Data Flow: Private and Non-Private Data, Kept Apart

Back in your restaurant: each order simultaneously generates two slips. One goes on the front-counter display (dish name + table number, all servers can see it); the other enters the membership system backend (complete record including the member's phone number, accessible only to operations staff). The distinction is which "slip" contains personal information.

Every event in Claude Code is similarly sent to two destinations. src/services/analytics/sink.ts routes each event to two backends:

// src/services/analytics/sink.ts
function logEventImpl(eventName: string, metadata: LogEventMetadata): void {
  const sampleResult = shouldSampleEvent(eventName)
  if (sampleResult === 0) return  // Sampling: this event was selected for "don't record" — discard

  if (shouldTrackDatadog()) {
    // Datadog is the general-access backend — strips _PROTO_* fields
    void trackDatadogEvent(eventName, stripProtoFields(metadataWithSampleRate))
  }

  // 1P (first-party) receives the full payload including _PROTO_* fields
  logEventTo1P(eventName, metadataWithSampleRate)
}
BackendData ReceivedAccess ControlPurpose
DatadogVersion without personal identifiers (strips _PROTO_* fields)General team access, all engineers can viewReal-time monitoring, alerts, dashboards
1P (first-party)Full data including personal identifiers (_PROTO_* fields)Permission-controlled BigQuery columnsDeep analysis with user identities

_PROTO_* is a field name prefix convention marking fields that contain PII (Personally Identifiable Information) — things like user email or account UUID. This prefix tells the code "this field can only go to authorized systems, not Datadog."