Cherry Studio privacy switch malfunctioning—turning off statistics still leaks device information

MarketWhisper

Cherry Studio privacy flaw

Open-source AI desktop client Cherry Studio found to have a privacy-design flaw: after users shut off the option “anonymously sending error reports and data statistics,” the client continues to transmit identification data including device IDs, system information, and CPU architecture. After GitHub user Yuerchu posted packet-capture screenshots in Issue #14387 , developer kangfenmao acknowledged in the comments that the problem is real.

Issue breakdown: three types of events vary in how strictly they follow the “off” setting

Cherry Studio privacy switch failure

(Source: Github)

According to code auditing, the Cherry Studio client reports three types of events, but the behavior of all three differs fundamentally:

AI conversations: normally complies with the user’s switch setting; once turned off, nothing is reported.

App launch: directly bypasses the switch setting; it will be reported regardless of how the user sets it.

Update checks: also directly bypasses the switch setting; it will be reported regardless of how the user sets it.

Each outbound request includes a dedicated device ID, plus an operating system version, CPU architecture, and the app version number—forming a long-term device identification and tracking combination.

Code audit: the switch was deliberately removed on March 22

Community members reviewed the code and found that when this reporting mechanism was first added in February 2026, the switch worked for all three event types. However, on March 22, maintainer kangfenmao submitted a change that didn’t just remove the switch-check logic for app launches and update checks—it also bundled additional device identification information into the request headers.

This problematic code ran continuously across four versions—v1.8.3, v1.8.4, v1.9.0, and v1.9.1—for about a month before the community discovered it and publicly disclosed it.

An even earlier old hole: a hidden script that silently re-enables the upgrade switch

While tracking older versions of the code, the community found another layer of the issue: when the analytics feature was first added in February 2025, an upgrade script was also embedded—whenever a user was upgraded from an older version, the “anonymous statistics” switch would automatically be turned on once. After that, although the analytics service backend was changed in sequence from Google Analytics to PostHog and Sentry, and then to the current self-hosted analytics.cherry-ai.com, this script that automatically turns the switch back on was never removed.

The practical impact is: users who installed Cherry Studio before February 2025 and then performed any upgrades—regardless of whether they previously manually turned off that setting—will have the switch silently re-enabled after every upgrade, and they must manually turn it off again after upgrading.

FAQ

What device information does Cherry Studio specifically collect?

According to code auditing, each reporting request contains: a unique device ID (persistent tracking across sessions), the operating system version, CPU architecture, and the app version number. This combination of information allows long-term identification and tracking of specific devices in the analytics backend; even without a name or account details, it can still form an effective device fingerprint.

Are sensitive data such as chat content and API keys also sent out?

Developer kangfenmao has explicitly stated that sensitive data such as chat content, user input, documents, and API keys does not go through this reporting channel and is outside the scope of impacted data. What is currently being sent is only device-identification-related metadata.

What actions should affected users take now?

The fixed version has been merged via PR #14390, and it is recommended that users update immediately to the latest version. After updating, users should manually confirm that the privacy statistics switch is turned off—because of the issue with the old upgrade script, the upgrade process itself may turn the switch back on again. If you have higher requirements for privacy, it is recommended that after updating you verify—using a network monitoring tool—that requests to analytics.cherry-ai.com have stopped.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

OristaPay Launches Telegram AI Payment Gateway with TON and BytePlus

Gate News message, April 23 — OristaPay, a brand under Yuanbi Technology, announced today at the TON AI Builders Day and Telegram AI Ecosystem Co-creation Summit in Hong Kong that it has established an end-to-end payment solution for AI agents operating on the Telegram ecosystem. During a live

GateNews1h ago

FTX Clears Cursor’s 5% Stake for $200k: SpaceX Valuation Now $200k

According to a CoinDesk report dated 4/23, the bankruptcy trustee of FTX sold approximately 5% of the Anysphere equity held by Alameda Research for $200,000 in 2023—the company behind the AI code editor Cursor. Based on the $60 billion valuation SpaceX has recently been in discussions about, that stake is now worth about $3,000,000,000, or 15,000 times the liquidation price from that year. Alameda acquired a 5% stake for $200,000 in 2022 CoinDesk noted that in April 2022, Alameda Research participated in Anysphere’s $400,000 round

ChainNewsAbmedia1h ago

BT and Nvidia-backed Nscale to Build 14MW AI Data Center Across UK Sites

Gate News message, April 23 — BT, a UK telecom company, announced a partnership with Nscale to develop AI data center capacity at three BT sites in the UK using Nvidia infrastructure. The project will deliver up to 14 megawatts of capacity, with BT providing site infrastructure and network

GateNews2h ago

Lenovo Opens AI Hub at Hong Kong-Shenzhen Tech Park

Lenovo opened an artificial intelligence innovation center on April 23 at the Hong Kong-Shenzhen Innovation and Technology Park, according to Xinhua. The move makes Lenovo one of the first large multinational technology companies to establish operations in the Hong Kong Park of the Innovation

CryptoFrontier4h ago

AI-Powered Web3 Games Take Center Stage as BuidlHack Seoul Crowns 'Bank or Plank' Champion

Gate News message, April 23 — YGG Play and Verse8 announced Bank or Plank as the winner of BuidlHack 2026's Casual Degen track, with 120 teams competing to build playable crypto-native games using AI tools in Seoul during Korea BUIDL Week. Bank or Plank, a 3D multiplayer pirate board game created b

GateNews5h ago

ByteDance Seed Team Releases Seed3D 2.0 with Enhanced Geometric Precision and Material Generation

Gate News message, April 23 — ByteDance's Seed team released Seed3D 2.0, a text-to-3D model that generates textured 3D assets from a single image. The upgrade focuses on geometric precision and material realism, with the API now available on Volcano Ark. Geometric generation employs a

GateNews5h ago
Comment
0/400
No comments