TokenMeter privacy

TokenMeter measures AI coding agents on your machine. It sends usage to this server only after you turn sharing on (tokenmeter share on), and only hours from the hour you turn sharing on: hours recorded before that are not sent, and turning sharing off and on again starts over from then.

SettingWhat reaches the server
Sharing offNothing.
Sharing onA random device token, platform and version, and per local hour: tool, route label, plan, model family, token counts, request count, estimated cost and timing sums.
Token League login (tokenmeter league login)Your GitHub id and login, the rooms you join, and your devices' iroh endpoint ids. With sharing off, one total cell per hour instead of the per-tool cells. The GitHub token is checked once and revoked; it is never stored.
Never sentPrompts, code, file paths, project names, session ids, private endpoint hostnames, custom service or model names.

IP addresses are used only in memory for rate limits and are not stored. We publish only aggregates. tokenmeter share preview shows the next upload; tokenmeter account delete deletes this device's data here (it leaves our backups within 14 days).

Room members see your GitHub login and live output rate. When the host starts a match, every member plays, and members see how many output tokens or how much estimated cost (USD) you added during it. While your meter is in a room, anyone who knows your device's endpoint id (current or past members of your rooms) gets your public IP address and local addresses when they connect, whether or not a direct connection opens; leaving a room or logging out changes the key. Live rates travel directly between members when the network allows it and otherwise pass through our relay, which does not keep them. tokenmeter league logout unlinks this device; if you logged in, tokenmeter account delete deletes your account, every linked device's data and your room memberships.

Contract and source of the client: docs/protocol. Contact: GitHub issues.