---
title: Agent Analytics privacy modes
description: "Compare the three Agent Analytics privacy modes (full, metadata_only, customer_enriched), what each one sends to Amplitude, and how to choose one before rollout."
product: general
lang: en
token_estimate: 936
---
# Agent Analytics privacy modes

> For AI agents: a documentation index is available at [/docs/llms.txt](/docs/llms.txt). Append `.md` to any page URL for markdown, or send `Accept: text/markdown`.

An Agent Analytics privacy mode controls whether prompt and response text leaves your infrastructure. There are three modes: `full` sends message content, `metadata_only` sends none, and `customer_enriched` sends none but uses quality labels you compute yourself. Every mode still sends tokens, cost, latency, model names, and session grouping.

Choose the mode before wide rollout, because it determines what your legal review needs to cover. Regulated environments, such as healthcare and finance, typically run `metadata_only` or `customer_enriched`.

## What each mode sends

|  | `full` (default) | `metadata_only` | `customer_enriched` |
| --- | --- | --- | --- |
| Message content (`$llm_message.text`) | Sent | Not sent | Not sent |
| System prompt | Sent | Not sent | Not sent |
| Tool inputs and outputs | Sent | Not sent | Not sent |
| Score comments | Sent | Not sent | Not sent |
| Tokens, cost, latency, models, session grouping | Sent | Sent | Sent |
| Amplitude enrichment (signals, evaluators) | Runs | Limited | Runs |
| Your own enrichment through `trackSessionEnrichment()` | Available | Available | Available |

Amplitude-generated enrichments (signals, topics, custom evaluators) run in every mode. What differs is what those enrichments see. In modes without content, content-dependent signals such as task completion and response quality carry less information. Structural signals, such as errors, behavioral friction patterns, cost, and latency, stay useful.

### `full`

Message content, system prompts, tool inputs and outputs, and score comments all reach Amplitude. Amplitude's built-in enrichment runs and produces the fullest signal set.

- The system prompt is optional, so you can omit it.
- The AI SDK redacts PII by default. It scrubs emails, phone numbers, SSNs, credit card numbers, and IP addresses before events leave your process. Built-in phone and SSN detection targets US formats. For international locales or domain-specific identifiers, add custom regex patterns or plug in your own redaction, such as Presidio.

### `metadata_only`

No message content, system prompts, tool payloads, or score comments leave your process. You still get tokens, cost, latency, model names, and session grouping, so analyses that don't need content still work.

### `customer_enriched`

No content leaves your process. Amplitude enrichment runs on the labels you send through `trackSessionEnrichment()` instead, so your labels are the only session-level quality data.

You can send Session Enrichment events in any mode. `customer_enriched` is the mode where those events are the only source of session-level quality data.

## Apply the mode

How you apply the mode depends on your instrumentation path:

- **AI SDK (Node, Python)**: Set `contentMode` (Node) or `content_mode` (Python) once on `AIConfig`. The SDK routes every content-bearing channel through one gate. Refer to [Choose a privacy mode](https://amplitude.com/docs/sdks/agent-analytics/sdk#choose-a-privacy-mode) in the SDK reference.
- **OpenTelemetry**: Turn content capture on or off in your OpenTelemetry instrumentation. Refer to [Apply your privacy mode](https://amplitude.com/docs/amplitude-ai/agent-analytics/instrument-opentelemetry#apply-your-privacy-mode).
- **HTTP API or a standard Amplitude SDK**: You redact or omit four content-bearing properties yourself, before you call `track()`. Refer to [Redact content before tracking](https://amplitude.com/docs/amplitude-ai/agent-analytics/instrument-http-api#redact-content-before-tracking).

