Privacy Policy

Your credentials stay on your Mac.

This policy explains how WhatTheToken handles provider usage, credentials, CloudKit sharing, and website data.

Effective August 9, 2026

Overview

WhatTheToken is developed by Siamplus Development Company Limited. The macOS app is the primary source of usage information. The iPhone app is an optional companion that receives normalized usage snapshots.

We design the app to avoid collecting provider credentials on company-operated servers.

Data the app handles

Depending on the providers and features you enable, WhatTheToken may process:

  • Provider usage percentages, limit windows, reset times, plan labels, and refresh state.
  • A local installation identifier, a Mac display label, app version, sync schema version, and snapshot timestamps.
  • Pairing records and connection status needed to share usage with an iPhone.
  • Provider authentication material already present on the Mac, or a GLM API key you add to the app.

WhatTheToken does not need the content of your prompts, source code, conversations, or generated responses to display usage limits.

Provider credentials

Claude and GPT Codex access uses their existing local app or CLI sessions. A GLM API key is stored in the macOS Keychain. WhatTheToken uses these credentials from the Mac to request usage information from the provider.

Provider credentials are not included in iPhone snapshots and are not copied to the iPhone through CloudKit.

CloudKit pairing and sync

If you pair an iPhone, the Mac publishes normalized usage snapshots using Apple CloudKit. A pairing invitation grants the connected iPhone read-only access to its shared records.

CloudKit data may include provider names, usage windows, percentages, reset dates, freshness state, the selected Mac label, installation identifier, and technical schema information. Apple processes this data under its own privacy terms.

Pairing is optional. You can revoke a paired device from the Mac, which removes its sharing relationship and associated CloudKit zone as supported by the app.

Website data

This website does not use advertising trackers or analytics cookies. It stores only your light or dark theme preference in browser local storage.

Infrastructure providers may process standard request information such as IP address, browser type, requested page, and security logs to deliver and protect the website.

Retention and security

Local app data remains on your devices until you remove it or uninstall the app. Shared CloudKit data remains until the pairing is revoked, its records are deleted, or Apple removes it according to its service rules.

No method of storage or transmission is completely secure. We limit the data shared between devices and use platform security features such as Keychain and CloudKit access controls.

Your control

  • Remove a GLM key from the Mac app.
  • Sign out of a provider CLI or revoke its session through that provider.
  • Revoke an iPhone pairing from the Mac.
  • Delete the app and its locally stored data from a device.
  • Contact us with a privacy question.

Changes to this policy

We may update this policy when the app, sync design, providers, or legal requirements change. The effective date at the top of this page identifies the current version.

Contact

For privacy questions, email apple-dev@siamplusdev.com.

Siamplus Development Company Limited, Thailand.