What is rtcreportingd on Mac?
Last updated: 2026-07-31
rtcreportingd is an Apple system daemon that collects diagnostic and usage telemetry when analytics sharing is enabled. Apple has not published its complete client list, payload fields, or a normal traffic range. You can stop automatic Mac analytics sharing in System Settings without deleting the daemon.
What it is
rtcreportingd is a system daemon supplied with macOS and started by launchd. Its executable is installed at /usr/libexec/rtcreportingd, it is signed by Apple for the platform, and it is registered through a system LaunchDaemon. Finding it in a process list or network monitor is therefore not, by itself, evidence that unwanted software has been installed.
The rtcreportingd manual page describes a narrower and more useful purpose: after a user opts into sharing analytics, the daemon locally collects diagnostic and usage telemetry. Apple components that use the private RTCReporting framework can submit session and event reports to it. Apple has not published a complete list of those components, nor has it documented all of the fields that may appear in the reports.
The letters “RTC” are not enough to establish that rtcreportingd currently exists only for FaceTime or video messages. Historical associations or suggestive internal names do not prove the present client list. The verified description is diagnostic and usage telemetry; FaceTime and Messages as current clients remain unverified.
Why it talks to the network
When Share Mac Analytics is enabled, Apple components using RTCReporting can pass session and event telemetry to rtcreportingd. The daemon may cache events and send them together later, or send them sooner when directed by server-side configuration. If the Mac is offline, analytics data can remain on the machine until a network connection becomes available and then be submitted.
Inspection of the Apple binary also shows another possible connection. rtcreportingd may make an HTTPS request to pancake.apple.com to obtain signed reporting configuration. It can then contact Apple telemetry backends named by that configuration. Apple has not published the current event-backend domain names, so seeing another Apple destination does not justify guessing which service it represents.
Apple also does not publish a complete list of software currently submitting reports through this daemon. In particular, there is not enough public evidence to state that a connection was triggered by FaceTime or Messages merely because rtcreportingd made it. Its verified network purpose is reporting telemetry and obtaining reporting configuration, not carrying a live audio or video stream.
How much traffic is normal
There is no reliable published number for normal rtcreportingd traffic. Apple provides no daily budget, per-session allowance, fixed upload frequency, or supported range that can be quoted as a threshold. Claims such as “a few megabytes per day” or “one small upload after every call” would add precision that the available evidence does not support.
Its implementation points toward intermittent configuration requests and event telemetry. That would ordinarily be much smaller than a real-time audio or video media stream, but this is a comparison of functions rather than a measured limit. It cannot support a promise that the process will always remain below a particular amount.
Traffic may also arrive in bursts because reports can be cached while the Mac is offline and submitted after connectivity returns. A short burst is therefore not enough to infer continuous monitoring, while sustained heavy transfer should not automatically be accepted as normal. The useful baseline is what the process actually transfers on the particular Mac over a clearly defined time window.
Can you turn it off
For users who do not want to share Mac analytics automatically, Apple provides this setting:
System Settings > Privacy & Security > Analytics & Improvements > Share Mac Analytics
Turning Share Mac Analytics off stops automatic sharing of the Mac’s diagnostic and usage analytics with Apple. The consequence is that Apple receives less information that could help it identify failures and improve products. This setting does not turn off FaceTime or Messages.
It also does not uninstall rtcreportingd. The process can remain installed, appear in process listings, or be started by the system after analytics sharing has been disabled. Apple’s public support material does not name rtcreportingd when describing a one-to-one relationship with this switch; the association comes from the daemon’s opt-in description in its manual page and the system-wide analytics control.
Deleting the executable or its LaunchDaemon is not the supported way to express this privacy choice. rtcreportingd is a protected system component, and launchd may restart it after it is forcibly ended. The setting changes analytics sharing without modifying protected operating-system files.
What people get wrong
- “
rtcreportingdis malware, a listening implant, or a remote-control tool.” That identification is incorrect. It is an Apple platform-signed executable under/usr/libexec, registered as a built-in system LaunchDaemon. Its mere presence and occasional network activity are expected properties of the installed system component.
- “RTC proves that it only reports FaceTime and video-message call quality.” The name does not prove that scope. Apple’s current public description says that the daemon collects diagnostic and usage telemetry, while the complete list of clients is not published. FaceTime or Messages may look plausible from the name and historical context, but their current use of the daemon has not been verified.
- “It is uploading my live call audio or video.” There is no evidence that the verified job of
rtcreportingdis media transport; the established role is telemetry reporting. The opposite absolute claim also goes too far, however. Because Apple has not published the payload schema, it is not possible to present “its reports never contain any call content” as a verified fact.
- “It always uploads a fixed small amount each day.” Apple publishes no normal daily quantity, frequency, or per-session figure for
rtcreportingd. Cached reports, network availability, submitted events, and reporting configuration can affect when activity appears. No specific megabyte number should be treated as an official or independently verified baseline.
- “Deleting it or repeatedly killing it will optimize the network.”
rtcreportingdis protected as part of macOS, andlaunchdcan start it again. Removing system files or repeatedly ending the process does not represent the documented privacy control. Share Mac Analytics is the available system setting for stopping automatic diagnostic and usage analytics sharing.
Seeing what it actually used
Open Bytetally, locate rtcreportingd, and check its measured uploads and downloads over a time window that covers the activity you are investigating. Compare a normal connected period with any burst seen after the Mac was offline, without assuming that one observation establishes a universal baseline. If transfer remains unusually large or sustained, preserve the time range and destinations for further investigation instead of classifying it as normal from the process name alone.
Related processes
Common questions
Is rtcreportingd malware?
No. It is an Apple platform-signed system daemon installed under /usr/libexec and registered as a system LaunchDaemon.
Is rtcreportingd only used by FaceTime?
That has not been verified. Apple describes its role as collecting diagnostic and usage telemetry but does not publish a complete list of current clients.
Can I disable rtcreportingd?
You can turn off Share Mac Analytics under System Settings > Privacy & Security > Analytics & Improvements. This stops automatic sharing of Mac diagnostic and usage analytics, but it does not uninstall the daemon.
How much data should rtcreportingd use?
Apple provides no reliable daily allowance, per-session figure, or normal range for this process. Its implementation suggests intermittent configuration and telemetry transfers, not a guaranteed fixed amount.
Does rtcreportingd upload FaceTime audio or video?
There is no evidence that its verified role includes transporting live call media. However, Apple has not published its payload schema, so claims that its reports can never contain any call-related content are also unverified.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account