TokenMeter

Privacy Policy

Version 2026-09-07-en · effective 2026-09-07

What we process

TokenMeter processes usage metadata: the account, device, team, tool and model behind a request, the token counts, the timestamps, the cost, and the verification status. With a consent you give separately, it also processes counts that describe how the projects on your own device are organized — counts only, described under "Devices" below. It never processes the content of prompts or responses. That is an architectural constraint of the product, not a configuration option.

Whose data it is

The workspace is the controller of its members' usage data; we process it on the workspace's instructions. A workspace records the legal ground on which it processes its own people's data — we do not choose that ground for it.

Where it lives

The hosted service runs on infrastructure we operate in Seoul (ap-northeast-2). Each workspace's rows are isolated from every other workspace at the database level, enforced by the database rather than by application code. Optional on-device analysis runs on the device itself.

Devices

Collection from a person's device begins only after that device is enrolled and consent is recorded, and stops when consent is withdrawn. Consent is given per kind of data, by the person whose device it is; an administrator cannot give it for anyone else. Each kind is listed below with what is read on the device and what is sent to us. You can turn any of them off at any time in the console under Settings › Me › My consent. Turning one off takes effect from the device's next collection cycle, and from then on the device does not read that kind of data.

Device · metadata

What is read on the device: the session records your AI tools already write for themselves — when a session ran, which tool and model it used, and the token counts. What is sent: those token counts by day, tool and model, with their timestamps, and two further figures per day added in this version — how many sessions ran, and how many of the tokens the model read went to subagents, the helper agents a tool starts to work on part of a task, so that the console can show that share. Both are counts. The content of a conversation is never read.

How your own projects are set up

Off by default: nothing described here is read until you turn it on. When it is on, the device looks at how the project folders your sessions ran in are organized — and only at two fixed places inside each: the documents folder (docs) and the skills folder (.claude/skills). It looks at structure only: whether a folder or file is there, how many files there are, and whether a document opens with a metadata block that names its type. It does not read what any document says, and it does not read the value of any metadata field. Of the projects it looked at, it reports on one — the one you worked in most recently that had something to count.

What is sent, for each check: the check's name and revision; a verdict — applied, partly applied, not applied, or could not be judged; the number of items that passed and the number examined; how many projects had something to count; how many files were left out because they could not be read within the limits below; the reason, when no verdict could be reached; and the date from which the result has been observed. Every one of these is a word from a fixed list or a number. No path, no folder or file name, no file content and no error message leaves the device.

The look is bounded, and hitting a bound gives "could not be judged", never a partial figure: at most 256 project folders per pass, most recent first; no deeper than four levels below the two places above; at most 2,000 entries per project; at most 4 KiB read from any one file; and at most ten seconds for the whole pass, checked at every step.

Who sees device results

You see the results for your own devices under Optimization › My devices in the console. Your workspace's administrators, and group leads for the people in their groups, see the same results per device under Optimization › Organization — not a ranking and not a score. Nobody can turn a consent on for you.

Your rights

You can ask for access, erasure, portability or correction of your personal data, and the product implements all four. Erasure removes or pseudonymizes the data that identifies you while keeping the financial record the workspace needs — your identity is severed from it, and figures that would otherwise misstate what an organization spent are preserved. Erasure also deletes the per-day device figures and the check results described above for every device that was yours. Ask your workspace administrator to raise the request.

Retention

Usage data lives as long as the workspace does. Closing a workspace ends access to it and stops collection. When you close one you choose what happens to the usage already collected: erase it as part of closing, or keep it — and if you keep it, those records stay until we erase them. The account records themselves are retained until erasure.

Contact

Write to us at the address on our site, or ask your workspace administrator, who can reach us on your behalf.