Skip to content

What Devpit sends, and what it never sends

A tool that deletes files should be honest about what it tells the internet. So here is the whole picture in plain words. Everything below comes from Devpit’s PRIVACY.md file and its source code, which you can read yourself.

  • Devpit sends nothing unless you turn usage stats on. They are off until you do.
  • The scan, the sizes, the deletions, the port list and the settings all stay on your PC.
  • If you turn stats on, one small report goes out after a cleanup. It has numbers and short labels. No file names. No paths.

Devpit reads and writes exactly two folders:

What Where Override
Settings %APPDATA%\devpit\config.toml DEVPIT_CONFIG_DIR
Caches and logs %LOCALAPPDATA%\devpit\ DEVPIT_CACHE_DIR

Nothing in either folder is uploaded.

The first time you run Devpit, it asks:

Help show how much space Devpit saves? Only totals are sent — no file names or paths.

The answer is already No. You can change your mind any time in Settings, Usage stats.

Two environment variables switch stats off, and they always win, even if you said yes:

  • DEVPIT_NO_TELEMETRY=1
  • DO_NOT_TRACK=1

Devpit never asks in a non-interactive run, and it never turns stats on by itself.

If you opted in, then after a cleanup Devpit posts one JSON body to https://devpit.zubyr.dev/api/report. The source code defines the fields, and there are no other fields. Here is the shape, with example values, not real data:

{
"v": 1,
"installId": "a random id made on your PC",
"version": "1.2.3",
"os": "windows",
"osVersion": "10.0.22631",
"freedBytes": 123456789,
"items": 4,
"types": { "node_modules": 3, "npm cache": 1 }
}

In words:

  • Bytes freed and the number of items removed.
  • Item types from a fixed list of rule names such as node_modules. Names that are not plain short labels are dropped, and there is a cap on how many labels one report may carry.
  • Operating system name and version, cleaned to plain characters and a short length.
  • The Devpit version.
  • A random install ID that Devpit makes on your PC. It identifies nothing else about you.
  • File, folder or project names
  • Any path, absolute or relative
  • Your user name, machine name or domain
  • Your IP address as a location. The server does not store it.
  • The contents of any file
  • What tools or apps you have installed
  • Anything at all when a scan finds nothing, or when you cancel
  • Reports go out in the background and never block you. There is a three second time limit.
  • If you are offline, or the server is down, or it takes too long, the report is dropped silently. Nothing is retried or saved to disk. A failed report never shows an error and never delays a cleanup.
  • The server rejects impossible values, so the public totals cannot be inflated by a forged report.
  • The server keeps a hashed form of your IP address for at most one hour, only to limit how many reports one connection can send.

These are not just promises in a document. The safety rules list each one with the test that checks it, for example that a report never carries a path or a name.

This is separate from usage stats. Devpit can ask GitHub’s public releases API at most once every 24 hours whether a newer version exists. That request sends nothing but the request itself. The result is cached on your PC. If you are offline it is skipped silently.

When a newer release exists you see a small “update” pill in the header, and Settings, About Devpit shows the one command to upgrade. Nothing is downloaded or replaced for you.

To turn it off, use Settings, Update check, or set DEVPIT_NO_UPDATE_CHECK=1, which wins over the setting. A build made from source never checks.

Some features need the internet to do their job. They are not tracking. They are the feature:

  • The icon font. If you choose to install it, Devpit downloads one pinned file from the Nerd Fonts project on GitHub and checks its checksum. It is only downloaded when you ask for it.
  • The package managers. When you use Update Everything or Install Developer Apps, winget, Scoop, Chocolatey and npm contact their own servers. That traffic is theirs, not Devpit’s.

Devpit is open source. The report is defined in one place, internal/telemetry, and the rule is that adding a field means changing PRIVACY.md first. If the policy changes, the file changes in the same release, the change is listed in the release notes, and anyone who had opted in is asked again.

You can also read the plain summary on the Safety and privacy page.

  1. Leave usage stats on No if you prefer. Nothing is sent.
  2. Or set DO_NOT_TRACK=1 so it is always off.
  3. Turn off the update check with DEVPIT_NO_UPDATE_CHECK=1 if you want no request at all.
  4. Read PRIVACY.md and the source. They are short.