Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

What telemetry actually sends, and why software collects it

Usage data genuinely improves products and is also the least examined category of collection in most software.

A laptop displaying VPN software sits on a wooden desk with a notepad and plant offering a secure workspace vibe.
Photograph by Kevin Paster via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

There is a short answer about telemetry and a useful one, and they are not the same. What follows is the useful one.

The short version

  • Crash reports and usage events are different collections with different risks.
  • Aggregated counts are far less revealing than event streams with identifiers.
  • Opt-out is common; genuinely disabling all of it often is not.

Three different things wear the same name

Crash reporting captures the state of a program when it failed, which may include memory contents and file paths containing your name. Usage analytics records which features were used, in what order and for how long, usually tied to a device or installation identifier.

Performance monitoring records timings and resource use, which is generally the least sensitive of the three. Settings frequently bundle them together, which prevents the sensible choice of allowing one and refusing another.

Why developers want it

Without usage data, decisions about what to build rest on the loudest feedback rather than on what people do. Crash data reveals failures that users never report, and a defect affecting a fraction of a per cent of launches is invisible any other way. Performance data reveals which real-world configurations are slow, which laboratory testing does not reproduce.

The short version: these are legitimate engineering needs rather than a pretext, which is why the argument is about scope rather than existence.

The difference between aggregate and identified

A counter recording that a feature was used ten thousand times reveals almost nothing about any individual. A stream of timestamped events tied to a stable identifier is a behavioural record and is a fundamentally different thing.

Techniques that add calibrated noise to individual reports so only population statistics are recoverable are deployed by several large platforms. Differential privacy of this kind is a genuine mathematical guarantee whose strength depends on parameters that are not always published.

What leaks unintentionally

Crash dumps have been found to contain document contents, file names, credentials held in memory and search queries. Error messages and stack traces routinely include file paths containing user names and directory structures. Screenshots attached to feedback reports capture whatever else was on screen.

These are accidents of implementation rather than intent, and they are common enough to assume rather than doubt.

Several data protection regimes require a lawful basis for collection and treat some telemetry as requiring consent rather than legitimate interest. Enforcement has focused on whether consent was freely given and whether refusing was as easy as accepting. Operating systems increasingly present a choice at first setup, where almost everybody accepts the default.

Requirements vary substantially by jurisdiction, so what is offered depends partly on where the device thinks it is.

Implementations differ, and vendors are not obliged to document the differences.

Reducing it in practice

Review the diagnostics settings on your operating system, browser and major applications once, since defaults differ and change between versions. Prefer basic or required-only levels where offered, which usually retains security-relevant reporting. Network-level blocking of known telemetry destinations is possible and can break software in ways that are hard to diagnose.

Reset advertising identifiers periodically, since those are what allow separate collections to be joined.

The takeaway

Aggregated counts are cheap to give away. Identified event streams are a different transaction entirely.

The constraint is almost always physical, and marketing rarely mentions which one.

Questions readers ask

Should I turn telemetry off?

Reducing it to required-only is a reasonable default that keeps security reporting and removes behavioural tracking. Blanket blocking can break update and crash handling in ways that are hard to trace.

Do crash reports contain my documents?

They can. A crash dump captures memory contents, which may include whatever the program was working on. Vendors filter for obvious sensitive data with imperfect results.

Data & Privacytelemetryanalyticscrash reportsconsent
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas