Overview
WhatTheToken is developed by Siamplus Development Company Limited. The macOS app is the primary source of usage information. The iPhone app is an optional companion that receives normalized usage snapshots.
We design the app to avoid collecting provider credentials on company-operated servers.
Data the app handles
Depending on the providers and features you enable, WhatTheToken may process:
- Provider usage percentages, limit windows, reset times, plan labels, and refresh state.
- A local installation identifier, a Mac display label, app version, sync schema version, and snapshot timestamps.
- A random pairing identifier, a device label such as “iPhone,” connection status, and timestamps needed to share usage with an iPhone.
- Provider authentication material already present on the Mac, or a GLM API key you add to the app.
WhatTheToken does not need the content of your prompts, source code, conversations, or generated responses to display usage limits.
Provider credentials
Claude and GPT Codex access uses their existing local app or CLI sessions. A GLM API key is stored in the macOS Keychain. WhatTheToken uses these credentials from the Mac to request usage information from the provider.
Provider credentials are never included in iPhone snapshots, sent to WTT Sync, or copied to the iPhone.
Encrypted WTT Sync
Pairing is optional and does not require an Apple Account, a cable, or the same Wi-Fi network. The Mac creates a one-time QR that expires after five minutes. The QR contains a random invitation token and an encryption key.
The encryption key is placed after the # fragment in the QR URL, so browsers and the WTT Sync server do not receive it. The Mac encrypts each normalized usage snapshot with AES-GCM before upload. The iPhone decrypts it locally after pairing.
WTT Sync is operated by Siamplus Development Company Limited on Cloudflare infrastructure. It stores hashed random access tokens, pairing status, a generic device label, timestamps, schema information, and the encrypted snapshot. It does not receive provider credentials, prompt content, source code, Apple Account contact information, or the snapshot encryption key.
You can revoke a paired iPhone from the Mac. Revocation deletes its server-side pairing record and prevents the iPhone from fetching future snapshots. Expired, unclaimed pairing records are automatically removed after a short cleanup period.
Website data
This website does not use advertising trackers or analytics cookies. It stores only your light or dark theme preference in browser local storage.
Infrastructure providers may process standard request information such as IP address, browser type, requested page, and security logs to deliver and protect the website.
Retention and security
Local app data remains on your devices until you remove it or uninstall the app. A claimed encrypted snapshot remains in WTT Sync until it is replaced or the pairing is revoked. Unclaimed invitations expire after five minutes and are removed automatically.
Revoking a pairing deletes its server-side record and stops future access. A previously received sanitized snapshot may remain in the iPhone's local cache until the app replaces or clears it, or the app is deleted.
No method of storage or transmission is completely secure. We limit the data shared between devices, encrypt snapshots end to end, hash server-side access tokens, and keep provider credentials in local platform-protected storage.
Your control
- Remove a GLM key from the Mac app.
- Sign out of a provider CLI or revoke its session through that provider.
- Revoke an iPhone pairing from the Mac to delete its WTT Sync record and stop future access.
- Delete the app and its locally stored data from a device.
- Contact us with a privacy question.
Changes to this policy
We may update this policy when the app, sync design, providers, or legal requirements change. The effective date at the top of this page identifies the current version.
Contact
For privacy questions, email apple-dev@siamplusdev.com.
Siamplus Development Company Limited, Thailand.