Transparency

Every event the apps and this site can send is listed below, verbatim. The lists are generated from the same contract file both apps' tests enforce, so the telemetry can't change without this page changing with it.

Both apps send anonymous telemetry. None of it is traceable back to you as a person, because there is no account, no login, no profile, only a random id minted on your machine, regenerated if you reset it or reinstall the apps. This stays true even if you buy Pro — at that stage you are trusting us with your email address as part of the license record and we could technically link your telemetry back to your email via the license, but we made a deliberate choice not to include any events that would allow us to do such a thing, so the telemetry truly is anonymous.

Telemetry is on by default and we disclose this on first install of both apps as well as the fact that you are free to switch it off completely (Clausage: Settings → Privacy; Clauswitch: VS Code's own telemetry.telemetryLevel setting).

Values in these tables are the complete possibilities: every property is a short label from a closed list, a coarse bucket, a version string, or a yes/no. Specific numbers never appear there.

What is never sent

  • OAuth tokens / secrets (token-shaped strings)
  • Email addresses
  • Organization names
  • Organization UUIDs (canonical dashed UUID)
  • Absolute filesystem paths (leading /, ~/, or an embedded /Users/…)
  • Folder-rule globs, and any value containing / or * (Clauswitch — see the note below)
  • Identity-tied usage percentages (no raw numbers appear in any event; counts are bucketed)
  • Info about usage credits / usage credit limits you set
  • Claude cache content and raw endpoint payloads
  • Account ids, account names, config-dir paths, workspace/repo names

On every event

PropertyValues
sourceclausage | clauswitch | site
versionthe app/extension version, verbatim
osmacOS <major> | Windows <major> | Linux
environmentdev | prod

day_active — the daily spine

One event per app & per day, carrying a coarse snapshot.

PropertyValues
install_agenew | week | month | older
tierfree | pro
sibling_installedyes | no
account_count_bucket0 | 1 | 2 | 3-4 | 5+
counters_days1 | 2-7 | 8+
primary_sourceendpoint | sharedCache | vscodeCache | snapshot | cli | none
failuresactivity bucket
worst_categorya diagnostics category, or none
dropped_eventsactivity bucket

Clausage only

PropertyValues
popover_opensactivity bucket
notificationsactivity bucket — notifications delivered in the span
notifications_enabledyes | no
launch_at_loginyes | no
offline_modeyes | no
revive_unavailableyes | no

Clauswitch only

PropertyValues
switchesactivity bucket
manual_refreshesactivity bucket
bind_viaseed | setting
window_count_bucketcount bucket
folder_rulescount bucket
terminals_boundyes | no
usage_sourceauto | localCacheOnly

The buckets, exactly

Where a table above says “bucket”, these are the only values that exist:

countBucket(n)     0 → "0" · 1 → "1" · 2 → "2" · 3…4 → "3-4" · ≥5 → "5+"
activityBucket(n)  0 → "0" · 1…5 → "1-5" · 6…20 → "6-20" · ≥21 → "20+"

And worst_category picks the highest-ranked problem seen that day, by this fixed order (most severe first):

no_service
keychain_read_fail
token_expired
usage_403
usage_401
usage_429
usage_http_error
transport_fail
parse_fail
cache_write_fail

Milestones

Explicit, low-volume, triggered by specific events.

EventPropertiesEmitted byWhen
license_activated—bothon successful activation, identity-free (no licence id, hashed or otherwise)
upsell_shown—clausagecontextual upsell was visible
upsell_clicked—clausagecontextual upsell was clicked
first_switch—clauswitchswitched accounts for the first time ever
multi_account_reached—boththe first time ≥2 accounts are seen
onboarding_completed—bothwalkthrough finished
cross_promo_clickedtarget (clausage | clauswitch)boththe sibling’s pointer was clicked
switch_to_local_only—bothentering cache-only mode
download_clickedtarget (clausage_dmg | clauswitch_marketplace)sitedownload CTA clicked
buy_clicked—sitebuy CTA clicked

diagnostic — when something breaks

Caught, categorised failure. Category and which pipeline layer it hit, both values come from closed lists.

Categories:

no_service
keychain_read_fail
token_expired
usage_401
usage_403
usage_429
usage_http_error
parse_fail
transport_fail
cache_write_fail

Layers:

endpoint
sharedCache
vscodeCache
snapshot
cli
keychain
store

crash_detected — Clausage only

If Clausage crashes, macOS writes a crash report on your Mac. On the next launch, Clausage sends a reduced digest — six closed-set values, no stack trace, no file, nothing free-text. The report file itself never leaves your Mac unless you attach it to a support email yourself.

PropertyValues
exception_typeEXC_BAD_ACCESS · EXC_BREAKPOINT · EXC_CRASH · EXC_BAD_INSTRUCTION · EXC_ARITHMETIC · EXC_GUARD · EXC_RESOURCE · other
signalSIGSEGV · SIGABRT · SIGTRAP · SIGBUS · SIGILL · SIGKILL · other
areapoller · usage · keychain · store · notifications · license · telemetry · selftest · ui · other
signature8 hex chars — a hash that groups identical crashes, carries no content
crashed_versionthe version that crashed, or unknown
uptimelaunch (< 10 s) · short (< 10 min) · long · unknown

This site

The site sends $pageview and $pageleave, plus download_clicked and buy_clicked (both in the milestones table above). Cookieless — nothing is written to cookies or local storage, so there is no banner to click and nothing about a visit survives closing the tab. Autocapture, session replay and location lookup are off.

That covers this site. The checkout is the one exception, and only while it is open: buying Pro opens Lemon Squeezy's checkout in a frame on /buy, and their checkout sets its own cookies on their own domain, as any payment page does. The script that opens it writes nothing here — no cookie, no local storage — and the frame is a separate origin, so nothing it stores is readable by this site or by us. Card details never touch schizm.app at all; Lemon Squeezy is the seller of record and handles them.

The apps build every payload by hand, so what they send is exactly the tables above. The analytics library on this site also attaches properties of its own to every event it sends. We reduced the default set to deny some of them; the table below lists all of it, including the library's own bookkeeping.

PropertySent?What it answers
source environment color_schemekeptour own three, registered on every event: which service sent it (site), that the build was live (prod), and whether the page rendered dark or light
$os $os_version $browser $browser_version $device_typekeptbasic system facts
$device $device_modelkeptthe device, where the browser reports one — observed on mobile visits only
$referrer $referring_domainkeptwhere the traffic came from
utm_source utm_medium utm_campaign utm_content utm_termkeptwhich announcement or listing sent them, when the link was tagged
$current_url $host $pathname titlekeptwhich page is being read. Public marketing URLs and their titles; the site has no per-visitor or parameterised routes for one to leak through
$session_entry_url $session_entry_host $session_entry_pathname $session_entry_referrer $session_entry_referring_domainkeptthe page and referrer the visit started on — the same public facts as the row above, remembered for the length of one visit
$screen_height $screen_width $viewport_height $viewport_widthkeptwhat the page is being read on
$device_id $session_id $window_id $pageview_idkeptlibrary’s own, per-tab, regenerated on every page load, nothing durable
$geoip_disable $process_person_profilekeptour own anonymity posture, sent so the server honours it: never resolve location, never build a person record
$lib $lib_version $lib_rate_limit_remaining_tokens $insert_id $sent_at $time $config_defaults $configured_session_timeout_ms $initialization_time $is_identified $recording_status $sdk_dist_channel $sdk_debug_extensions_init_method $sdk_debug_extensions_init_time_ms $sdk_debug_retry_queue_sizekeptSDK plumbing — the library’s own name, version, timing, delivery bookkeeping and self-diagnostics. Nothing about the visitor; kept as one row because the set belongs to posthog-js and moves with it, and enumerating it row by row would publish a list a future SDK release quietly falsifies
distinct_id tokenkeptenvelope rather than properties: the per-page-load id (the same value as $device_id) and the site’s write-only ingestion key
$raw_user_agentdeniedfingerprint component
$timezone $timezone_offsetdeniedcoarse location info
$browser_language $browser_language_prefixdeniedcoarse location info

Leaving a page sends one more event, which carries how far down that page you got. It adds these:

PropertySent?What it answers
$prev_pageview_id $prev_pageview_pathname $prev_pageview_durationkeptwhich page was just left, and for how long
$prev_pageview_max_scroll $prev_pageview_max_scroll_percentage $prev_pageview_last_scroll $prev_pageview_last_scroll_percentagekepthow far down the page the visitor got, furthest and final
$prev_pageview_max_content $prev_pageview_max_content_percentage $prev_pageview_last_content $prev_pageview_last_content_percentagekeptthe same two measures against the content box rather than the raw page height

Caps

Volume is bounded by design:

CapValue
Per-install, per-day, all events50
diagnostic per day10
diagnostic per (category, layer) per day — both apps1
crash_detected per signature per day — Clausage1
upsell_shown per day1
Offline buffer100 events, in memory, drop-oldest

What the license refresh sends

Not telemetry, but it is the one other thing the apps ever send us, so it belongs on this page. If you buy Pro, the app confirms your license with our server about once a day while it runs. Free installs never make this call — there is nothing to refresh.

The request carries exactly three fields: key — your signed license, which contains your name and email as the licensed-to line; install — a random id; and app — clausage or clauswitch — with the app's version in the request's standard User-Agent header. Nothing else rides along: no usage data, no telemetry id, no hardware fingerprint. The install id is minted randomly on the first refresh and stored in a file next to the license — it says nothing about your machine, and deleting the file mints a new one.

What we keep: on the license record, the time of the last refresh and a running count; per install id, which app it is and first/last-seen timestamps. Server logs record the license id, the outcome and timestamps — never the key itself. Like any web request, the call arrives with your IP address; it is used for rate limiting and is not attached to the license record.

The server's answer is a freshly signed copy of your license. If the server is unreachable, nothing changes right away — the last confirmation is good for 45 days.

Our telemetry backend

PostHog, EU region, one shared project for both apps and this site. Events are anonymous at the protocol level. If you have further questions, contact us at [email protected].