Privacy Policy
Last updated: 2026-10-08 · Applies to the tokentracker-cli npm package, the macOS app, the Windows app, the Linux app, and www.tokentracker.cc.
TokenTracker reads the local logs that AI coding tools already write to your disk, and turns them into token counts and cost estimates. It is local-first: the dashboard, the parsers and the database all run on your machine.
This document lists every network request the software can make, what each one sends, and how to switch it off. If you find a request that is not listed here, that is a bug — please open an issue.
1. What never leaves your machine
TokenTracker's parsers extract numbers and timestamps only. TRAE Work CN is a narrow exception to the local-only source model, and it is off by default: only when you explicitly set TOKENTRACKER_TRAE_CN_USAGE=1, during an eligible non-background sync, when local TRAE Work CN auth exists, does TokenTracker transmit the existing sign-in authorization from the locally signed-in app to TRAE's internal API for a read-only usage request. Without that variable nothing is ever sent. It is not an unconditional or default generic network request. That authorization is never persisted or logged.
Never retained as usage data or uploaded to TokenTracker:
- Prompts, responses, and conversation bodies — TokenTracker may parse local tool files containing conversation records to extract usage metrics, but prompt and response texts are never persisted, collected, or transmitted
- File contents from your projects
- Commit messages and diffs — Git attribution runs
git loglocally, uses the subject line only to detect reverts, and keeps nothing - API keys, cookies, and session tokens belonging to your AI providers are never persisted or logged by TokenTracker
Recorded locally, never uploaded:
- File paths, project names, and repository names. The Projects view needs to know which repo a session belonged to, so
project.queue.jsonlstores a project key and git remote URL, andsession.queue.jsonlstores each session's working directory. Both files stay on your machine — they are excluded from cloud sync (see §4) and the Projects view is computed entirely locally. SetTOKENTRACKER_DISABLE_GIT_ATTRIBUTION=1to stop deriving them at all.
You can verify this in src/lib/rollout.js: every parse*Incremental function emits only the queue row shapes described below.
2. What is stored locally
Everything lives under ~/.tokentracker/ (%USERPROFILE%\.tokentracker\ on Windows):
| Path | Contents |
|---|---|
tracker/queue.jsonl |
Append-only hourly buckets: source, model, token counts, timestamp |
tracker/project.queue.jsonl |
The same hourly buckets, split per project: git remote URL and owner/repo key. Never uploaded |
tracker/session.queue.jsonl |
Per-session token totals and timing for the Sessions view, plus each session's working directory. Never uploaded |
tracker/cursors.json |
Read offsets so parsing stays incremental |
tracker/config.json |
Your preferences |
tracker/*-usage-limits-cache.json |
Last successful quota reading per provider, so a timeout shows stale bars instead of an error |
pets/, skills/, cache/ |
Desktop pet assets, skill index, misc caches |
To erase everything TokenTracker knows about you, delete that directory. tokentracker uninstall additionally removes the hooks it installed into your AI tools.
3. Network requests
3.1 Enabled by default
| Request | Destination | What is sent | Frequency |
|---|---|---|---|
| Anonymous heartbeat | srctyff5.us-east.insforge.app |
A one-way hash of the machine id, plus the app version, OS platform, and app shell (cli / macos / windows / linux) as separate plain fields. Nothing else. |
At most once per day |
| Dashboard analytics | us.i.posthog.com (PostHog) |
Pageviews and explicitly instrumented feature events, plus which shell you use. Autocapture and session recording are off; browser Do-Not-Track is respected. | While the dashboard is open |
| Provider quota reads | The provider's own API (api.anthropic.com, chatgpt.com, cursor.com, api.github.com, api.kimi.com, api.z.ai, qoder.com, qoder.com.cn, openapi.qoder.sh, openapi.qoder.com.cn, cloudcode-pa.googleapis.com, …) |
Whatever that provider's own endpoint requires, authenticated with the credentials that provider already stored on your machine. These requests go directly from your machine to the provider — they never pass through our servers, and we never see the response. | While quota bars are visible |
| TRAE Work CN usage read | TRAE's internal API | Transmits the existing sign-in authorization from the locally signed-in TRAE Work CN app to TRAE; reads usage metadata only. TokenTracker never persists or logs the auth token or prompt/response content. | Off unless you set TOKENTRACKER_TRAE_CN_USAGE=1; then during eligible non-background sync when local TRAE Work CN auth exists |
| GitHub star count | api.github.com |
Nothing but the request itself (public repo metadata) | On dashboard load |
| Update check | api.github.com |
Nothing but the request itself | Windows: once at launch. macOS: only when you click "Check for Updates" |
| Pricing data refresh | raw.githubusercontent.com |
Nothing but the request itself (public model pricing JSON from BerriAI/litellm) | At most once every 24 hours when the local pricing cache is missing or stale |
Both telemetry items are disabled together by a single switch:
export TOKENTRACKER_NO_TELEMETRY=1 # or DO_NOT_TRACK=1
You can also set "telemetry": false in ~/.tokentracker/tracker/config.json. On localhost and inside the desktop apps, the dashboard asks the local server for this preference before initialising analytics — and if the answer cannot be confirmed, analytics stays off (fail-closed).
Audit: src/lib/telemetry.js, dashboard/src/lib/analytics.js, src/lib/pricing/litellm-fetcher.js.
3.2 Only after you opt in or click something
| Request | Destination | What is sent | Trigger |
|---|---|---|---|
| Devin quota read | server.codeium.com (Devin's official GetPlanStatus RPC) |
An empty JSON body, authenticated with the Devin CLI session token already stored on your machine. The token is never persisted or logged by TokenTracker. | Off by default — only while the Devin provider switch in Settings → Usage & Limits → Providers is on, and only on a locally authenticated request |
| Cloud sync / leaderboard | srctyff5.us-east.insforge.app |
Hourly buckets only — see §4 | Signing in to a TokenTracker account |
| Exchange rates | open.er-api.com |
Nothing but the request itself | Selecting a non-USD display currency |
| Desktop pet download | codex-pets.net |
The pet id you chose | Importing a pet from a link |
| IP check page | ip.net.coffee, claude.ai, 1.1.1.1 |
Your IP address is, by design, what these endpoints observe — that page exists to tell you how providers see your network | Opening the IP Check page |
| Service status page | Provider status pages (status.claude.com, status.openai.com, status.cursor.com, …) |
Nothing but the request itself | Opening the Service Status page |
| Share card fonts | fonts.googleapis.com |
Standard web-font request; Google can see your IP address | Generating a share image |
3.3 Never
- No request contains prompt text, responses, file contents, paths, or project names.
- We operate no ad network, no data broker integration, and no cross-site tracking.
- We do not sell or rent your data. Service providers listed in this policy process data only for the purposes described here.
4. Cloud account and leaderboard
Signing in is entirely optional. TokenTracker is fully functional without an account; the leaderboard, cross-device aggregation, badges and public profiles are the only features that require one.
Sent when signed in:
- Hourly usage buckets, each containing exactly:
hour_start,source,model,input_tokens,output_tokens,cached_input_tokens,cache_creation_input_tokens,reasoning_output_tokens,total_tokens,conversation_count - A machine id at device-registration time, so usage from several computers can be merged into one account without double-counting
- The email address and display name from your OAuth provider (GitHub or Google)
Not sent, ever:
- Prompts, responses, file contents, project or repository names, file paths
- Local session records —
session.queue.jsonlstays on your machine - Per-project breakdowns —
project.queue.jsonlis never uploaded - Any provider credential
Public visibility: your profile appears on the public leaderboard only while Settings → Account → Public profile is on. Turning it off removes you from the leaderboard and turns badges into a "private" placeholder.
Deleting cloud data: contact us privately at rynnsun0509@gmail.com and we will remove the account and its rows. Deleting ~/.tokentracker/ removes the local copy immediately.
5. Third parties
| Service | Role | Their policy |
|---|---|---|
| InsForge | Backend for accounts, cloud sync, leaderboard, heartbeat | github.com/InsForge |
| PostHog | Anonymous product analytics | posthog.com/privacy |
| Vercel | Hosting for www.tokentracker.cc | vercel.com/legal/privacy-policy |
| GitHub | Source hosting, releases, OAuth, star counts, upstream pricing data (raw.githubusercontent.com) |
GitHub Privacy Statement |
| OAuth sign-in, fonts on share cards | policies.google.com/privacy |
AI providers whose quota endpoints TokenTracker reads (Anthropic, OpenAI, Cursor, GitHub Copilot, Google, Moonshot, Z.ai, Qoder, Devin, …) are governed by their own policies. TokenTracker acts on your behalf with credentials already on your machine; it does not create any new relationship with them.
6. Turning things off
| Variable | Effect |
|---|---|
TOKENTRACKER_NO_TELEMETRY=1 |
Disables the daily heartbeat and dashboard analytics |
DO_NOT_TRACK=1 |
Same as above (respects the standard) |
TOKENTRACKER_DISABLE_GIT_ATTRIBUTION=1 |
Stops TokenTracker running git log inside your project directories |
Signing out removes cloud sync. Not signing in means it never starts.
7. Children
TokenTracker is a developer tool and is not directed at children under 13. We do not knowingly collect personal information from children.
8. Changes
Material changes to this policy will be noted in the release notes and in the Last updated date above. The full history is in this file's Git log.
9. Contact
Questions, corrections, or deletion requests: rynnsun0509@gmail.com. Do not publish private account or payment information in GitHub issues.
Planned Cloud billing
Paid Cloud has not launched. For the planned billing service, Waffo Pancake will operate hosted checkout and handle payment details under its own terms and privacy policy. TokenTracker will receive the order/payment reference, billing email, purchased plan, amount/currency, payment status, subscription term and refund status necessary to deliver access and handle billing. Full payment card numbers and security codes are not stored by TokenTracker. Only the usage metrics described above will be synchronized.
The planned membership provides access to 90 days of hourly details and 24 months of daily summaries. After membership expires, personal history has a 30-day read/export window. These are access windows, not a promise to delete all stored usage on the expiry date. Aggregated community statistics and compressed usage metrics may be retained to preserve and correct lifetime statistics. Necessary billing records may be retained to meet legal/accounting obligations and resolve payment disputes. Contact the private support address for access, correction or deletion requests; legally required records may be retained. Local data is unaffected by Cloud expiry.
TokenTracker is operated by Sun Xiufeng, an individual developer in China. Account and usage storage uses the existing InsForge backend, including infrastructure in the United States; other providers can process data in their operating regions. Contact rynnsun0509@gmail.com for privacy and security requests. This billing supplement was added on 8 October 2026 and describes the planned billing service. Paid Cloud is not yet open.