Telemetry
The Qualor server sends anonymous usage statistics to the Qualor project once a day. They tell us
how many servers run, which versions, and which languages and features people use, so we know
what to work on. The scanner (qualor scan) sends nothing.
Turn it off
Set QUALOR_TELEMETRY=false and restart the server.
- Docker Compose: add
QUALOR_TELEMETRY=falseto the server’senvironment(or.env). docker run:-e QUALOR_TELEMETRY=false.- Helm:
config.telemetry: false.
At every start the server logs one line that says which it is:
Telemetry: disabled
When and where
About a minute after the server starts, and then every 24 hours, the server sends one HTTPS
POST to https://qualor.dev/api/telemetry. It waits 5 seconds at most and never retries. When
it cannot reach qualor.dev (an offline network, a proxy), nothing else changes.
What is sent
The whole report, as an example:
{
"schema": 1,
"installationId": "3f0c9a52-6d1e-4c8b-9f0a-2b7d1e5c4a91",
"version": "0.6.0",
"edition": "community",
"platform": { "os": "linux", "arch": "x64", "node": "22.11.0", "runtime": "docker" },
"database": "embedded",
"counts": {
"organizations": 1, "users": 4, "projects": 12, "branches": 30,
"analyses30d": 310, "qualityGates": 2, "qualityProfiles": 5, "webhooks": 1
},
"languages": ["java", "typescript"],
"engines": ["qualor", "semgrep"],
"scm": ["gitlab"],
"features": { "sso": false, "scim": false, "aiAssistant": true }
}
| Field | Meaning |
|---|---|
installationId |
a random id the server creates on its first report and keeps. It is not derived from your licence, organisations or host |
version, edition |
the server’s version, and community or enterprise |
platform |
operating system, CPU architecture, Node.js version, and whether it runs from the Docker image, on Kubernetes or as a plain Node.js process |
database |
embedded (the image’s own PostgreSQL) or external (DATABASE_URL) |
counts |
how many organisations, users, projects, branches, quality gates, quality profiles and webhooks exist, and how many analyses ran in the last 30 days |
languages |
the languages of the analysed files |
engines |
the built-in analyzers that ran successfully in the last 30 days, and external when a SARIF report from another tool was imported |
scm |
gitlab and/or github, when a connection exists |
features |
whether single sign-on, SCIM and the AI assistant are set up |
What is never sent
Names of users, organisations, projects, repositories or branches, email addresses, URLs and host names, source code, file paths, issues, tokens, secrets and the licence key.
What happens on our side
qualor.dev stores the report under the installation id, one per day, and keeps it for 24 months. It keeps the report without the IP address it came from; like every request to qualor.dev, the address appears in the load balancer’s logs, which are deleted after 30 days. Only the Qualor project sees the data. See also the privacy policy.