TokenTracker

Privacy Policy

Last updated: 2026-10-08 · Applies to the tokentracker-cli npm package, the macOS app, the Windows app, the Linux app, and www.tokentracker.cc.

TokenTracker reads the local logs that AI coding tools already write to your disk, and turns them into token counts and cost estimates. It is local-first: the dashboard, the parsers and the database all run on your machine.

This document lists every network request the software can make, what each one sends, and how to switch it off. If you find a request that is not listed here, that is a bug — please open an issue.


1. What never leaves your machine

TokenTracker's parsers extract numbers and timestamps only. TRAE Work CN is a narrow exception to the local-only source model, and it is off by default: only when you explicitly set TOKENTRACKER_TRAE_CN_USAGE=1, during an eligible non-background sync, when local TRAE Work CN auth exists, does TokenTracker transmit the existing sign-in authorization from the locally signed-in app to TRAE's internal API for a read-only usage request. Without that variable nothing is ever sent. It is not an unconditional or default generic network request. That authorization is never persisted or logged.

Never retained as usage data or uploaded to TokenTracker:

Recorded locally, never uploaded:

You can verify this in src/lib/rollout.js: every parse*Incremental function emits only the queue row shapes described below.


2. What is stored locally

Everything lives under ~/.tokentracker/ (%USERPROFILE%\.tokentracker\ on Windows):

Path Contents
tracker/queue.jsonl Append-only hourly buckets: source, model, token counts, timestamp
tracker/project.queue.jsonl The same hourly buckets, split per project: git remote URL and owner/repo key. Never uploaded
tracker/session.queue.jsonl Per-session token totals and timing for the Sessions view, plus each session's working directory. Never uploaded
tracker/cursors.json Read offsets so parsing stays incremental
tracker/config.json Your preferences
tracker/*-usage-limits-cache.json Last successful quota reading per provider, so a timeout shows stale bars instead of an error
pets/, skills/, cache/ Desktop pet assets, skill index, misc caches

To erase everything TokenTracker knows about you, delete that directory. tokentracker uninstall additionally removes the hooks it installed into your AI tools.


3. Network requests

3.1 Enabled by default

Request Destination What is sent Frequency
Anonymous heartbeat srctyff5.us-east.insforge.app A one-way hash of the machine id, plus the app version, OS platform, and app shell (cli / macos / windows / linux) as separate plain fields. Nothing else. At most once per day
Dashboard analytics us.i.posthog.com (PostHog) Pageviews and explicitly instrumented feature events, plus which shell you use. Autocapture and session recording are off; browser Do-Not-Track is respected. While the dashboard is open
Provider quota reads The provider's own API (api.anthropic.com, chatgpt.com, cursor.com, api.github.com, api.kimi.com, api.z.ai, qoder.com, qoder.com.cn, openapi.qoder.sh, openapi.qoder.com.cn, cloudcode-pa.googleapis.com, …) Whatever that provider's own endpoint requires, authenticated with the credentials that provider already stored on your machine. These requests go directly from your machine to the provider — they never pass through our servers, and we never see the response. While quota bars are visible
TRAE Work CN usage read TRAE's internal API Transmits the existing sign-in authorization from the locally signed-in TRAE Work CN app to TRAE; reads usage metadata only. TokenTracker never persists or logs the auth token or prompt/response content. Off unless you set TOKENTRACKER_TRAE_CN_USAGE=1; then during eligible non-background sync when local TRAE Work CN auth exists
GitHub star count api.github.com Nothing but the request itself (public repo metadata) On dashboard load
Update check api.github.com Nothing but the request itself Windows: once at launch. macOS: only when you click "Check for Updates"
Pricing data refresh raw.githubusercontent.com Nothing but the request itself (public model pricing JSON from BerriAI/litellm) At most once every 24 hours when the local pricing cache is missing or stale

Both telemetry items are disabled together by a single switch:

export TOKENTRACKER_NO_TELEMETRY=1     # or DO_NOT_TRACK=1

You can also set "telemetry": false in ~/.tokentracker/tracker/config.json. On localhost and inside the desktop apps, the dashboard asks the local server for this preference before initialising analytics — and if the answer cannot be confirmed, analytics stays off (fail-closed).

Audit: src/lib/telemetry.js, dashboard/src/lib/analytics.js, src/lib/pricing/litellm-fetcher.js.

3.2 Only after you opt in or click something

Request Destination What is sent Trigger
Devin quota read server.codeium.com (Devin's official GetPlanStatus RPC) An empty JSON body, authenticated with the Devin CLI session token already stored on your machine. The token is never persisted or logged by TokenTracker. Off by default — only while the Devin provider switch in Settings → Usage & Limits → Providers is on, and only on a locally authenticated request
Cloud sync / leaderboard srctyff5.us-east.insforge.app Hourly buckets only — see §4 Signing in to a TokenTracker account
Exchange rates open.er-api.com Nothing but the request itself Selecting a non-USD display currency
Desktop pet download codex-pets.net The pet id you chose Importing a pet from a link
IP check page ip.net.coffee, claude.ai, 1.1.1.1 Your IP address is, by design, what these endpoints observe — that page exists to tell you how providers see your network Opening the IP Check page
Service status page Provider status pages (status.claude.com, status.openai.com, status.cursor.com, …) Nothing but the request itself Opening the Service Status page
Share card fonts fonts.googleapis.com Standard web-font request; Google can see your IP address Generating a share image

3.3 Never


4. Cloud account and leaderboard

Signing in is entirely optional. TokenTracker is fully functional without an account; the leaderboard, cross-device aggregation, badges and public profiles are the only features that require one.

Sent when signed in:

Not sent, ever:

Public visibility: your profile appears on the public leaderboard only while Settings → Account → Public profile is on. Turning it off removes you from the leaderboard and turns badges into a "private" placeholder.

Deleting cloud data: contact us privately at rynnsun0509@gmail.com and we will remove the account and its rows. Deleting ~/.tokentracker/ removes the local copy immediately.


5. Third parties

Service Role Their policy
InsForge Backend for accounts, cloud sync, leaderboard, heartbeat github.com/InsForge
PostHog Anonymous product analytics posthog.com/privacy
Vercel Hosting for www.tokentracker.cc vercel.com/legal/privacy-policy
GitHub Source hosting, releases, OAuth, star counts, upstream pricing data (raw.githubusercontent.com) GitHub Privacy Statement
Google OAuth sign-in, fonts on share cards policies.google.com/privacy

AI providers whose quota endpoints TokenTracker reads (Anthropic, OpenAI, Cursor, GitHub Copilot, Google, Moonshot, Z.ai, Qoder, Devin, …) are governed by their own policies. TokenTracker acts on your behalf with credentials already on your machine; it does not create any new relationship with them.


6. Turning things off

Variable Effect
TOKENTRACKER_NO_TELEMETRY=1 Disables the daily heartbeat and dashboard analytics
DO_NOT_TRACK=1 Same as above (respects the standard)
TOKENTRACKER_DISABLE_GIT_ATTRIBUTION=1 Stops TokenTracker running git log inside your project directories

Signing out removes cloud sync. Not signing in means it never starts.


7. Children

TokenTracker is a developer tool and is not directed at children under 13. We do not knowingly collect personal information from children.

8. Changes

Material changes to this policy will be noted in the release notes and in the Last updated date above. The full history is in this file's Git log.

9. Contact

Questions, corrections, or deletion requests: rynnsun0509@gmail.com. Do not publish private account or payment information in GitHub issues.

Planned Cloud billing

Paid Cloud has not launched. For the planned billing service, Waffo Pancake will operate hosted checkout and handle payment details under its own terms and privacy policy. TokenTracker will receive the order/payment reference, billing email, purchased plan, amount/currency, payment status, subscription term and refund status necessary to deliver access and handle billing. Full payment card numbers and security codes are not stored by TokenTracker. Only the usage metrics described above will be synchronized.

The planned membership provides access to 90 days of hourly details and 24 months of daily summaries. After membership expires, personal history has a 30-day read/export window. These are access windows, not a promise to delete all stored usage on the expiry date. Aggregated community statistics and compressed usage metrics may be retained to preserve and correct lifetime statistics. Necessary billing records may be retained to meet legal/accounting obligations and resolve payment disputes. Contact the private support address for access, correction or deletion requests; legally required records may be retained. Local data is unaffected by Cloud expiry.

TokenTracker is operated by Sun Xiufeng, an individual developer in China. Account and usage storage uses the existing InsForge backend, including infrastructure in the United States; other providers can process data in their operating regions. Contact rynnsun0509@gmail.com for privacy and security requests. This billing supplement was added on 8 October 2026 and describes the planned billing service. Paid Cloud is not yet open.