Documentation
Privacy and crash reporting
The privacy stance and how crash reports work without telemetry.
Privacy stance (put this verbatim-ish in README and SECURITY.md)
- No telemetry. Raml KQL does not collect usage data, analytics, feature counters or identifiers.
- Your queries go from your machine straight to Microsoft, using your own identity. No Raml KQL server is involved.
- Results stay in memory, or in an encrypted session cache that is destroyed when the app closes.
- The only network traffic the app itself initiates:
- Microsoft identity/Azure endpoints you query
- git hosts for sources you added
- the GitHub Releases update check (disable with
update.checkAutomatically: false)
- Extensions can only reach the network after you grant it.
Add a "Network Activity" developer view (command "Developer: Show Network Activity") listing the hosts contacted this session with counts. It makes the claims verifiable, which matters to a security audience.
Crash reporting: local first, user-sent
The goal is to get actionable crash reports without a telemetry backend and without leaking customer data.
- Capture:
- Uncaught exceptions / unhandled rejections in main and renderer, extension-host crashes (attributed to the extension), and
render-process-gone/child-process-gone. - Electron
crashReporterwithuploadToServer: falsefor native minidumps, stored locally instate/crashes/.
- Uncaught exceptions / unhandled rejections in main and renderer, extension-host crashes (attributed to the extension), and
- Sanitize before anything is shown or sent. Keep stack traces with app-relative paths. Strip or replace:
- Query text
- Tenant, subscription and workspace IDs and names (GUID regex →
<guid>) - UPNs/emails
- IPs
- JWT-like strings
- Home directory paths (→
~) - Anything from result data
- Next start after a crash: a notification "Raml KQL closed unexpectedly. Report the problem?" with actions:
- Preview & Report on GitHub: shows the sanitized report in an editor tab so the user can read and edit it, then opens a prefilled GitHub new-issue URL (title, app version, OS, Electron version, sanitized stack). The user submits it themselves in the browser. Minidumps are not attached automatically; instructions explain how to attach one if a maintainer asks.
- Copy report
- Don't ask again
- Setting
crashReporting.mode:"ask"(default): the flow above."off": capture locally only, never prompt."auto": send sanitized reports to a configured endpoint.- Implement the plumbing behind an interface, with a Sentry adapter (
@sentry/electron,sendDefaultPii: false,beforeSendrunning the same sanitizer, no breadcrumbs of user data) enabled only when a DSN is configured at build time. - Public builds ship without a DSN. Enabling it is a maintainer decision and would be documented in the privacy stance first.
- Implement the plumbing behind an interface, with a Sentry adapter (
Tests: the sanitizer gets a corpus-based unit test (fixtures containing GUIDs, UPNs, IPs, JWTs, paths, KQL). Every sensitive token must be removed.