# Telemetry and privacy

`c3 deploy` sends C3 one short summary per run so we can diagnose submission failures, latency and capacity problems. There is currently no opt-out.

## What is sent[​](#what-is-sent "Direct link to What is sent")

* CLI version and the command entrypoint.
* Outcome, a stable failure code and the stage it failed in.
* Timings for each phase: route preview, upload, submission.
* Job and journey identifiers, and the selected provider, region and hardware.
* A configuration snapshot: whether a provider was pinned, hardware constraints, capacity policy, `time`, environment kind, and the number of datasets.
* Workspace statistics: file count, total bytes, uploaded bytes and deduplicated bytes.

## What is never sent[​](#what-is-never-sent "Direct link to What is never sent")

File names, file contents, local paths, script text, dataset names, mount paths, environment variable values, credentials, the raw `.c3`, Docker image references, and free-text error messages. User, organisation and project identifiers are pseudonymised with an HMAC before storage.

## How it is sent[​](#how-it-is-sent "Direct link to How it is sent")

One request after submission, before any `-f` log following. It has a 750 ms timeout and a 16 KiB payload limit, is never retried and is never queued offline. A failed telemetry request does not change the deploy result. A dry run reports only the route preview timing.
