xAI Confirms Grok CLI Uploaded 5 Gigabytes to Review 192 Kilobytes; Calls This Thoroughness
SAN FRANCISCO — xAI confirmed Monday that its Grok Build command-line tool had been transmitting users' complete code repositories — including configuration files, cloud credentials, and API keys — to a Google Cloud Storage bucket named grok-code-session-traces, and characterized the practice as intentional, beneficial, and disclosed in the product's terms of service.
The confirmation followed a wire-level traffic analysis published to GitHub, which reached the front page of Hacker News with 353 points and found that a test repository of 12 gigabytes generated 5.10 gigabytes of outbound upload traffic while the model's inference channel received 192 kilobytes of data — a ratio of approximately 27,800 to one.
"We upload the full context so Grok can reason comprehensively," said a company spokesperson. "The model used 192 kilobytes. The other 5.09 gigabytes were there in case."
The analysis additionally found that running the CLI with the --no-telemetry flag did not reduce uploads. xAI said the flag governed a separate category of telemetry and that the session-trace uploads were a distinct system the flag was not designed to affect. The company said it planned to add documentation clarifying the distinction and was targeting the third quarter of 2027 for that update.
In response to developer concerns, xAI announced a new Trace Transparency add-on, available through the $19-per-month Grok Pro tier, which would provide users a downloadable manifest of what had been uploaded within 72 hours of the session completing.
"Developers deserve full visibility into what we sent," the spokesperson said. "We are providing it, retroactively, for a small monthly fee."