Privacy
Privacy notice
Effective August 11, 2026 · Version 1.0
TokenSpend measures AI coding spend by reconciling Claude Code usage against your GitHub activity. We are built metadata-first: the capture hook parses usage metadata only, and none of your code or conversation content leaves your machine.
What we collect
- Usage metadata: model, token counts, and computed cost per session.
- Git metadata: repository name, branch, and commit SHA used to attribute spend to pull requests.
- Identity: your email and GitHub login, to associate usage with the right engineer and workspace.
- Router traffic: prompts and responses sent through the Token Router, unless workspace ZDR is on.
What capture never collects
The fleet capture hook never sends your prompts, the model’s responses, your source code, or your diffs. It is metadata-only by design, and Claude Code content telemetry stays off.
Token Router request history
Requests routed through the Token Router (prompts and responses) are stored encrypted for 30 days to power request history, visible only to your own workspace admins, then deleted. Zero data retention is a one-click workspace setting: nothing is stored from that moment and anything already stored is deleted immediately. Enterprise agreements guarantee zero data retention contractually.
How we use it
We use workspace data to operate and improve TokenSpend, meter Router requests, attribute spend to work, keep the service secure, and support customers. We do not sell personal data.
Downstream model providers
Router requests are sent to the selected model provider or a contracted inference processor. TokenSpend ZDR controls TokenSpend storage only. Downstream handling follows the applicable provider account, configuration, policy, and contract. The Trust center describes the boundary for BYOK and managed routes.
Retention and deletion
- Router request and response bodies expire after 30 days.
- ZDR stops new TokenSpend body storage immediately and deletes existing stored bodies.
- Metering receipts remain metadata-only and continue under ZDR so usage and cost stay auditable.
- Account, workspace, capture, and receipt metadata is kept while needed to operate the service, meet legal obligations, and resolve disputes.
Access and security
Stored Router bodies are encrypted at rest and visible through the product only to admins of the same workspace. TokenSpend does not provide a general admin browser across customer workspaces. Contact us to request access, correction, export, or deletion.
Changes
Version 1.0, August 11, 2026: published the first dated notice, including Router retention, ZDR scope, downstream boundaries, and request paths. Current and archived versions are listed in the legal version history.
Privacy, deletion, DPA, and processor-list requests: privacy@tokenspend.dev.