TokenMeter

Privacy Policy

Version 2026-09-25-en · effective 2026-09-25

What we process

TokenMeter processes usage metadata: the account, device, team, tool and model behind a request, the token counts, the timestamps, the cost, and the verification status. With a consent you give separately, it also processes counts that describe how the projects on your own device are organized — counts only, described under "Devices" below. Separately from all of that, it records the fact of signing in, keeps a record of each session you have open, and keeps what you write to us when you ask for help — each described under "Retention" below. It never processes the content of prompts or responses. That is an architectural constraint of the product, not a configuration option.

Signing in

When someone signs in, or tries to and fails, we record the time, the address that was entered, the internet address the request came from, and the description the browser gives of itself. The address that was entered is not stored in readable form: we can check an address against what we hold, and we cannot read an address back out of it. That makes the record harder to read, not anonymous — the internet address, the browser description and the time stand as recorded. We record this to investigate accounts that have been locked and attempts to break into the sign-in page, and for nothing else: not for analytics, not for marketing, and never added to anyone's account record. We record it whether or not the address belongs to an account here — an address somebody types by mistake is recorded the same way as one that works.

While you are signed in, each session also carries the internet address and browser description it was opened from, so that you can recognize your own sessions and end the ones you do not. You see them under Settings › Me › Sessions.

Whose data it is

The workspace is the controller of its members' usage data; we process it on the workspace's instructions. A workspace records the legal ground on which it processes its own people's data — we do not choose that ground for it.

Sign-in records are different. We hold them for ourselves, not for any workspace, and we are the controller of them — including for an address that belongs to no account here and to someone who has never had one. Our ground is our own legitimate interest in keeping the sign-in page safe (GDPR Article 6(1)(f)); we weighed that interest against the people recorded, and we will show you that reasoning if you ask. That is the one category in this product where the choice is ours rather than a workspace's, and it is why the rest of this notice's routes through a workspace administrator do not apply to it.

Where it lives

The hosted service runs on infrastructure we operate in Seoul (ap-northeast-2). Each workspace's rows are isolated from every other workspace at the database level, enforced by the database rather than by application code. Sign-in records and what you write to us are outside that isolation because they are ours rather than a workspace's; a workspace's administrators do not see them. Optional on-device analysis runs on the device itself.

Devices

Collection from a person's device begins only after that device is enrolled and consent is recorded, and stops when consent is withdrawn. Consent is given per kind of data, by the person whose device it is; an administrator cannot give it for anyone else. Each kind is listed below with what is read on the device and what is sent to us. You can turn any of them off at any time in the console under Settings › Me › My consent. Turning one off takes effect from the device's next collection cycle, and from then on the device does not read that kind of data.

Device · metadata

What is read on the device: the session records your AI tools already write for themselves — when a session ran, which tool and model it used, and the token counts. What is sent: those token counts by day, tool and model, with their timestamps, and two further figures per day added in this version — how many sessions ran, and how many of the tokens the model read went to subagents, the helper agents a tool starts to work on part of a task, so that the console can show that share. Both are counts. The content of a conversation is never read.

How your own projects are set up

Off by default: nothing described here is read until you turn it on. When it is on, the device looks at how the project folders your sessions ran in are organized — and only at two fixed places inside each: the documents folder (docs) and the skills folder (.claude/skills). It looks at structure only: whether a folder or file is there, how many files there are, whether a document opens with a metadata block that names its type, and whether the first 4 KiB of a skill's entry file (SKILL.md) holds a line that starts with verdict: or triage: — the rest of that line, and the rest of the file, are never read. It does not read what any document says, and it does not read the value of any metadata field. Of the projects it looked at, it reports on one — the one you worked in most recently that had something to count.

What is sent, for each check: the check's name and revision; a verdict — applied, partly applied, not applied, or could not be judged; the number of items that passed and the number examined; how many projects had something to count; how many files were left out because they could not be read within the limits below; the reason, when no verdict could be reached; and the date from which the result has been observed. Every one of these is a word from a fixed list or a number. No path, no folder or file name, no file content and no error message leaves the device.

The look is bounded, and hitting a bound gives "could not be judged", never a partial figure: at most 256 project folders per pass, most recent first; no deeper than sixty-four levels below the two places above; at most 2,000 entries per project; at most 4 KiB read from any one file; and at most ten seconds for the whole pass, checked at every step.

Who sees device results

You see the results for your own devices under Optimization › My devices in the console. Your workspace's administrators, and group leads for the people in their groups, see the same results per device under Optimization › Organization — not a ranking and not a score. Nobody can turn a consent on for you.

When you write to us

If you send us a question or a report from the console, we keep what you wrote along with your address and the name on your account, and our staff read it to answer you. Write only what you want us to have: the box is free text and we do not inspect what goes in it.

Your rights

You can ask for access, erasure, portability or correction of your personal data, and the product implements all four. Erasure removes or pseudonymizes the data that identifies you while keeping the financial record the workspace needs — your identity is severed from it, and figures that would otherwise misstate what an organization spent are preserved. Erasure also deletes the per-day device figures and the check results described above for every device that was yours. Ask your workspace administrator to raise the request.

If you have no workspace here — because an address of yours appears only in a sign-in attempt — there is no administrator to ask, so write to us at info@token-monitor.com. Tell us the address that was entered; that is what we search on, and we will tell you what is held against it or that nothing is, and delete it if that is what you ask. Because we record attempts on addresses that have no account here as readily as on ones that do, an answer about an address tells you nothing about whether an account exists under it. We answer these by hand rather than through the console, because the console's request screen belongs to a workspace and you are not in one.

Retention

Usage data lives as long as the workspace does. Closing a workspace ends access to it and stops collection. When you close one you choose what happens to the usage already collected: erase it as part of closing, or keep it — and if you keep it, those records stay until we erase them. The account records themselves are retained until erasure.

Sign-in records are deleted on a schedule and are not kept beyond ninety days. That period does not change when a workspace closes, because these records are not the workspace's to close. The session records described above last as long as the account does, and you can end a session yourself at any time. What you write to us is kept for a hundred and eighty days.

Contact

Write to us at info@token-monitor.com, or ask your workspace administrator, who can reach us on your behalf. If you have no workspace here, that address is the only route and it is enough.