How data is handled
TokenTracker reads AI CLI log folders that you explicitly authorize and builds usage, cost and quota summaries in a local database on your Mac. The ledger stores usage, model/provider data and incremental-scan checkpoints; project names, path summaries and session IDs are optional. Data is retained for up to 365 days by default, and Clear Index removes events and checkpoints. Log and CLI credential files are read-only. The app does not upload prompts, responses, chat content or your local ledger, and contains no advertising, analytics SDK or cross-app tracking.
Quota refresh
When you explicitly refresh quota, the app sends only the necessary credential directly to the selected provider to obtain your own quota snapshot; TokenTracker servers are not involved. Grok uses cli-chat-proxy.grok.com and, when needed, auth.x.ai; Kimi uses api.kimi.com and, when needed, auth.kimi.com; OpenRouter uses openrouter.ai; and DeepSeek uses api.deepseek.com. Claude and Codex quota snapshots come from local logs or CLI caches. Refreshed tokens are used in memory and are not written back to source files. Raw logs and prompt content are not sent to those endpoints.
Exchange-rate refresh
When you explicitly refresh the USD/CNY exchange rate, the app requests the current rate from Frankfurter. The request contains no account credentials, logs, prompts, or local ledger data.
Direct-edition activation
When the direct edition is activated or reverified, the licensing service receives the product identifier, license key, device-fingerprint digest, device name, app version and channel. The request IP is used temporarily for rate limiting. This data is used only to issue licenses, enforce the three-device limit and support device unbinding.
Mac App Store edition
The Mac App Store edition is unlocked after paid download and never connects to the TokenTracker licensing service. It does not use license keys. Apple handles purchase and download data under its own privacy policy.
Local permissions
The sandboxed edition can access only folders selected through the system picker and restores that access with security-scoped bookmarks. You can revoke folder access in the app settings. Log and credential files are not modified; CSV files are written only to a location you choose through the save panel. Login-item settings are managed by macOS.
Contact
For privacy questions, contact yoqulin@qq.com.