What Microsoft is disputing
Microsoft has rejected claims that Windows 11 has introduced a new background service intended to track users. The concern centres on a performance-diagnostics mechanism associated with the Windows Health and Optimized Experiences service, sometimes seen through its local diagnostic-output folder, Whesvc.
The feature is not a newly disclosed addition to Windows 11. Microsoft described it in a Windows Insider release note published in July 2025, when it said that logs could be collected after a PC experienced slow or sluggish performance. Those files are stored locally in a temporary Windows directory. Microsoft said they are sent only when an Insider submits feedback through Feedback Hub under the specified performance category.
That distinction is important. A component that records local diagnostic material in anticipation of a user-submitted report is not, on the evidence available, the same thing as an always-on service created to transmit browsing or behavioural records automatically. Calling it a “new tracking service” overstates what Microsoft has publicly documented.
Why the service still raised alarm
The reaction is understandable. Windows processes often have opaque names, run with elevated privileges and provide little explanation in Task Manager about precisely what they collect, when they run or how long their output remains on a device. A temporary directory called DiagOutputDir may be technically meaningful to engineers, but it does not reassure people already concerned about operating-system telemetry.
Microsoft’s 2025 wording also leaves room for questions. It says logs are collected when the computer has experienced slow or sluggish performance, rather than saying that logging begins only after a person first opens Feedback Hub. The company’s account is that the material remains local and becomes available for upload only when feedback is submitted. Still, users and administrators reasonably want more technical detail: the triggers that create a trace, the categories of data captured, retention rules and whether the behaviour remains confined to Insider builds or later reaches wider releases.
Performance traces can be valuable for diagnosing intermittent slowdowns that developers cannot reproduce in a laboratory. Depending on how they are designed, however, such logs can also contain sensitive context, including process information, timestamps, system configuration and application activity. Local storage and user-controlled submission reduce the privacy impact, but do not remove the need for clear documentation and safeguards around access to the files.
Existing Windows data collection is a separate issue
The claim about the performance feature should not be treated as a full answer to the broader Windows privacy debate. Windows already has established mechanisms for collecting required service data and diagnostic data. Microsoft separates required service data, used to deliver connected experiences and essential services, from diagnostic data used to maintain, secure and improve Windows.
Microsoft says required service data is normally ephemeral and typically discarded within 48 hours after the relevant service is provided. It also says optional diagnostic data can include information about device configuration, product usage, performance, software inventory and, in defined circumstances, browsing history, in addition to identifiers used to correlate diagnostic events. Settings and organisational policies affect some categories of collection, but required service data is not governed by the same controls as diagnostic-data settings.
That framework means two statements can be true at once: the disputed sluggishness logging feature may not be a new covert tracking system, while Windows can still collect meaningful data through other documented channels. Privacy analysis must therefore focus on the particular data flow rather than treating every service as equivalent.
The GDID disclosures changed the context
Recent reporting around Microsoft’s Global Device Identifier, or GDID, has made the timing especially sensitive. A US federal complaint in the case against alleged Scattered Spider member Peter Stokes described Microsoft records that investigators used to associate a Windows installation with online activity. The Justice Department stresses that a criminal complaint is an allegation, not proof of guilt, but the filing has nonetheless brought the identifier and the persistence of device-linked records into public view.
GDID is distinct from the 2025 performance-log mechanism. Conflating them risks obscuring the facts of both issues. The former concerns an identifier that can help correlate records associated with a Windows installation; the latter concerns local performance traces intended to accompany voluntary Feedback Hub reports. Yet the public response shows why Microsoft cannot expect users to evaluate such distinctions without accessible, specific explanations.
For many people, the question is not whether a single component meets a narrow definition of spying. It is whether they can identify the data their computer produces, understand which services receive it, control non-essential collection and assess the consequences of a persistent identifier being linked to service records.
A better standard for transparency
Microsoft’s clarification appropriately corrects the central factual claim: there is no evidence that the sluggishness feature is a newly deployed service that secretly uploads performance traces as routine surveillance. Users should not disable Windows services on the basis of viral descriptions alone, particularly because doing so can impair updates, security functions or troubleshooting.
But a denial is only the first step. Microsoft could reduce uncertainty by publishing a plain-language technical note for the feature, including the builds in which it exists, the exact data fields that may enter a trace, the conditions that generate a trace, its deletion schedule and the feedback-submission path that authorises transfer. It should also make clear where the feature sits relative to required and optional diagnostic data.
In security and privacy, trust depends less on broad assurances than on verifiable boundaries. The performance-logging controversy may not reveal a new tracking service, but it does reveal a continuing gap between how Windows explains data collection and how many users experience it.
Sources
- Microsoft Denies New Tracking Service in Windows 11 — TechPowerUp
- Announcing Windows 11 Insider Preview Build 26200.5710 (Dev Channel) — Microsoft
- Required service data for Windows — Microsoft Learn
- Optional diagnostic data for Windows 11 and Windows 10 — Microsoft Learn
- Affidavit in United States v. Peter Stokes — US Department of Justice



