Privacy
Privacy notice
Effective August 21, 2026 · Version 1.1
TokenSpend measures AI coding spend by reconciling Claude Code usage against your GitHub activity. We are built metadata-first: the capture hook parses usage metadata only, and none of your code or conversation content leaves your machine.
What we collect
- Usage metadata: model, token counts, and computed cost per session.
- Git metadata: repository name, branch, and commit SHA used to attribute spend to pull requests.
- Identity: your email and GitHub login, to associate usage with the right engineer and workspace.
- Router traffic: prompts and responses only when a workspace admin enables request logging.
What capture never collects
The fleet capture hook never sends your prompts, the model’s responses, your source code, or your diffs. It is metadata-only by design, and Claude Code content telemetry stays off.
Token Router request history
TokenSpend does not store Router prompts or responses by default. A workspace admin can enable request logging for 30-day encrypted history visible only to that workspace's admins. Turning logging off stops new content storage. Existing history keeps its original expiry unless you request earlier deletion.
How we use it
We use workspace data to operate and improve TokenSpend, meter Router requests, attribute spend to work, keep the service secure, and support customers. We do not sell personal data.
Downstream model providers
Router requests are sent to the selected model provider or a contracted inference processor. Request logging controls TokenSpend storage only. Downstream handling follows the applicable provider account, configuration, policy, and contract. The Trust center describes the boundary for BYOK and managed routes.
Retention and deletion
- Request and response bodies are stored only after logging opt-in and expire after 30 days.
- Turning logging off stops storage for new requests. It does not delete existing history.
- Metering receipts remain metadata-only so usage and cost stay auditable.
- Account, workspace, capture, and receipt metadata is kept while needed to operate the service, meet legal obligations, and resolve disputes.
Access and security
Stored Router bodies are encrypted at rest and visible through the product only to admins of the same workspace. TokenSpend does not provide a general admin browser across customer workspaces. Contact us to request access, correction, export, or deletion.
Changes
Version 1.1, August 21, 2026: made Router content logging opt-in and separated TokenSpend storage from downstream retention. Current and archived versions are listed in the legal version history.
Privacy, deletion, DPA, and processor-list requests: privacy@tokenspend.dev.
