS 1.2 or later. It works with most VPNs and LLM proxies. In normal use it talks to: the distribution server for installs and updates; Anthropic for authentication and the API; and, optionally, telemetry and error reporting endpoints plus Google Cloud Storage (and GitHub) for feedback.
Encryption at rest depends on the provider:
| Provider | At rest |
|---|---|
| Anthropic API | AES-256 disk encryption at infrastructure level; zero data retention means no server-side persistence |
| Amazon Bedrock | AES-256 with AWS-managed keys; customer-managed keys through AWS KMS |
| Google Cloud's Agent Platform | Google-managed keys; CMEK available |
| Microsoft Foundry | Depends on hosting. Hosted on Azure keeps prompts and completions in Azure, with only usage metadata and safety-flagged content going to Anthropic. Hosted on Anthropic routes to Anthropic infrastructure with AES-256 disk encryption |
Remote Control follows the local flow because execution is local, but while connected the transcript is also stored on Anthropic servers to sync devices.
Cloud sessions
Cloud sessions run in Anthropic-managed VMs unless routed to a self-hosted environment. In Anthropic-hosted sessions:
- your repository is cloned into an isolated VM, and the transcript is stored so you can return to it, under your account type's retention rules;
- GitHub credentials stay encrypted on Anthropic's servers and are attached by a proxy, never entering the VM;
- all outbound traffic passes a security proxy for audit logging and abuse prevention;
- prompts, changes and outputs follow the same policies as local use.
Claude only accesses the repository you started the session in, not every repository you have connected. More in Security.
Telemetry streams
Claude Code has two operational streams, each with its own switch. CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC turns off all nonessential traffic at once.
| Stream | Contents | Destination | Switch |
|---|---|---|---|
| Metrics | Latency, reliability, usage patterns. Never code, prompts or file paths | Anthropic and third-party logging, over TLS | DISABLE_TELEMETRY=1 |
| Error reports | Error messages and stack traces from Claude Code itself, with secrets, paths, emails and other personal data redacted first | Third-party error tracking, over TLS | DISABLE_ERROR_REPORTING=1 |
Error reporting is only active when all four hold: you sign in with Pro or Max, you run v2.1.198 or later, you connect directly to the Claude API, and your organisation has no zero data retention or HIPAA agreement.
Note:
DISABLE_TELEMETRYandCLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFICalso switch off feature-flag evaluation, which can make Remote Control unavailable.DISABLE_ERROR_REPORTINGdoes not.
Defaults by provider
On Bedrock, Agent Platform, Microsoft Foundry and Claude Platform on AWS, metrics, error reports and /feedback are off by default. Session quality surveys and the WebFetch safety check run whatever the provider. In a signed-in Claude apps gateway session, usage analytics, error reporting and survey ratings to Anthropic are disabled by the gateway credential and cannot be re-enabled.
| Stream | Claude API | Bedrock, Agent Platform, Foundry, Claude Platform on AWS |
|---|---|---|
| Metrics | On; DISABLE_TELEMETRY=1 to stop | Off when the provider variable (CLAUDE_CODE_USE_BEDROCK, CLAUDE_CODE_USE_VERTEX, CLAUDE_CODE_USE_FOUNDRY or CLAUDE_CODE_USE_ANTHROPIC_AWS) is 1 |
| Error reports | On for Pro and Max on v2.1.198+, otherwise off; DISABLE_ERROR_REPORTING=1 to stop | Off when the provider variable is 1 |
/feedback reports | On; DISABLE_FEEDBACK_COMMAND=1 to stop | Off when the provider variable is 1 |
| Session quality surveys | On; CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1 to stop | On; same switch |
| WebFetch safety check | On; skipWebFetchPreflight: true to stop | On; same switch |
Any of these environment variables can live in the env block of settings.json (see Settings). CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC does not touch the WebFetch check or the official plugin marketplace auto-install; the latter has its own switch, CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL.
If a host platform embedding Claude Code sets CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST, metrics default to on for those four providers and obey DISABLE_TELEMETRY; error reports and /feedback stay off.
The WebFetch domain safety check
Before WebFetch retrieves a URL, it sends just the hostname (no path, no page content) to api.anthropic.com to check it against Anthropic's safety blocklist. A hostname that passes is cached for five minutes; a blocked or failed one is checked again next time.
It runs on every provider and ignores CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC. If your network blocks api.anthropic.com, WebFetch fails until you allowlist the host or set skipWebFetchPreflight: true. Skipping it means WebFetch will try any URL, so pair it with WebFetch permission rules if you need to limit domains (see Permissions).