Data Flow: Private and Non-Private Data, Kept Apart
Back in your restaurant: each order simultaneously generates two slips. One goes on the front-counter display (dish name + table number, all servers can see it); the other enters the membership system backend (complete record including the member's phone number, accessible only to operations staff). The distinction is which "slip" contains personal information.
Every event in Claude Code is similarly sent to two destinations. src/services/analytics/sink.ts routes each event to two backends:
// src/services/analytics/sink.ts
function logEventImpl(eventName: string, metadata: LogEventMetadata): void {
const sampleResult = shouldSampleEvent(eventName)
if (sampleResult === 0) return // Sampling: this event was selected for "don't record" — discard
if (shouldTrackDatadog()) {
// Datadog is the general-access backend — strips _PROTO_* fields
void trackDatadogEvent(eventName, stripProtoFields(metadataWithSampleRate))
}
// 1P (first-party) receives the full payload including _PROTO_* fields
logEventTo1P(eventName, metadataWithSampleRate)
}
| Backend | Data Received | Access Control | Purpose |
|---|---|---|---|
| Datadog | Version without personal identifiers (strips _PROTO_* fields) | General team access, all engineers can view | Real-time monitoring, alerts, dashboards |
| 1P (first-party) | Full data including personal identifiers (_PROTO_* fields) | Permission-controlled BigQuery columns | Deep analysis with user identities |
_PROTO_* is a field name prefix convention marking fields that contain PII (Personally Identifiable Information) — things like user email or account UUID. This prefix tells the code "this field can only go to authorized systems, not Datadog."