Summary
The Mac app reads selected AI coding tools and provider services on the Mac. The iPhone app, widgets, Live Activity, and Apple Watch can display a privacy-filtered snapshot that the user chooses to sync. TokenRemain does not require a TokenRemain account, use advertising, or track users across apps or websites.
Data processed on the Mac
Depending on the providers enabled, TokenRemain may read local configuration files, local databases, command-line output, localhost services, or credentials already stored by those tools. It may send authenticated requests directly to a selected provider to retrieve quota or usage information.
Provider credentials—including access tokens, API keys, cookies, and account sessions—remain on the Mac. TokenRemain does not upload them to iCloud or a TokenRemain-operated server, refresh third-party OAuth tokens, or upload prompts, projects, conversations, account names, email addresses, or request-level history.
Settings, quota caches, aggregate history, and optional feed data are stored locally for dashboards, trends, alerts, and offline states.
Optional Apple-device sync
Sync uses the user's CloudKit Private Database. Before upload, the Mac reduces data to a strict allowlist and encrypts the snapshot with AES-256-GCM. The encryption key is stored in a dedicated synchronizable iCloud Keychain access group available only to the TokenRemain Mac and iPhone main apps.
The snapshot may contain
- Stable provider identifiers, quota-window percentages, reset dates, capture times, and availability states.
- Sanitized subscription-tier labels and source/version/sequence metadata used to reject stale, replayed, or wrong-source updates.
- If enabled, up to 30 days of aggregate Claude and Codex token and estimated-cost history.
- Up to three selected public feed posts with display text and public links.
The snapshot never contains
Provider credentials, API keys, cookies, account names, email addresses, prompts, project names or paths, conversations, or individual request records. CloudKit notification payloads only indicate that a record may have changed; they do not carry quota details.
The iPhone validates and decrypts a snapshot before writing a reduced display snapshot to the App Group used by widgets and Live Activity. Apple Watch data is delivered from the iPhone through WatchConnectivity. Extensions do not receive CloudKit or sync-key access.
Freshness diagnostics
The iPhone privately stores up to 240 timing observations to measure foreground sync freshness. Each contains a stable provider slug and the provider-capture, Mac-upload, phone-receipt, and phone-render timestamps. It contains no quota value, credential, account identifier, or content and is not uploaded to iCloud, an App Group, or a TokenRemain server.
Notifications
Sync does not require notification permission. Notification permission is requested only when the user enables an alerting feature. CloudKit silent notifications are system delivery hints and do not display provider data in a notification banner.
If the user enables the daily public AI feed notification, TokenRemain registers a random installation identifier, device-generated revocation key, APNs device token, platform, locale, time zone, and notification preference with the TokenRemain broadcast service. It receives no Provider credential or TokenRemain account identity and uses these fields only to deliver or revoke the requested notification.
Purchases and Apple services
No public iPhone App Store product is available yet. If a future iPhone app is distributed through the App Store, TokenRemain will not receive payment-card details; purchase and re-download records will be handled by Apple. The planned app contains no subscription, advertising SDK, or in-app purchase product.
Apple may process CloudKit, iCloud Keychain, App Store, crash, and opt-in diagnostic data under Apple's terms and privacy policies.
Analytics, tracking, and provider services
TokenRemain includes no developer-operated advertising or analytics SDK, does not sell user data, and does not combine TokenRemain data with other companies' data for advertising.
The website download endpoint keeps only one aggregate Mac download count and its last-update time. It does not store an IP address, device identifier, user agent, cookie, or per-download event. GitHub and Cloudflare may process ordinary delivery logs under their own terms.
Provider requests are governed by the selected provider's privacy policy. The Mac sends only what is required to authenticate and retrieve the provider's quota response.
Retention and deletion
Local caches and settings remain until the user removes them or the operating system clears eligible cache data. Cloud sync keeps the current encrypted snapshot and limited operational metadata in TokenRemain's private CloudKit zone.
An active public-feed notification registration remains until the user disables notifications or the service invalidates the APNs token. Disabling the feature sends the locally held revocation key to deactivate that installation.
Users can disconnect sync and remove TokenRemain's private CloudKit data and dedicated sync key without deleting provider credentials or Mac-local quota history. If iCloud Keychain encrypted data is reset, prior synchronized records may no longer be decryptable.
Security
TokenRemain uses platform code signing, Keychain storage, CloudKit Private Database controls, application-layer authenticated encryption, schema and range validation, expiry checks, and source/sequence replay protection. No system can eliminate every risk, particularly on an unlocked or compromised device.
Children, international use, and changes
TokenRemain is not directed to children and does not knowingly request contact, location, health, or advertising-identifier data. Users are responsible for complying with provider terms and applicable laws in their region.
Material changes will be reflected here with a revised effective date.
Contact
For privacy questions or deletion assistance, contact Dongheng Li.
[email protected]