Does Cardinal read my prompts?
No. No prompt or response text is ever collected, from anyone.
What Cardinal receives from your Claude use
- Telemetry from Claude Code: usage events and metrics such as tokens, cost, models, active time and counts of prompts and tool results. Claude Code can include prompt and response text in telemetry only if special options are turned on. Cardinal never turns them on.
- A session-end hook: when a session closed and the folder it ran in. It carries no prompt text.
That is why Me says "No prompt or response text is ever collected."
What managers see
Managers see numbers about the people who report to them, for the time they reported to them: hours, sessions, cost, waste patterns and the folders sessions ran in. They don't see what anyone typed, and they don't see your briefing text, your Ask the guide questions or the answers.
AI jobs Cardinal sends to your computer
When Cardinal drafts something, it sends your runner a job made from Cardinal's own data: an invoice's lines, a quote, a day's session titles, your computed numbers, or the help articles that match your question. Your runner answers with your own claude -p, which:
- uses no tools and no MCP servers
- loads none of your settings, hooks or plugins
- saves nothing to your Claude session history
The answer comes back to Cardinal and is written onto the draft.
Your Claude login
Cardinal never sees, stores or passes on your Claude login. The installer doesn't touch your keychain, credentials or API keys, and the runner never sends anything that looks like one.
The workspace owner's tracker
On the workspace owner's own Mac, the collector reads session history to count time and estimate traditional-build hours. It sends numbers and a short estimate, not the conversation.