Questioning Grok Build's Privacy and Telemetry
WesEklund · x · 2026-07-14
This post presses hard on Grok Build's data handling and privacy mechanisms:
- Before disablecodebaseupload was set to true, which repositories were uploaded, how long were they kept, and when will they be deleted?
- Why is the upload toggle server-side controlled rather than requiring explicit client-side consent? This means xAI could potentially re-enable uploads without users updating their clients.
- Does GROKWORKSPACEDATACOLLECTIONDISABLED=1 actually work? The author claims it shows no measurable change in network behavior.
- Does the opt-out in /privacy genuinely disable telemetry? The author observed that Mixpanel and Grok analytics events are still firing.
- It also questions whether ZDR (zero data retention) is actually available to all users.
More from Safety
- PNAS special issue examines copyright, governance, and AI in the legal system — chrmanning · 2026-07-22
- Pensar Launches AI Security Agent to Autonomously Discover and Patch 0-Days — andriy_mulyar · 2026-07-22
- Bloomberg says Sam Altman will brief Trump officials and Congress on GPT-6 next week — soumitrashukla9 · 2026-07-22
- AI x Bio research should not be treated as one switch, says the post — lemire · 2026-07-22
- mcp-doctor adds CI-friendly health and security audits for MCP servers — sticky_block · 2026-07-22
- Research finds memory compression makes AI agents drop safety rules and hit 59% violations — gerardsans · 2026-07-22