Docs/ Security/ Telemetry & Bug Reports

Telemetry & Bug Reports

Usage statistics and bug reports: what an sh0 server sends to sh0.dev about itself, and when.

Overview

Usage statistics are opt-in and turned off by default, including on servers upgraded from an earlier version. Until an administrator turns them on in Settings, the server sends no statistics at all.

The telemetry packet

Once turned on, the server sends this packet when you enable it, then at most once a day. It is the whole packet, not an excerpt:

POST https://sh0.dev/api/telemetry
{
  "schema": 1,
  "version": "1.10.3",
  "os": "linux",
  "arch": "x86_64",
  "app_count": 4
}
  • schema -- the packet format version, always 1 today.
  • version -- the sh0 version running on the server.
  • os -- the operating system (linux or macos).
  • arch -- the processor architecture (x86_64 or aarch64).
  • app_count -- how many applications the server runs, as a number.

The sh0.dev endpoint refuses any packet with another field, a missing field or another format version, so this list cannot grow without this page changing.

What is never sent

No application name, domain, IP address, environment variable, log line, e-mail address or account identifier is part of the packet. The endpoint uses the sending address only to limit request rates, in memory, and does not store it.

Turning it on and off

In the panel, open Settings and find "Anonymous usage statistics". "Show the exact packet" displays the packet your server would send, built by the same code that sends it; the button to turn it on stays disabled until you have looked at it. Turning it off stops all sending immediately.

Note
Statistics are off by default: neither a fresh install nor an upgraded server sends a statistics packet until an administrator turns them on.

Separately from the server, the install script reports the operating system, the architecture and the installed version to sh0.dev once, at install time. Run it with SH0_NO_TELEMETRY=1 to skip that report.

Bug reports

"Report a bug" in the panel sidebar sends a report to the sh0 team. You write a title and a description, and you may pick the application concerned. Its last 200 log lines are attached only if you tick the box. Before anything is sent, the panel shows the exact report, including the sh0 version, operating system and architecture; the server then sends that report unchanged.

Retention

Statistics packets are stored in a dedicated table with no instance identifier. Reports sent to sh0.dev -- bug reports from sh0 servers and reports from the AI assistant -- are stored in their own table. Both are kept 12 months, then deleted automatically every day.