隐私政策
Privacy Policy
2026-08-27
以下保留原有政策正文及更新日期。当前下载与开发构建的区别请参阅版本信息更新日志;政策中的渠道与价格描述不作为当前商店在售或价格的确认。
我们如何处理数据
纸账在你的 Mac 本地读取你主动授权的 AI CLI 日志目录,并在本地数据库中生成用量、费用和额度统计。账本会保存用量、模型/平台和增量扫描检查点;你可以选择是否保存项目名、路径摘要和会话 ID。默认最多保留 365 天,清空索引会删除事件与检查点。日志与 CLI 凭证只读,不上传聊天正文、提示词、输出内容或本地账本,也不使用广告、分析 SDK 或跨应用追踪。
额度刷新
当你主动刷新额度时,应用只把必要凭证直接发送给对应平台,用于获取你自己的额度快照,不经过纸账服务器。Grok 使用 cli-chat-proxy.grok.com 和必要时的 auth.x.ai;Kimi 使用 api.kimi.com 和必要时的 auth.kimi.com;OpenRouter 使用 openrouter.ai;DeepSeek 使用 api.deepseek.com。Claude 与 Codex 的额度快照来自本地日志或 CLI 缓存。刷新后的 token 只在内存中使用,不回写源文件;原始日志和提示词内容不会发送给这些接口。
汇率刷新
当你主动刷新 USD/CNY 汇率时,应用会向 Frankfurter 请求当前汇率;请求不包含账号凭证、日志、提示词或本地账本数据。
官网直售版激活
当你激活或复验官网版时,授权服务会接收产品标识、激活码、设备指纹摘要、设备名称、应用版本和渠道。服务还会短期使用请求 IP 进行防撞库限流。上述数据仅用于发放许可证、限制三台设备及售后解绑。
Mac App Store 版
App Store 版付费下载后直接解锁,不连接纸账授权服务,也不使用激活码。Apple 会依照其隐私政策处理购买和下载数据。
本地权限
沙盒版仅能访问你通过系统文件选择器授权的目录,并用安全书签恢复授权。你可以在应用设置中撤销目录授权;日志目录与凭证文件不会被修改;CSV 只会写入你通过系统保存面板选择的位置。登录启动设置由 macOS 管理。
联系我们
隐私问题请联系 yoqulin@qq.com。
English policy / 英文正文
How data is handled
TokenTracker reads AI CLI log folders that you explicitly authorize and builds usage, cost and quota summaries in a local database on your Mac. The ledger stores usage, model/provider data and incremental-scan checkpoints; project names, path summaries and session IDs are optional. Data is retained for up to 365 days by default, and Clear Index removes events and checkpoints. Log and CLI credential files are read-only. The app does not upload prompts, responses, chat content or your local ledger, and contains no advertising, analytics SDK or cross-app tracking.
Quota refresh
When you explicitly refresh quota, the app sends only the necessary credential directly to the selected provider to obtain your own quota snapshot; TokenTracker servers are not involved. Grok uses cli-chat-proxy.grok.com and, when needed, auth.x.ai; Kimi uses api.kimi.com and, when needed, auth.kimi.com; OpenRouter uses openrouter.ai; and DeepSeek uses api.deepseek.com. Claude and Codex quota snapshots come from local logs or CLI caches. Refreshed tokens are used in memory and are not written back to source files. Raw logs and prompt content are not sent to those endpoints.
Exchange-rate refresh
When you explicitly refresh the USD/CNY exchange rate, the app requests the current rate from Frankfurter. The request contains no account credentials, logs, prompts, or local ledger data.
Direct-edition activation
When the direct edition is activated or reverified, the licensing service receives the product identifier, license key, device-fingerprint digest, device name, app version and channel. The request IP is used temporarily for rate limiting. This data is used only to issue licenses, enforce the three-device limit and support device unbinding.
Mac App Store edition
The Mac App Store edition is unlocked after paid download and never connects to the TokenTracker licensing service. It does not use license keys. Apple handles purchase and download data under its own privacy policy.
Local permissions
The sandboxed edition can access only folders selected through the system picker and restores that access with security-scoped bookmarks. You can revoke folder access in the app settings. Log and credential files are not modified; CSV files are written only to a location you choose through the save panel. Login-item settings are managed by macOS.
Contact
For privacy questions, contact yoqulin@qq.com.