Logging and privacy
The CLI keeps a local, size-capped log of the Hypertext Transfer Protocol (HTTP) exchanges it performs. The log exists for troubleshooting on your machine; the CLI sends no telemetry.
What is logged
By default each request produces one newline-delimited JSON (NDJSON) line with metadata only:
Response bodies
Pass --log-bodies on a command, or set DEEL_LOG_BODIES=1, to include the full URL and the response body in the log entry. Keys whose names suggest sensitive data are masked as ***, matched case-insensitively by substring: token, password, secret, authorization, credential, api_key, ssn, tax, iban, swift, email, phone, dob, birth, address, bank, card, cvv, pin, passport, national_id, routing, account_number, and similar.
Masking is best effort. A response body can still contain personal data under other keys. Enable body logging only while diagnosing a problem, and delete the log afterwards.
Log location
The log file lives in a platform-specific default location:
DEEL_LOG_DIR overrides the directory. The directory is created with mode 0700 and the file with mode 0600, so only your OS user can read them.
Rotation
When the file reaches DEEL_LOG_MAX_SIZE bytes (default 10 MiB) it is renamed to deel.log.1, previous files shift up, and at most DEEL_LOG_MAX_FILES (default 5) rotated files are kept.
Disable logging
Turn off logging for one command or for every command:
Logging is fail-open: if the log directory cannot be written, the command still runs.