Questions
The long form of most answers is on the transparency page and in the launch post.
Where does the money actually go?
What do I get out of it?
What's the best way to financially support open source projects?
What does this cost advertisers?
What does install actually touch?
statusLine in your agent's own settings, written through the interface that agent documents. Nothing else, and no file belonging to another program gets read or rewritten. It also asks four targeting questions, all defaulting to no, and prints the JSON your answers produce. Uninstall puts it back.What do you collect about me?
By default: the package names in your lockfile, your agent and OS, and whether anyone is at the keyboard. Never your hostname, your repo name, or a file path. It sits under a random install ID, not an account. Your lockfile counts toward the totals we publish either way; no package is named there until 5 separate installs report it.
Opt in and advertisers can also aim at those packages, your country, your IP range, and what your agent has been reading. This is the exact JSON a render sends, either way:
obrigado privacy
{
"deps": [
{ "p": "npm:react", "d": 0 },
{ "p": "npm:scheduler", "d": 1 }
],
"private_repo": false,
"signals": {
"ci": false,
"tty": true,
"display": true,
"agent": "claude-code",
"agent_version": "2.1.4",
"client_version": "0.1.0",
"surface_version": "0.1.0",
"os": "linux",
"sharing": {
"packages": false,
"region": false,
"network": false,
"activity": false
},
"docker": false,
"container": false
}
}
{
"deps": [
{ "p": "npm:react", "d": 0 },
{ "p": "npm:scheduler", "d": 1 }
],
"private_repo": false,
"signals": {
"ci": false,
"tty": true,
"display": true,
"agent": "claude-code",
"agent_version": "2.1.4",
"client_version": "0.1.0",
"surface_version": "0.1.0",
"os": "linux",
"sharing": {
"packages": true,
"region": true,
"network": true,
"activity": true
},
"retrieved": ["npm:react"],
"docker": false,
"container": false
}
}
The sharing block is permission, not information. Your country and IP range come off the connection, get matched, and are never stored.
Once the line is shown, a second request confirms it. No prompt, no message, no filename, no model, no cost.
{
"events": [
{
"type": "impression",
"impression_id": "8f1c0e2a-5d77-4a31-9b0e-2c6f1d4e8a55",
"nonce": "3Qk1r0Zp8vJt2mXq5Lw9Aw==",
"signals": {
"timing": { "session_s": 1840, "api_s": 412 }
}
}
]
}
{
"events": [
{
"type": "impression",
"impression_id": "8f1c0e2a-5d77-4a31-9b0e-2c6f1d4e8a55",
"nonce": "3Qk1r0Zp8vJt2mXq5Lw9Aw==",
"signals": {
"timing": { "session_s": 1840, "api_s": 412 },
"retrieved": ["npm:react"]
}
}
]
}How does ad targeting work here?
npm:react plus region:DE reaches React users in Germany rather than both groups.Can an advertiser target my packages, my location or my company?
obrigado privacy switches them off again, deleting what was stored rather than merely ceasing to read it. Say no to all four and the line still runs and still funds the same grants: the flag decides only whether an advertiser may aim at your lockfile, never whether it is worth anything. Impression counts are withheld for campaigns targeting an IP range, because a count beside an address is a measure of one company's working day.