Privacy Policy

Effective 16 July 2026

DRAFT — pending legal review. This document is written in plain language and is accurate to our engineering, but has not yet been cleared by a lawyer. Nothing here is legal advice.

The whole thing, in plain English

  • • Your usage data lives in your browser, on your device. We don’t have it.
  • • We never see prompts, AI outputs or files — only the token counts you choose to analyse, and only on your device.
  • • Pasted reporting keys are used once, in memory, never stored or logged.
  • • Analytics runs only if you say yes. We honour Global Privacy Control automatically.
  • • Delete everything yourself, instantly: Track page → Clear data.

1. Our design: privacy by not having your data

Tokenokio is local-first. Machine scans parse entirely in your browser; synced provider usage is returned straight to your browser; everything is stored in your browser’s local storage. Our servers act as a momentary pipe for syncs you initiate and keep nothing. The strongest privacy guarantee we can offer is the architecture itself: for your usage data, there is nothing on our side to breach, sell, or subpoena.

2. What we process, and why

  • Usage data you analyse (token counts, models, dates, project names, costs): processed on your device; transits our sync endpoint in memory only when you press Sync. Purpose: showing you your own spend. Legal basis: performing the service you asked for (GDPR Art. 6(1)(b)).
  • Reporting keys you paste: stored in your browser; sent over HTTPS for the single sync you request; used in memory; never stored or logged by us. Purpose: fetching your usage from your provider. Legal basis: your request (Art. 6(1)(b)).
  • Product analytics (pages, feature events — via PostHog): only after you consent through our banner, and never including your usage data, prompts or keys. Purpose: improving the product. Legal basis: consent (Art. 6(1)(a)); withdraw anytime by clearing the choice in your browser.
  • Support email: what you send us, used to help you. Legal basis: legitimate interest in answering you (Art. 6(1)(f)).
  • Anonymised contribution (free tier, opt-in): category-level shapes (task type, model, token counts, outcome) with no prompts, no keys, no identifiers — powering the public capability index. It cannot be traced back to you.

We do not sell or share personal information for advertising. No exceptions.

2a. Exactly what the scan and the shim read — and what stays local

Tokenokio has two ways of seeing your usage. Here is precisely what each one touches:

  • The local scan reads your AI tools’ own log files on your device (for example Claude Code and Codex session logs). It parses only the accounting fields — timestamps, model names, token counts, request counts and, where present, the cost the tool recorded. It skips the message bodies: your prompts, the model’s replies, file contents and tool output are not read into Tokenokio. Parsing happens in your browser; the results are written to your browser’s local storage. None of it is sent to us.
  • The optional local proxy (“the shim”) runs on your own machine, on localhost, only if you start it. It sits between your AI tool and your provider so it can meter spend live, catch runaway agents, and (if you turn those on) reroute or compress. It sees request metadata — model, token counts, timing, and the per-agent/project tags you choose to send — and it forwards your request to your provider over your own connection. The shim does not send your requests, prompts, responses or usage to Tokenokio’s servers; its live numbers are exposed only to your own browser on localhost. Any provider API key the shim uses stays on your machine.
  • Provider sync (when you paste a read-only reporting key) fetches your usage summary from your provider’s billing API. The request passes through our endpoint as a momentary, in-memory pipe and the result is returned straight to your browser; we store neither the key nor the usage.

Stays local, never uploaded: your usage records, project and agent tags, provider/reporting keys, prompts, model outputs, files, and the shim’s live meter.
Leaves your device only when you act: a provider sync you trigger (in memory, not stored), support email you send us, and — only with your consent — anonymous product-analytics events (never usage data, prompts or keys).

3. Your AI content is out of scope — deliberately

Prompts, model outputs, code and files belong to you and your AI providers under your agreements with them. Tokenokio neither receives nor wants them: our scanners read the accounting lines (tokens, models, dates) and skip the content. For your providers’ handling of your content, see their privacy terms.

4. Where you live: your rights, ready to use

European Union & EEA (GDPR) — you have the rights of access, rectification, erasure, restriction, portability and objection, and to withdraw consent anytime. Because your data stays on your device, most of these you can exercise instantly yourself; for anything held in analytics or email, write to us and we’ll act within 30 days. You may also complain to your supervisory authority.

United Kingdom (UK GDPR) — identical rights apply, with complaints to the ICO.

United States — all states — residents of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and every state with a comprehensive privacy law have rights to know, access, correct, delete, and opt out of sale/sharing and targeted advertising. Our position is simple: we do not sell or share personal information, and we do not use it for targeted advertising — so you’re already opted out. We honour Global Privacy Control: if your browser sends it, analytics stays off without you clicking anything. California residents: we collect only the categories above, for the purposes above; “Limit the Use of My Sensitive Personal Information” doesn’t arise because we don’t collect sensitive categories.

Australia (Privacy Act & APPs) — the same access, correction and complaint rights apply; contact us first and we’ll resolve it fast, or you may contact the OAIC.

Everywhere else — same promises, same email, same speed.

5. International transfers, retention, security

Your usage data doesn’t transfer internationally because it doesn’t leave your device. Consented analytics is processed by PostHog (US region) under standard contractual protections. Sync requests pass through our hosting (Vercel) in memory. Retention: usage data — until you clear it; analytics — per your consent; support email — as long as useful for helping you. Security: HTTPS everywhere, no server-side secret storage, read-only keys by design, and honest engineering enforced by tests.

6. Children, changes, contact

Tokenokio is a business tool, not directed to children under 16. We’ll post any material changes here with a new effective date. Privacy questions and requests: privacy@tokenok.io — or start at the support page for instant answers.