privacyagent guideagent apiledger specanchoringopentelemetry exportagents supported

Privacy

What agent-blackbox records, where it keeps it, how long, and what leaves your machine.

What leaves your machine

Nothing. The code opens no outbound connection: the recorder listens on 127.0.0.1 only (src/daemon.js), the hook and CLI talk to it over loopback (src/local-http.js), and the local UI loads no external script, font or image. There are no runtime dependencies. blackbox share and scan --card draw images from aggregate numbers and fixed category labels, never from project names, hosts, commands or prompts.

The one exception is something you do on purpose: a file you publish yourself (a share card, an anchor head).

What is recorded, and where

Everything lives in ~/.blackbox/ (folders 0700, files 0600).

WhatWhereProtection
Record metadata: sequence, time, event kind, tool name, session id, working directory of a session start, decisions and rule namesledger.jsonlclear text, hash-chained and signed
One-line summary of each hook record (prompt, command, path text, secrets masked)ledger.jsonlsealed with the session key (AES-256-GCM)
Full payloads: prompt, tool arguments, tool resultsblobs/<key>/sealed with the session key, secrets replaced by fingerprints
Prompt and response text through telemetryblobsonly with install --prompts
Full model request and response bodiesblobsonly with install --raw; Claude Code writes them in clear text to api-bodies/ until the recorder scrubs and moves them (about 3 minutes at most)
Secretsnever storedreplaced by [secret:<fingerprint>]; the fingerprint is a truncated HMAC with a per-install salt

Session keys are wrapped by a master key. blackbox purge or retainDays destroys a session key: that session's payloads and summaries become unreadable everywhere, backups included. The chain keeps every hash and still verifies.

Still in clear text after a purge: record metadata, the working directory of session starts, rule names and the reasons of decisions (secrets masked). These are what lets verify and the timeline keep working.

Retention

Nothing is deleted unless you ask. blackbox purge --days N erases on demand; "retainDays": N in ~/.blackbox/config.json does it automatically (at start, then hourly). Off by default.

What the defaults do not protect against

Team mode

Not built. The privacy rules it must meet before any code are in ROADMAP.md.

Edit this page on GitHub