Jolli Edu and Jolli Code Telemetry
Last Updated: October 2, 2026
1. About This Page
This page lists every network connection the Jolli Code applications make and everything the Jolli Edu website records about your use, what travels over each, and how to control it. It is written from the shipped code. It covers Jolli Edu (the website and web application, including institution sites and the sign-in service) and Jolli Code (the desktop application, command-line interface, terminal interface, and the web application at app.jolli.ai). The Jolli Memory telemetry page at https://jollidev.com/telemetry describes Jolli Memory and does not apply to these products.
In one line: neither product contains a usage-analytics tracker. Jolli Code sends the data needed to run the service (your conversations to Jolli's model gateway, tagged with the course and conversation they belong to), crash reports from the desktop and web applications if the build has crash reporting enabled and an unexpected error occurs, and ordinary update and package downloads. The Jolli Edu website counts visits, keeps sign-in and AI usage records, and loads two third-party scripts: Cloudflare's bot check on the sign-up page and a code-editor component.
2. Every Connection Jolli Code Makes
| Connection | Host | What is sent | When | Control |
|---|---|---|---|---|
| Sign-in | auth.jolli.ai, and the identity provider you sign in with | A random state value, a callback address on your own machine, the client name and version. Then a one-time code, exchanged for an access token and a refresh token. Later, the refresh token to renew your session. | When you sign in, and periodically to renew. | Required to use Jolli Code. |
| Model requests | api.jolli.ai, or the Jolli host your account is assigned to | The full context of the request: your prompts, the AI's earlier responses, the system prompt, and the file contents, command output, and tool results the agent has gathered. Request headers carry identifiers for the conversation, turn, attempt, request, and step; the course and course assistant; the parent session, if any; the name of the slash command that started the turn; the names of connected tool servers and tool overrides; the names of tools that failed; and the Jolli Code version. Your sign-in token. | Every turn of every conversation. | Cannot be disabled. This is how the service works. |
| Session titles | Same gateway | Your first message, sent to a model to generate a title. The resulting title, or one built from your course code and your text, saved to the conversation. | Once per conversation. | Not separately controllable. |
| Course catalogue | The Jolli host your account is assigned to | Your sign-in token. Returns your courses, roles, assistants, available models, and course tool configuration. | At startup and about every 5 minutes while in use. | Required. |
| Course roster | The Jolli host your account is assigned to | Your sign-in token. Returns the names, email addresses, and roles of the members of that course. | When you open the sharing panel. | Only happens when you choose to share. |
| Course tools | The Jolli host your account is assigned to | The arguments of each course tool call, your sign-in token, and the course and assistant identifiers. | When the agent uses a tool provided by your course. | Part of the course's configuration. |
| Crash reports | Sentry (sentry.io) | If a report is sent, it may contain the error message, a stack trace, the application version, a platform tag (desktop or web), and basic operating system or browser information. No activity breadcrumbs. We do not attach your name, email, or account identifier. An error message may incidentally contain a file path from your device. | Only from desktop and web builds compiled with a crash-reporting key, and only when an unexpected error occurs. Builds without a key send nothing. | No in-app switch today. Builds without a crash-reporting key send none, and the command-line interface, terminal interface, and local server never send crash reports. |
| Desktop updates | github.com, the jolliai/jollicode-releases repository | The current application version. GitHub sees your IP address. | When the desktop application checks for updates, including when you choose Check for Updates. An update is downloaded only after you accept it. | Decline the update when prompted. |
| CLI update check | api.github.com and jolli.ai/install | The current version. GitHub and Jolli see your IP address. | When the command-line interface checks for a newer release. | Set JOLLICODE_DISABLE_AUTOUPDATE=1. |
| Model catalogue | models.opencode.ai | Nothing beyond an ordinary web request. The host sees your IP address. Returns a public catalogue of AI model capabilities. | At startup. | Set JOLLICODE_DISABLE_MODELS_FETCH=1. |
| Plugin installs | registry.npmjs.org | The names of packages you install. | Only when you add a plugin. | Do not add plugins. |
| Your own tracing | An endpoint you choose | Trace spans for AI calls. | Only if you set OTEL_EXPORTER_OTLP_ENDPOINT. | Off by default. Leave the variable unset. |
3. What the Jolli Edu Website Records
| Record | What it holds | Kept for |
|---|---|---|
| Visits | A visitor identifier from a first-party cookie and, when you are signed in, your user identifier, recorded each time the application loads. No page names, no referrer. | The cookie lasts 1 year; the records stay with your account. |
| Sign-in sessions | Your IP address, browser or client type, sign-in method, and timestamps. | For the life of the session. |
| Security audit log | Who performed account and administrative actions, the action, the IP address, and the browser, with personal details encrypted. | 365 days. |
| AI request usage log | Your user identifier, the model used, token counts and cost, the conversation identifier, and your IP address, for every AI request from Jolli Code or course chat. | 90 days. |
| Diagnostic traces of AI requests | Timing, model, token counts, and identifiers for each AI request, in a tracing system that runs inside our own cloud. The text of requests and responses is not attached in production. | 90 days in the active store, then archived. |
| Server logs | Request logs with sensitive parts of the address redacted, and error output. | 1 month. |
| Transactional messages (verification, password reset, invitations, join requests, course notifications) sent through SendGrid. We have not enabled open or click tracking. | Not stored beyond delivery records. |
Third-party services the website contacts from your browser or on your behalf:
- Cloudflare Turnstile, on the sign-up page only, to verify that you are not a bot. Cloudflare receives your IP address and browser information.
- cdn.jsdelivr.net, to load the TypeScript compiler when you open a feature that needs it. The host sees your IP address and nothing else.
- Google or GitHub, when you choose to sign in with them.
- Tavily, when a course assistant searches the web to answer a question in course chat. The search query is sent; your identity is not.
The website also has a telemetry endpoint that accepts anonymous usage events from Jolli's command-line and editor tools. Events are scrubbed on arrival of anything that looks like an email address, a name, a path, a URL, a prompt, or a secret, and are kept for 3 years. Neither Jolli Code nor the Jolli Edu web application sends events to it today. Our servers also send a heartbeat to an uptime-monitoring service; it carries no user data.
4. What the Services Never Do
- No usage-analytics software. Neither product includes PostHog, Segment, Mixpanel, Amplitude, Google Analytics, Hotjar, FullStory, LogRocket, or any similar tracker, and there is no session replay.
- No keystrokes, screen contents, clipboard contents, or browsing activity.
- No public sharing. The upstream OpenCode feature that publishes a session to a public link is disabled. Sharing happens only inside your course, on Jolli, with the course members you choose.
- No direct connections from your device to Anthropic, OpenAI, Google, or any other model provider. All AI requests go through Jolli's gateway, which forwards them to the provider configured for your workspace or course.
- No web search from Jolli Code models by default. The Exa and Parallel search tools are off for Jolli models unless they are enabled in your configuration. Course assistants use Tavily only where a course enables it.
- No conversation content to anyone other than Jolli's gateway, the configured AI model provider, and, for course chat with web search, the search provider.
5. What Identifies You
- Your account. Every request to Jolli carries your sign-in session or token, so conversation records, usage logs, visit records, and course data are tied to your account. The request metadata in Section 2 is used for statistics and debugging and is not anonymous.
- Crash reports (Jolli Code). Reports are not tagged with your name, email, or account identifier. They carry the application version, a platform tag, and whatever the error message contains.
- Other hosts. GitHub, the npm registry, models.opencode.ai, cdn.jsdelivr.net, and Cloudflare receive an ordinary web request and see your IP address. They receive no account information and no conversation content.
6. How to Turn Things Off
- Model requests, request metadata, usage logs, and visit records cannot be turned off while you use the Services. Sign out and stop using them to stop them.
- Crash reports (Jolli Code): there is no in-app setting today. Builds compiled without a crash-reporting key send none, and the command-line and terminal interfaces never send any.
- Update checks: set
JOLLICODE_DISABLE_AUTOUPDATE=1for the command-line interface. The desktop application never downloads an update without your confirmation. - Model catalogue download: set
JOLLICODE_DISABLE_MODELS_FETCH=1. - Tracing: leave
OTEL_EXPORTER_OTLP_ENDPOINTunset. - Cookies: clear them in your browser at any time. Clearing the sign-in cookies signs you out. Leave "remember me" unchecked to avoid the long-lived remember-me cookie.
- The
DO_NOT_TRACKenvironment variable and browser Do-Not-Track signals: the Services do not currently read them.
The older OPENCODE_ prefix is accepted as an alias for each JOLLICODE_ variable.
7. Data Kept on Your Device
Jolli Code stores its data in standard per-user directories. On macOS, Linux, and Windows the defaults are the same paths under your home folder, and the XDG_DATA_HOME, XDG_CONFIG_HOME, XDG_CACHE_HOME, and XDG_STATE_HOME variables override them.
| Data | Location |
|---|---|
Sessions, messages, transcripts, sign-in credentials (the jollicode.db database), and logs | ~/.local/share/jollicode |
| Configuration | ~/.config/jollicode |
| Course catalogue cache and downloaded tool binaries | ~/.cache/jollicode |
| Run state and locks | ~/.local/state/jollicode |
Signing out of Jolli Code removes your credentials and the course catalogue cache. Deleting the directories above removes everything else. The desktop application also keeps window layout and update state in its own application support folder, which is removed when you uninstall it.
The Jolli Edu website keeps the following in your browser: the cookies listed in the Privacy Statement (sign-in, remember-me, visitor identifier, sign-up intent, theme, and sign-in preferences), and local storage for display preferences, panel widths, your current workspace, and a session heartbeat. Clearing site data for jolli.ai removes all of it.
8. Questions
Email support@jolli.ai with questions or concerns about anything on this page.