Questioning Grok Build's Privacy and Telemetry
WesEklund · x · 2026-07-14
This post presses hard on Grok Build's data handling and privacy mechanisms:
- Before disablecodebaseupload was set to true, which repositories were uploaded, how long were they kept, and when will they be deleted?
- Why is the upload toggle server-side controlled rather than requiring explicit client-side consent? This means xAI could potentially re-enable uploads without users updating their clients.
- Does GROKWORKSPACEDATACOLLECTIONDISABLED=1 actually work? The author claims it shows no measurable change in network behavior.
- Does the opt-out in /privacy genuinely disable telemetry? The author observed that Mixpanel and Grok analytics events are still firing.
- It also questions whether ZDR (zero data retention) is actually available to all users.
More from Safety
- Anthropic accused of hyping AI fear to lock in a regulatory moat, sparking pushback — ShakeelHashim · 2026-09-11
- AI safety community mocked as 'bridge engineers' who say bridges can never be safe — Dan_Jeffries1 · 2026-09-11
- Why So Many AI Researchers Think the Machines Could Kill Everyone — wiredmagazine · 2026-09-11
- California creates standards for independent AI auditors to verify lab safety testing — VraserX · 2026-09-11
- a16z podcast: why 2-3 person startups are absent from policy debates — a16z Podcast · 2026-09-11
- Researcher questions AI safety eval firm, citing 'blatantly sloppy' security and monitoring — Kyrannio · 2026-09-11