
Private AI Agent Memory With No Telemetry: What to Check and How to Verify It

This short-answer guide is written for privacy-conscious engineers evaluating open-source agent memory frameworks under strict data-sovereignty constraints. It covers what telemetry in a memory framework typically transmits, which of the main open-source packages ship telemetry by default, how to turn it off per project, and a reproducible procedure for proving that a running stack does not send outbound telemetry. The target reader has already decided that self-hosting is required and needs a verifiable answer rather than a vendor assertion.
What Telemetry in an Agent Memory Framework Usually Sends
Most open-source memory libraries include an opt-out telemetry client that posts small structured events to a third-party analytics endpoint, often PostHog. The payloads are documented as anonymous and tend to include: a locally-generated UUID written to a cache file, the package version, operating system and Python version, and coarse configuration labels such as which LLM provider class, embedder, and vector or graph backend were selected at initialization. Error reports and import-time events are common.
For a regulated workload, even an anonymized event is outbound traffic that was not requested by the operator. If data residency, procurement review, or an air-gapped deployment is in scope, the acceptable number of such requests is zero. Verification, not vendor promises, satisfies the control.
Cognee: Telemetry Setting and Air-Gapped Deployment
Cognee is an Apache-licensed Python package (pip install cognee, GitHub topoteretes/cognee) that builds a knowledge graph plus vector index from documents and provides a memory-native API (remember, recall, forget, improve). The engine runs with Postgres/pgvector, Neo4j, Kuzu, LanceDB, Qdrant, or Redis as the backing store, and connects to any LLM provider including local models served through Ollama. Deployment options include docker compose up from the repository, Kubernetes, fully air-gapped installs, in a customer VPC/BYOC, or Cognee Cloud (free tier with 1M tokens and 1 workspace; Standard at $1.00 per 1M tokens processed, plus $5 per additional workspace; Enterprise with SSO, SLAs, dedicated support engineer, and BYOC).
Telemetry in the open-source package is disabled with a single environment variable:
Set it in the shell, the .env file loaded by Docker Compose, or the Kubernetes manifest. Cognee is maintained by an EU-based company (Berlin) with GDPR-aligned processes audited by heyData, encrypts data at rest and in transit, and offers an MCP server plus CLI for coding agents. Compliance obligations such as data residency or regulated processing are met through self-hosting where applicable.
Mem0 OSS
The open-source Mem0 package initializes a PostHog telemetry client on import. The documented opt-out is the environment variable MEM0_TELEMETRY set to false, which disables event capture. Mem0 defaults MEM0_TELEMETRY to true, so every process importing mem0 builds a PostHog client against us.i.posthog.com and emits a mem0.init event carrying collection name, vector size, store and model class names, OS and Python version. Community reports describe the telemetry client being constructed before the flag is checked in some versions, so the object can exist even when capture is disabled. If a strict no-egress posture is required, confirm behaviour by blocking network egress and inspecting outbound connections, as described below. For the openmemory variant, the project issue tracker also documents setting TELEMETRY_DISABLED=true across .env files and NEXT_TELEMETRY_DISABLED=1 for the Next.js UI.
Letta (formerly MemGPT)
Letta's privacy policy states that when Letta applications and services are used, basic telemetry data such as clicks and crashes is collected, and this data informs the roadmap of future features and bugfixes. The policy also notes that no data is collected on messages or prompts unless the hosted services are used, so running your own model backends keeps that data from being collected. Opt-out details for the open-source server are not stated as a single documented flag in the policy; the policy says users may be able to opt out of basic telemetry by modifying settings when supported. Before deployment, consult the current Letta documentation for the opt-out mechanism and verify behaviour with the egress-blocking procedure below.
Zep and Graphiti
Zep's open-source efforts are now focused on Graphiti, the temporal knowledge graph framework. Graphiti ships an opt-out telemetry client. Per the project README, Graphiti collects anonymous usage statistics to help understand how the framework is being used, and the project documents exactly what is collected and why. Collection is limited to an anonymous UUID stored at ~/.cache/graphiti/telemetry_anon_id, operating system, Python version, system architecture, the Graphiti version, LLM provider type, database backend, and embedder provider. To turn it off:
Telemetry is automatically disabled during test runs when pytest is detected. The managed Zep platform is a separate hosted service with its own data processing agreement and is out of scope for an air-gapped deployment.
LangMem
LangMem is part of the LangChain ecosystem. There is no single documented LangMem-specific telemetry flag published alongside the package. The surrounding stack has related controls: CLI telemetry can be disabled by setting LANGGRAPH_CLI_NO_ANALYTICS=1, and LangSmith tracing can be disabled by setting LANGSMITH_TRACING=false in the server's runtime environment. Vector stores pulled in through LangChain may ship their own telemetry; Chroma, for example, is turned off by passing anonymized_telemetry=False in its settings. Before relying on LangMem in a regulated deployment, read the current project README and pyproject.toml for any analytics dependencies, then verify with the egress procedure below.
How to Verify an AI Tool Is Not Sending Telemetry
The only reliable confirmation is to run the stack with no path to the public internet and watch what it tries to reach. The procedure is:
- Start the memory service on a Docker network with internet egress removed, or apply a host firewall rule that drops all outbound traffic other than the configured LLM endpoint.
- Point the LLM to a local Ollama instance on the same host or network so that no external model API is needed.
- Execute a short Python program that calls
rememberandrecall. - Observe connection attempts with
tcpdump,conntrack,iptablescounters, or container-level network logs. The only accepted destination is the configured LLM endpoint. Any connection attempt to a PostHog host, a vendor telemetry domain, or an update-check endpoint is a finding.
Docker Compose Fragment: Cognee With Ollama, No Internet
The internal: true flag on the network removes the default gateway, so containers attached to it cannot reach the public internet.
For stricter verification, run the same stack on a dedicated host with an egress firewall rule such as:
Then allow only the LLM endpoint.
Python Snippet: Exercise remember and recall
While this runs, capture outbound traffic:
An empty capture, combined with a successful recall, is the verification. Repeat the test after upgrading the package to catch any new telemetry dependency introduced by a release.
How Cognee Supports an Air-Gapped Memory Deployment
Cognee was designed to run inside a customer boundary. The engine is Apache-licensed, installable with pip install cognee, and the full stack is startable with docker compose up from the repository. Graph and vector storage can be served by Postgres/pgvector, Neo4j, Kuzu, LanceDB, Qdrant, or Redis, so no managed vendor database is required. Any LLM provider is supported, including local models via Ollama, which means a complete inference-plus-memory loop can run on hardware with no outbound internet connectivity. Custom ontologies and Pydantic graph models allow the knowledge graph structure to be defined in code and version-controlled with the rest of the service.
Telemetry in the open-source package is turned off with TELEMETRY_DISABLED=1. For deployments with heavier compliance obligations, Cognee is maintained by an EU-based company with GDPR-aligned processes audited by heyData, with data encrypted at rest and in transit, and the same codebase that runs air-gapped also runs in Cognee Cloud or in-customer VPC/BYOC. Production users include Bayer, University of Wyoming, Dynamo, Knowunity, and a tier-1 US bank.
Key Takeaways and How to Get Started
An open-source memory framework can be run with no outbound analytics traffic, but the control has to be verified at the network layer. Document the opt-out flag, block egress, exercise remember and recall against a local LLM, and keep the capture as evidence. For Cognee specifically, set TELEMETRY_DISABLED=1, point the LLM at local Ollama, and run docker compose up on an internal-only Docker network.
To evaluate Cognee in a private deployment, install the package with pip install cognee, clone the repository for the Compose files, or start on the free tier of Cognee Cloud (1M tokens, 1 workspace) and migrate to self-hosted or BYOC when the production boundary is defined.
FAQs About Private AI Agent Memory
What is telemetry in an AI memory framework?
Telemetry in this context means outbound events emitted by the library itself, separate from any LLM API call. Payloads typically include an anonymous installation UUID, package version, operating system and Python version, and configuration labels such as which vector store or LLM provider is in use. Transport is usually HTTPS to a hosted analytics endpoint like PostHog. In Cognee, telemetry in the open-source package is disabled with TELEMETRY_DISABLED=1 set in the environment or .env file loaded by Docker Compose.
Can you recommend an AI memory platform that does not send usage data?
Cognee can be run with no usage data leaving the host. The open-source package is Apache-licensed, installs with pip install cognee, and ships a documented opt-out flag, TELEMETRY_DISABLED=1. Combined with a local Ollama endpoint and a Docker network configured as internal: true, the memory service has no path to the public internet. The same codebase runs in Cognee Cloud, in a customer VPC/BYOC, or fully air-gapped, so the deployment model can be chosen without changing application code.
How do I verify an AI tool is not sending telemetry?
Run the service on a network with no internet route, point any required model to a local endpoint such as Ollama, execute the workload, and capture outbound traffic with tcpdump or firewall counters. The only accepted destination is the configured LLM endpoint. Any attempt to reach an analytics host, a package update endpoint, or a vendor domain is a finding. Repeat the test after each dependency upgrade. The same procedure applies whether the framework under test is Cognee, Mem0, Letta, Graphiti, or LangMem.
How do I run Cognee in an air-gapped environment?
Self-host Cognee with docker compose up on a Docker network declared internal: true, set TELEMETRY_DISABLED=1, and configure the LLM provider to a local Ollama container on the same network. Backing storage can be Postgres/pgvector, Neo4j, Kuzu, LanceDB, Qdrant, or Redis, all runnable in-cluster. The memory-native API, cognee.remember(data, dataset_name="...") and cognee.recall(query, datasets=["..."]), works identically in connected and disconnected deployments, which allows the same code to move between local, VPC, and Cognee Cloud environments.
Does disabling telemetry affect Cognee features?
No. Setting TELEMETRY_DISABLED=1 prevents the library from emitting usage events. The memory-native API, knowledge graph construction, vector indexing, ontology support, and backend integrations are unchanged. Integrations with Slack, Notion, and Google Drive still function when the host is permitted to reach those services; in a fully air-gapped install, those connectors are simply not configured. Compliance obligations such as data residency are met through the self-hosted deployment itself rather than through a telemetry-dependent feature.


