Privacy policy

EFFECTIVE AUGUST 24, 2026 · CLOUDY INDUSTRIES LLC

01Who we are

Cloudy Industries LLC ("Tokematic", "we", "us") operates the Tokematic app and the sync service at api.tokematic.app. We are based in Washington State, USA. We control the personal information described in this policy.

02What this policy covers

This policy covers the Tokematic desktop app (macOS and Windows), the iPhone app and the web dashboard. It explains what we collect, why, where it goes, how long we keep it, and the choices you have. Our Terms of service are a separate document.

03The credential collection, in plain terms

Tokematic's main job is to read your AI subscription status and usage so it can warn you as you approach your limits. To do that, the desktop app finds the credentials you already have on your computer:

  • Browser cookies for Chrome, Brave, Edge, Arc, Firefox and Safari. To read Safari cookies the app needs Full Disk Access, which you grant in macOS settings. The app reads Safari cookies, not your Safari saved passwords.
  • Sign-in files left by the Claude, Codex and Kimi command-line tools, and the Kimi desktop app.
  • Items in your macOS Keychain, including items belonging to those other apps.

The app uses those credentials to sign in to the provider as you and read your usage. Your credentials never leave your device. They are sent only to the provider's own service to authenticate you. We do not transmit them to our servers, to CloudKit, or anywhere else.

This is session replay with your own credentials. The app identifies itself to the provider with the same client identity the credential was issued to: a browser identity for browser cookies, the command-line tool's own identity for command-line tokens. It does not impersonate a different user.

One narrow exception. When Tokematic detects that your Claude account may be past due, it creates a throwaway conversation on your Claude account, sends a single one-token message, reads the resulting error, and deletes the conversation. This fires only on a billing cue and is cached for 30 minutes. It sends minimal content to Anthropic as the provider.

04What we collect, and why

CategoryWhat it isWhySource
Provider credentialsAPI keys, cookies and command-line tokensTo sign in to your providers and read your usageYour device only, never sent to us
Usage dataSubscription status, quota percent, reset times, spend, balance, window, fetched timeTo pace you and warn you of limitsYour providers, via your credentials
Account identifiersAccount ID, device ID, host name, last four characters of your key, account labelsTo group your accounts across devices and dedupe themDerived from your device and providers
Sync and historyUsage snapshots, which device holds which provider, pace history, exhaustion eventsTo sync across your devices and your teamYour devices
PreferencesDisplay choices, alerting, account order and enable flagsTo carry your settings across devicesYour settings
Network and opsIP address (kept about two hours for rate limiting), Cloudflare edge logsTo operate and secure the serviceThe network connection
Support contentAnything you send to supportTo answer your requestYou

We do not collect your prompts, your model inputs, or your model outputs. We do not collect your precise geolocation. We do not collect health information. We do not scan your files generally. Full Disk Access, if you grant it, is used only to read Safari cookie stores, with one exception for the Kimi desktop app's local storage described in section 10.

05Where your data lives, and who can see it

On your device. Your credentials and your account records. Credentials live in your Keychain or are read on demand from browser stores and sign-in files. Account records and labels live in your system preferences. Pace history on your device is a bounded window, roughly 90 days for a heavy user, with the oldest samples dropping off as new ones arrive.

In iCloud, if sync is on and you are not in a team. Your usage snapshots, sync records and preferences travel through your private iCloud database so your other Apple devices can set themselves up.

On our sync server, if sync is on and you are in a team. The same usage data travels to api.tokematic.app so your team can share it. The server is a dumb store. It validates the shape of records and serves them back. It does not parse or decrypt the sealed fields.

What we can and cannot see. Your account names and labels are end-to-end encrypted with a key that only you and your team members hold. We cannot read them. The manager of a team can read everything in the team because they hold the key.

Today, to operate the service and dedupe your accounts across devices, the server does hold some account identifiers in readable form: your account ID, device ID, host name, the last four characters of your key, and your device label. We are completing work to hash and seal these so the server will hold only an opaque token and the usage numbers, with no name, device or person attached. Account names and labels are already end-to-end encrypted and unreadable to us.

Your share code. Your share code (for example PE84-KF7XQ9M2PDRW) is created the first time any of your devices can reach our server. It has two halves: a short alias that identifies your group, and a secret body your devices use to derive both your access credential and your encryption key. The key half is never sent to our server: our server can verify a sign-in but cannot decrypt your names.

  • Every use of your code asks you first. Signing in on the web or adding a device shows an approval prompt, with a short confirmation code to compare, on a device you already have. There is no code-only path.
  • Anyone you give the full code to can read your account names and see your data in their dashboard. Share it like a password.
  • Entering someone else's code sends your data to their group too, and they can see your account names. You can leave a group at any time, which stops future sharing.
  • If you lose every device, your account names are unrecoverable. We hold no key and cannot help. Your usage history remains, but the names stay encrypted forever.

06Sharing, sale and advertising

We do not sell your personal information. We do not share it for cross-context behavioral advertising. We do not rent or trade it.

We share the minimum needed to run the service with these subprocessors:

  • Cloudflare, hosting and edge network, US region.
  • Apple iCloud and CloudKit, sync through your private iCloud.

When they ship, we will also use:

  • Stripe, for payments. Stripe handles card data; we do not.
  • A support-automation AI inference provider, to help answer support requests. Support transcripts stay in our database on the retention schedule in section 7.

We may disclose information to respond to a valid legal request, to protect our rights, or where required by law.

Support access is not end-to-end. If you grant Tokematic support access to debug a problem, that access is scoped, time-limited and revocable from the app. For the duration of that session our server holds the key in usable form, so this is not the end-to-end model that protects your labels. We close the access when the work is done.

07How long we keep your data

DataRetention
Your credentialsOn your device only, until you remove them or stop using the app
Your usage snapshots and historyThe active lifetime, shortening to a 90-day window once our schemas stabilize
Fine-grained reporting sourceThe active lifetime in these early years, to allow reprocessing, shortening to the 90-day window
Account identifiers and labelsThe active lifetime, deleted on request or closure
Aggregate trends (token-free, no names)3 to 5 years
Network and ops data (IPs, edge logs)Short and purpose-tied, swept regularly
Support transcriptsOn the retention schedule above, tied to the ticket

When you ask us to delete your account, we disable it immediately. We hold the data for a short internal window, up to 30 days, so a legitimate party can respond if an ex-employee or an attacker triggered the deletion, and we notify you. After that window we delete the live data. Backups expire on a 90-day cycle that we control, so a hacked account cannot destroy recoverable data. If you have an open support ticket, we hold deletion until the ticket resolves.

If you stop using Tokematic, we notify you at 21 months of inactivity and delete your data at 24 months unless you log in or ask us to keep it. Inactivity means no product use and no support tickets. Not paying a subscription is not a trigger; it feeds the inactivity clock.

These periods are maximums. We may delete earlier. We may keep data longer where required by law or to resolve an open issue or security investigation.

08Your choices

Turn off sync. Sync is on by default so your other devices set themselves up. You can turn it off in Settings, and the app stays fully local. Nothing leaves your device while sync is off.

Pace and subscriptions. The credential collection that powers pace and subscription alerts is part of the service. If you prefer not to use automatic discovery, you can enter API keys manually in Settings; manual keys give spend figures but not subscription quota.

Turn off support access. Revoke it from the app at any time.

Analytics. We do not yet run analytics on your data. When we do, you will be able to opt out from Settings, and your data will be excluded from the aggregate trends.

09Your rights, and how to exercise them

You have the right to:

  • Access the personal information we hold about you.
  • Delete it.
  • Correct it if it is wrong.
  • Export it in a structured, portable format.
  • Opt out of sync, and of analytics when it ships.

To exercise any of these, email [email protected]. We verify your identity before we act. We respond within 30 days. If we need longer, we tell you why and take up to a further 60 days. If we deny a request, we tell you why and how to appeal. You can also complain to your state Attorney General.

10The details we owe you

This section lists behaviors a careful reviewer would want to know. None of it is hidden; it is here so the policy matches the product.

  • To read cookies from Chrome, Brave, Edge and Arc, the app decrypts them in memory using each browser's own Safe Storage key.
  • To read the Kimi desktop app's sign-in token, the app byte-scans that app's local storage files.
  • When a command-line token refreshes, the app writes the new token back to the originating sign-in file in place.
  • To rotate the Claude command-line token, the app runs the Claude tool in a sandbox.
  • The app reads each browser profile separately, so multiple logins to one provider are discovered.
  • The tokematic-probe creates and deletes a conversation on your Claude account, described in section 3.
  • While the app runs, it polls our server for team-join approvals every 15 seconds.
  • Your team share code transits your iCloud so your own Apple devices can adopt it.
  • We keep raw IP addresses for about two hours for rate limiting, plus Cloudflare edge logs.
  • Sync is on by default.

11Children

Tokematic is not for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

12Security

All traffic to our servers uses TLS. We use end-to-end encryption for account names and labels, with keys held only by you and your team. Authentication tokens are stored as one-way hashes, and API tokens are shown exactly once. The sync server cannot decrypt the sealed fields. We hold account identifiers in readable form today for operation and dedupe, and we are sealing them (section 5). We do not store your provider credentials on our servers at all.

13Your California privacy rights

If you are a California resident, you have the rights above plus:

  • The right to know what we collect and why, given in this policy.
  • The right to limit the use of your sensitive personal information. We do not use sensitive personal information for secondary purposes.
  • The right to opt out of sale or share. We do not sell or share.
  • The right to non-discrimination for exercising your rights.

We do not sell or share personal information, so there is no "Do Not Sell or Share" link. We do not collect precise geolocation. We do not process sensitive personal information for secondary purposes.

14Changes to this policy

We update this policy when we change what we do. We post the new version and note the date. If a change is material, we notify you.

15Contact

Privacy questions and rights requests: [email protected].