Privacy
ContextClues reads some of the most sensitive text on your machine, so it is worth being precise about where that text goes. The short version: nowhere.
The tool makes no network requests. It has no cloud service, no account, no authentication, and no telemetry. It reads session files that Claude Code has already written to your own disk, indexes them locally, and serves a dashboard on 127.0.0.1. Nothing is uploaded, and nothing you do in the dashboard is reported anywhere.
What the tool reads
- Session transcripts from
~/.claude/projects/and the session registry in~/.claude/sessions/. - Configuration that lists which tools are available:
~/.claude.json,~/.claude/settings.json, project-level.mcp.json, plugins and skills.
All of these are opened read only. ContextClues never modifies a file that Claude Code owns.
What the tool writes
One SQLite database at ~/.contextclues/, containing an index of your transcripts: sizes, timestamps, categories, tool names, and short redacted previews. Delete that directory at any time and it rebuilds itself from the transcripts.
Secret redaction
Transcripts routinely contain credentials, so every preview is scrubbed before it is written to the database or rendered in the browser. The redactor covers vendor API keys (Anthropic, OpenAI, Google, Stripe, AWS, GitHub, GitLab, Slack, npm, HuggingFace), JWTs, bearer tokens, private key blocks, passwords embedded in database connection strings, and assignments whose name looks secret.
Redaction is a safety net rather than a guarantee. It is pattern based, so a credential in an unusual format can slip through. If you find one, open an issue and it will be added.
Network exposure
The server binds the loopback interface (127.0.0.1) by default, so the dashboard is reachable only from your own machine and not from your local network. Passing --host 0.0.0.0 overrides that and exposes a view of your transcripts to anyone who can reach the port, so do that only on a network you trust.
This website
- No cookies. This site sets none, and stores nothing in your browser.
- No third-party requests. Fonts are served from this domain rather than a font CDN, so no other company sees your visit.
- Cookieless analytics. Aggregate page view counts are collected from this domain to gauge interest. No cookies are set, no personal data is stored, and visitors are not tracked between sites or across sessions.
The analytics apply to this website only. The ContextClues tool you install still makes no network requests of any kind.
Questions
The whole thing is open source and small enough to audit in an afternoon. The redaction rules live in lib/redact.ts, and every claim above is checked by the test suite. If something here does not match the code, that is a bug worth reporting.
Last updated 1 September 2026 · Source on GitHub