Privacy
Your usage data, explained.
TokenMaxing can work as a local macOS app or sync normalized usage metadata to provide history, sharing, and team features. This page explains that difference and the choices available to you.
Last updated:
Local-only mode
The collector reads usage-bearing records from Claude Code session files
under ~/.claude/projects and
Codex session files under ~/.codex/sessions. Custom source
directories can be configured for additional accounts.
In local-only mode, this processing stays on your device. Cloud sync is optional and requires a configured source key. You can also use a dry run to parse and inspect local totals without sending them.
What cloud sync sends
When you enable sync, TokenMaxing sends normalized usage metadata: the tool and model; input, output, cache-read, cache-write, and cache-creation token counts; estimated cost; duration when available; timestamp; request identifier; and the source/key identity used to place the record in the correct account or organization.
Repository attribution can include a sanitized repository host, name, remote, and subpath. Limited provider context used for attribution and deduplication can include a session identifier, model provider, service tier, and Git branch.
TokenMaxing does not upload your prompts, transcripts, source code, or original local session files through the default collector path.
Accounts and organizations
Clerk provides authentication. When you sign in, TokenMaxing may receive and store profile details such as your email address, name, profile image, Clerk identifier, and connected GitHub identifier and username.
Organization names, slugs, images, memberships, and roles are used to control access to team views. GitHub repository ownership and visibility information is used to decide who can manage a repository and how public or private information is presented.
Service providers
TokenMaxing uses Clerk for authentication, Convex for application data, and Cloudflare Workers, Queues, and R2 for the website and ingestion pipeline. modelpricing.ai is used to estimate token costs from normalized model and usage fields. Ahrefs web analytics measures visits to the public website. These providers process information as needed to perform those functions.
Public and private sharing
Repository cards are private unless an authorized owner opts them into public sharing. Contributor handles and model details have additional opt-in controls. Team views are private and membership-gated. Public surfaces show selected usage summaries rather than account email addresses, real names, prompts, transcripts, or source code.
Retention
Application usage history is retained to provide historical views. Intermediate pipeline objects are intended to support limited replay and operations. We do not state a fixed retention period here because a complete, enforced retention schedule is not verified in the source-controlled infrastructure.
Access, correction, and deletion
TokenMaxing does not yet provide a self-service account deletion control. To request access to, correction of, or deletion of your account information and synced usage data, follow the instructions on the support page. Requests are reviewed and handled manually; we do not promise immediate or fully automated erasure.
Security and changes
We use reasonable technical and organizational safeguards appropriate to the service. No method of storage or transmission is completely secure, and this statement does not claim a security certification.
This notice is effective August 20, 2026. We may update it as TokenMaxing, its data practices, or its service providers change. A revised page will show a new last-updated date, and material changes will be communicated through an appropriate product or website notice.