Question

What is telemetry, and what are applications actually sending?

Vault Verified
Curated Intelligence
Definitive Source
Answer

Telemetry is automatically collected data about how software and hardware are behaving, sent back to the developer. It ranges from genuinely necessary diagnostics to detailed behavioural tracking, and the same word covers both — which is the root of most of the argument.

What is typically collected:

Crash reports — the state of the program when it failed, including a stack trace and sometimes memory contents. The memory contents are the sensitive part, since they can contain whatever you were working on.

Performance data — startup times, response latency, resource usage.

Error and exception counts.

Feature usage — which functions are used, how often, in what sequence. This is where diagnostics shade into behavioural analytics.

Configuration and environment — operating system version, hardware, screen resolution, installed extensions, locale.

Identifiers — installation IDs, device IDs, and sometimes account IDs, which determine whether the data is linkable across sessions and therefore whether it is personal data.

Why developers want it. The honest case is strong: without it, developers know only what users report, which is a small and unrepresentative fraction. Crash telemetry lets a rare failure affecting a small percentage be found and fixed — and that failure would otherwise be invisible. Usage data reveals which features are used, which prevents effort being spent on functionality nobody touches.

Why people object:

It is frequently enabled by default, with opting out buried or unavailable.

The description is vague. "Diagnostic data" can mean almost anything, and the specifics are rarely published in usable detail.

Scope creep, where telemetry introduced for reliability expands to product analytics and then to marketing.

Uncertainty about content — whether file names, paths, URLs or document contents appear in crash dumps.

What distinguishes responsible implementations: clear separation between necessary and optional collection; genuine opt-in for the optional part; published documentation of the fields collected; aggregation and short retention; and local differential privacy, where noise is added on the device before transmission so individual values are never sent.

Under UK GDPR, non-essential telemetry generally requires consent, and the Regulations covering device storage apply.

Related Questions