Archived version. Read the current privacy notice.

Privacy

Privacy notice

Effective September 14, 2026 · Version 1.2

TokenSpend measures AI coding spend by reconciling Claude Code usage against your GitHub activity. We are built metadata-first: the capture hook parses usage metadata only, and none of your code or conversation content leaves your machine.

What we collect

What capture never collects

The fleet capture hook never sends your prompts, the model’s responses, your source code, or your diffs. It is metadata-only by design, and Claude Code content telemetry stays off.

Token Router request history

TokenSpend does not store Router prompts or responses by default. A workspace admin can enable request logging for 30-day encrypted history visible only to that workspace's admins. Turning logging off stops new content storage. Existing history keeps its original expiry unless you request earlier deletion.

How we use it

We use workspace data to operate and improve TokenSpend, meter Router requests, attribute spend to work, keep the service secure, and support customers. We do not sell personal data.

Downstream model providers

Router requests are sent to the selected model provider or a contracted inference processor. Request logging controls TokenSpend storage only. Downstream handling follows the applicable provider account, configuration, policy, and contract. The Trust center describes the boundary for BYOK and managed routes.

Admins may separately require no downstream content retention in Router Policy. This optional routing control uses current evidence for the actual route, account, model, and request features. Unsatisfied requirements block forwarding, including on retries and fallback. It does not itself create a contractual ZDR guarantee. Metadata records policy changes and each strict attempt's eligibility decision.

Retention and deletion

Access and security

Stored Router bodies are encrypted at rest and visible through the product only to admins of the same workspace. TokenSpend does not provide a general admin browser across customer workspaces. Contact us to request access, correction, export, or deletion.

Changes

Version 1.2, September 14, 2026: documented the separate downstream routing requirement and policy audit metadata. Logging defaults and the 30-day window are unchanged. Current and archived versions are listed in the legal version history.

Privacy, deletion, DPA, and processor-list requests: privacy@tokenspend.dev.