11.1 — What Claude Code sends (and doesn't send)
The first legitimate question when you introduce Claude Code to a team: what data leaves your machine? The answer is transparent and verifiable.
Claude Code is a local client that communicates with the Anthropic API. Three categories of data are sent: your prompts (what you type and the history of the current conversation), the content of files read (only those Claude consults via the Read tool to accomplish a task), and the outputs of executed commands (result of git diff, test output, etc.). This data constitutes the context the model needs to respond.
What is not sent: your entire codebase at startup (no global scan), your system environment variables, your SSH keys, your global configuration files, or the content of directories outside the project. The context size is limited (up to 1M tokens depending on the model), Claude Code couldn't send gigabytes even if it wanted to.
The flow is controllable in real time. Each tool call (Read, Bash, Grep) is visible in the interface. In default mode, nothing leaves without your explicit approval, it's an "explicit consent" model. And when you close your session, the context disappears. The next conversation starts from scratch.
┌─────────────┐ ┌──────────────────┐
│ Your machine│ ───────► │ Anthropic API │
│ │ Sent: │ │
│ - prompts │ 1. Prompts │
│ - files │ 2. Files read │
│ - terminal │ 3. Command outputs │
└─────────────┘ └──────────────────┘
✗ No global scan
✗ No system env variables
✗ No SSH keys
✗ No silent telemetry
Key takeaways
• Only files explicitly read, prompts, and command outputs are sent.
• No global repo scan at startup, Claude reads on demand.
• Every action is visible and requires approval in default mode.
• The context is ephemeral: it disappears at the end of the session.