What the installer changes on your computer
The install line changes a small, fixed set of things. It never touches your Claude login, keychain or API keys.
Files it writes
On a Mac:
~/.config/cardinal/cardinal-runner.mjs: the runner, one file with no dependencies, downloaded from your Cardinal.~/.config/cardinal/runner.json: your Cardinal address, your member key, and whereclaudeis. Readable only by you.~/Library/LaunchAgents/dev.ramcore.cardinal.runner.plist: the login item that keeps the runner going.~/.config/cardinal/runner.log: the runner's log.
On Windows:
%LOCALAPPDATA%\Cardinal\cardinal-runner.mjs: the runner.%APPDATA%\Cardinal\runner.json: your Cardinal address, member key and whereclaudeis.- A Scheduled Task called "Cardinal runner", for your user only.
The runner also keeps a runner-work folder next to runner.json for temporary job files. Each job's files are removed when it ends.
Claude settings it adds
Your Claude Code user settings file is ~/.claude/settings.json on a Mac and %USERPROFILE%\.claude\settings.json on Windows. The installer merges in:
- Telemetry settings under
env:CLAUDE_CODE_ENABLE_TELEMETRY, theOTEL_...exporter settings that point at your Cardinal with your key, andCARDINAL_SETUP_VERSION. - One
SessionEndhook that tells Cardinal when a session closed and in which folder.
Everything else in the file is kept. Before writing, it saves a copy next to the file, named settings.json.cardinal-backup- followed by the date and time. If your file has a JSON error, it stops and changes nothing, and tells you the line number.
What is not sent
Cardinal never sets the options that would log prompt or response text, so none is sent. The session-end hook carries no prompt text either.
Claude Desktop and Cowork
Claude Desktop's Code tab reads the same settings file, so its sessions are counted too. Cowork doesn't read these settings on individual plans; on Claude Team or Enterprise, your admin turns on Cowork telemetry in the admin console instead.