Tokenkarma browser extension Privacy Policy
The Tokenkarma browser extension is a collector. On the AI services you are already signed in to (Claude, ChatGPT, Gemini, Grok, Perplexity and Cursor) it reads the usage counters those services expose, and sends the readings to your tokenkarma account.
It does not modify the pages you visit, and it displays nothing inside them. The extension does not inject a usage badge or other content into provider pages. Your numbers are read in the tokenkarma app and in the web dashboard; the extension's own popup shows collection status only. This policy covers the browser extension; the tokenkarma desktop app has its own policy.
The extension is account-based: it syncs your readings to your tokenkarma account so you get history, charts and limit alerts across devices. We are upfront about exactly what that means below.
What we collect
- Your tokenkarma account. Your email and account information returned by email-code sign-in identify you as the account owner. The extension stores a Tokenkarma authentication token locally to authenticate synchronization requests.
- Your AI provider accounts. When you are signed in to a supported AI service, the extension reads the account email or identifier of that service. We collect this so your usage is stored separately for each account (see "Multiple accounts"). Subscription details are also processed when exposed by the provider.
- Your usage data. For each provider we read the usage/limit information the service exposes, for example the percentage of a 5-hour or weekly limit, messages or requests remaining, or usage-based spend. We store these readings over time so you get history, charts and alerts. We do not read the content of your conversations.
- Installation information. A persistent installation identifier, browser information, operating system and extension version help associate readings with the correct installation.
- Collection diagnostics. Provider, detected subscription, timestamps, collection outcome, request-stage and HTTP-status information, and available measurement capabilities help diagnose collection failures and changed provider endpoints. These diagnostics are associated with your account and installation; they are not anonymous.
Your browser's existing provider sessions are used to request information from those providers. Provider authentication credentials are not included in the readings sent to Tokenkarma.
Multiple accounts
Your tokenkarma account is who sees the data. The account the usage belongs to is whichever account is currently signed in on the AI service. If you switch to a different Claude (or ChatGPT, etc.) account, the extension records that account's usage, kept distinct from your other accounts. One tokenkarma user can hold many provider accounts, each stored separately.
How and where data is stored
Usage, account, installation and diagnostic data are sent to tokenkarma's backend, which runs on Cloudflare infrastructure in the EU (West Europe). Data is encrypted in transit and at rest, and tied to your tokenkarma account. The extension also keeps a small local cache in the browser: your sign-in state, collection schedule, validated endpoint configuration, recent readings and pending synchronization data. This allows collection and synchronization to resume after a browser restart or temporary network failure.
Remote configuration
The extension retrieves public configuration from Tokenkarma's API. It contains provider availability and endpoint paths, including paths selected for detected subscriptions. The configuration contains no customer information.
Request logic and parsing are included in the extension package. This configuration does not download or execute remote program code.
What we never do
- We never read or store the content of your conversations.
- We never sell your personal data.
- We never read pages other than the six AI services listed below.
- We never insert, modify or remove anything in the pages you visit.
Aggregated, anonymized usage statistics may be used to improve the product or shown publicly, only with your explicit consent.
Sites the extension can reach
These are every host the extension is allowed to contact, and nothing else. Six are the AI services whose usage you asked it to track; the seventh is our own service.
| Host | Why |
|---|---|
https://claude.ai/* | Read your Claude usage counters, on a page you are already signed in to. |
https://chatgpt.com/* | Read your ChatGPT usage counters, on a page you are already signed in to. |
https://grok.com/* | Read your Grok usage counters, on a page you are already signed in to. |
https://www.perplexity.ai/* | Read your Perplexity usage counters, on a page you are already signed in to. |
https://gemini.google.com/* | Read your Gemini usage counters, on a page you are already signed in to. |
https://cursor.com/* | Read your Cursor usage and spend counters, on a page you are already signed in to. |
https://*.tokenkarma.app/* | This is our own service, not a third party. It is where you sign in to Tokenkarma, retrieve configuration and synchronize readings. The wildcard covers our API and dashboard subdomains. |
Permissions the extension asks for
The extension asks for two permissions, plus access to the hosts listed above. That is the whole list.
| Permission | Why |
|---|---|
storage | Keep authentication state, collection settings, configuration, readings and pending synchronization locally in the browser. |
alarms | Schedule bounded periodic collection and retry pending synchronization. |
Version 1.1.10 declares no content_scripts or
web_accessible_resources. It asks for no identity,
tabs, scripting, webRequest,
notifications, idle or sidePanel permission.
Your rights
You can request export, correction, or deletion of your data at any time. Deleting your tokenkarma account removes your stored usage history. See the general privacy policy for additional information about data processing and your rights.
Contact
Questions or requests: Contact support.