Skip to main content
#privacy#telemetry

A late notice about the telemetry install ID

In May 2026 hackmyagent, opena2a and ai-trust changed how the telemetry install ID is made, without the notice our privacy policy promised. How to opt out.

OpenA2A Team

In May 2026 hackmyagent, opena2a and ai-trust changed how they make the install ID that each telemetry event carries. Our privacy policy promised that material changes would be announced on this blog and in the tools' release notes before they took effect. This was one, and we did not announce it. This post is that notice, and it is late.

What changed

Since opena2a-cli 0.10.3 (the opena2a command), released May 11, 2026, and hackmyagent 0.23.1 and ai-trust 0.7.2, released May 24, 2026, a new install ID is a SHA-256 hash of the computer's hardware identifier (the machine-id on Linux, the hardware UUID on macOS, the MachineGuid on Windows) or, where that cannot be read, of its hostname, platform and Node.js major version, or else a random value. An ID made from the hardware identifier is the same for every user account on the computer and comes back even if the file that stores it is deleted. Anyone who knows or guesses the inputs of a hashed ID can compute it.

Before those releases, a new ID was a SHA-256 hash of the platform, the Node.js major version, the path of the npm cache folder, which usually includes the user name, and the 30-day period in which that folder last changed, or a random value where that folder was missing. secretless-ai and dvaa still make new IDs that way. All of these tools share one saved ID in ~/.config/opena2a/telemetry.json (under $XDG_CONFIG_HOME/opena2a when that is set). A tool that finds an ID there keeps it and sends it, so a computer that ran an earlier release kept its earlier ID after the upgrade.

What the policy said

The privacy policy called this usage data anonymous and said it carried no personally identifying information. The install ID identifies the computer, so the data is personal data. The policy and the telemetry page now say so. The telemetry library's change log called the hash irreversible, which was misleading: a hash cannot be run backwards, but anyone who knows or guesses its inputs can compute it again.

How to turn telemetry off

Set OPENA2A_TELEMETRY=off with nothing after off: in current releases a trailing space or a Windows carriage return leaves telemetry on, and DO_NOT_TRACK does not turn it off. Or run telemetry off in any one of the tools, for example hackmyagent telemetry off. The setting is saved in the same file, so it applies to hackmyagent, opena2a, ai-trust, secretless-ai and dvaa alike. Either way, no events are sent. Current releases still save the ID in that file even with telemetry off.

Questions about this notice or about your data: info@opena2a.org.