TokenTank
Deutsch

Privacy

TokenTank is a macOS app with no server, no account and no telemetry. This page says what the app reads, what it stores, and when it talks to the internet.

What the app reads

  • Claude Code session logs under ~/.claude/projects: numbers (tokens), model names, timestamps and the working directory only. Message contents are not read.
  • The Codex CLI's credentials (~/.codex/auth.json) when you adopt an account; from then on they live in the keychain.
  • Claude Code's login token from the keychain, to ask for the limits.
  • On request: the GitHub CLI's token (gh auth token), the Gemini CLI's file, a cookie from cursor.com. Only when you add that provider.
  • On request: debits from MoneyMoney or a CSV from your bank, to show actual subscription costs. Only totals per vendor are stored.

What the app stores

Everything lives under ~/Library/Application Support/dev.troisi.quota: configuration, utilisation history, sums per project and month, and state.json for extensions such as Raycast (without account identifiers). Credentials and the licence key live in the keychain.

When the app goes online

  • To the providers' usage endpoints, with your own login, about every five minutes.
  • To the update server (Sparkle), to ask for new versions, recipes and price tables. No system profile is sent.
  • To the licence server (Stripe): on activation and about every three days to confirm. Sent: the licence key and your Mac's name as the instance name.

Nothing else. No analytics, no crash reports, no advertising.

Your rights

Since TokenTank transmits no personal data to us, there is nothing to delete on our side. The purchase runs through the merchant of record, whose privacy policy covers the purchase. Questions: support@tokentank.app.

Controller: see the imprint. Last updated 2026-09-09.