Privacy Policy
OhMyToken 隐私政策
生效及最后更新日期:2026 年 9 月 25 日
OhMyToken 不运营开发者服务器,不接入广告、分析或跨 App 跟踪 SDK。账号凭据、额度快照与趋势记录不会上传给 OhMyToken 开发者。
1. 适用范围
本政策适用于 iOS 与 macOS 应用 OhMyToken。OhMyToken 是一款 AI Agent 额度与 Token 用量看板,用于展示用户主动连接的第三方服务账号额度、重置时间、使用节奏,以及在 macOS 上汇总经用户授权访问的本机会话记录。
2. OhMyToken 处理的数据
账号凭据与登录状态
当你主动连接服务时,OhMyToken 可能处理访问令牌、刷新令牌、Cookie、账号标识或 OAuth 客户端信息,以检查登录状态、查询额度或刷新已过期的访问令牌。手动保存的凭据存储在 Apple 系统钥匙串中;从本机 Agent 客户端读取的凭据不会被写回或修改。
额度、计划与账号标签
应用会处理第三方服务返回的额度百分比、使用量、重置时间、计划名称、余额、模型额度和必要的账号标签,用于在应用与小组件中展示状态。这些快照与趋势历史保存在应用沙盒或 App Group 容器中。
macOS 本机 Agent 数据
本机读取默认关闭。经你明确授权后,macOS 版会只读访问下列客户端的默认登录或会话目录,以识别登录状态、查询额度或汇总本机 Token 消耗:
- Codex:
~/.codex/ - Grok:
~/.grok/ - Claude Code:
~/.claude/,以及仅在你主动连接 Claude 后读取相应钥匙串项目 - Gemini CLI:
~/.gemini/ - GitHub Copilot:
~/.config/github-copilot/ - Cursor:
~/Library/Application Support/Cursor/
OhMyToken 不会修改或删除这些目录中的文件,也不会替第三方客户端续期或写入登录。令牌需要刷新时,来自第三方客户端的刷新结果仅保留在内存中;应用自己保存的凭据则可能更新在系统钥匙串中。
本机会话 Token 汇总
当你开启本机消耗扫描时,应用会在设备上解析可识别的 Codex、Grok 会话记录,并按日期、小时和来源汇总 Token 数量。会话正文不会发送给 OhMyToken 开发者,也不会用于广告、分析或模型训练。
应用设置与本地历史
Provider 显示状态、刷新间隔、授权选择、评估选项、额度历史及最近快照存储在设备本地。主应用会通过 Apple App Group 与自己的 Widget Extension 共享必要的最近快照。
3. 网络请求与第三方服务
额度查询和令牌刷新请求由你的设备直接发往你选择的第三方服务商,不经过 OhMyToken 开发者运营的服务器。服务商会像处理其客户端发出的普通请求一样看到必要的账号凭据、请求信息、设备网络地址与技术日志,并依据其自身政策处理这些数据。
OhMyToken 是独立应用。第三方名称仅用于说明兼容服务,不代表这些公司对 OhMyToken 的隶属、赞助或背书。你还应遵守所连接服务的适用条款。
4. 开发者是否收集数据
OhMyToken 当前没有开发者后端、遥测、广告、分析或崩溃上传服务。开发者不会从应用接收你的凭据、额度、会话、账号标签、设备标识符或使用历史。应用代表你向所选服务商发送完成主要功能所必需的请求,不会让 OhMyToken 开发者取得这些数据。
5. 数据保留与安全
- 应用自己保存的凭据保存在 Apple 系统钥匙串中。
- 额度快照、趋势和设置保存在应用沙盒或 App Group 容器中。
- OhMyToken 不会把第三方客户端的完整登录或会话文件复制到开发者服务器。
- 网络请求使用操作系统提供的 HTTPS 能力;第三方服务端的安全与保留由对应服务商负责。
6. 你的控制与删除方式
- 在 macOS“设置 → 本机读取”中撤销本机 Agent 访问授权;撤销后自动刷新与会话扫描会停止。
- 在账号详情中断开单个服务,删除 OhMyToken 保存的该账号凭据、快照与趋势记录。
- 关闭 Provider 可停止其后续刷新并从应用界面隐藏。
- 卸载应用会删除其沙盒数据;系统钥匙串项目的卸载后保留行为由 Apple 平台规则决定。如需协助清理,可联系我们。
- OhMyToken 不会删除第三方 Agent 客户端自身的数据;这些数据应在对应客户端或服务商账号中管理。
7. 儿童隐私
OhMyToken 不面向 13 岁以下儿童,也不会故意收集儿童个人信息。
8. 政策更新与联系我们
如果数据处理方式发生实质变化,我们会更新本页面和顶部日期,并在适用时通过应用界面重新取得授权。隐私或删除请求请发送至 935517644@qq.com。
English
OhMyToken Privacy Policy
Effective and last updated: September 25, 2026
OhMyToken operates no developer server and includes no advertising, analytics, or cross-app tracking SDK. Account credentials, quota snapshots, and usage history are not uploaded to the OhMyToken developer.
1. Scope
This policy applies to the OhMyToken applications for iOS and macOS. OhMyToken is a local dashboard that displays quotas, reset times, pace, and token usage for third-party AI Agent services that you choose to connect.
2. Data processed
Credentials and account status
When you connect a service, OhMyToken may process access tokens, refresh tokens, cookies, account identifiers, or OAuth client information to check login status, retrieve quota information, or refresh an expired token. Credentials saved by OhMyToken are stored in Apple Keychain.
Quota information
The app processes quota percentages, usage totals, reset times, plan names, balances, model limits, and necessary account labels returned by the connected service. Snapshots and trend history are stored in the app sandbox or App Group container for display by the app and its widget.
Local Agent files on macOS
Local access is disabled by default. After your explicit authorization, the macOS app reads the default login or session locations of Codex, Grok, Claude Code, Gemini CLI, GitHub Copilot, and Cursor. Access is read-only. OhMyToken does not modify or delete those clients' files or write refreshed credentials back to them. You can revoke authorization in Settings at any time.
Local token totals
If enabled, the app parses recognized Codex and Grok session records on-device and aggregates token counts by time and source. Session content is not sent to the OhMyToken developer and is not used for advertising, analytics, or model training.
3. Network requests and third parties
Quota and token-refresh requests travel directly from your device to the third-party service you selected. They do not pass through a server operated by the OhMyToken developer. The provider receives the credentials and technical request data needed to provide its service and handles that data under its own terms and privacy policy.
See the privacy policies of OpenAI, Anthropic, Google, GitHub, xAI, and Cursor. OhMyToken is independent and is not affiliated with, sponsored by, or endorsed by these providers.
4. Developer collection and tracking
OhMyToken currently has no developer backend, telemetry, advertising, analytics, or crash-upload service. The developer does not receive your credentials, quota data, sessions, account labels, device identifiers, or usage history. OhMyToken does not track you across apps or websites.
5. Storage, controls, and deletion
- Credentials saved by OhMyToken are stored in Apple Keychain.
- Preferences, snapshots, and trend history are stored in the app sandbox or App Group container.
- Revoke local Agent access in Settings to stop automatic local reads and session scanning.
- Disconnect an account to remove credentials, snapshots, and history saved by OhMyToken for that account.
- Uninstalling removes sandboxed app data. Post-uninstall retention of Keychain items follows Apple platform behavior; contact us for assistance.
- Data owned by third-party Agent clients must be managed in those clients or provider accounts.
6. Children
OhMyToken is not directed to children under 13 and does not knowingly collect children's personal information.
7. Contact
For privacy or deletion requests, email 935517644@qq.com.