Skip to main content
TTokenWise
PrivacyTermsSupport中文

Contents

  1. 1. Scope
  2. 2. Principles
  3. 3. Local data
  4. 4. Network requests
  5. 5. Collection
  6. 6. Permission, retention & deletion
  7. 7. System features
  8. 8. Children
  9. 9. Changes
  10. 10. Contact

Privacy Policy

Privacy Policy

Effective: July 12, 2026 · Last updated: July 21, 2026

In short: TokenWise has no developer-operated account system, server, advertising, or analytics. Credentials and quota data are stored locally, and the TokenWise developer cannot access them. When you sign in, validate a credential, or refresh, the App sends only the necessary authentication information directly to the service you selected.

1. Scope

This Privacy Policy applies to the TokenWise iOS app (“TokenWise” or the “App”) and this legal information website. It explains what information the App processes, why it is processed, where it is stored, and the choices available to you.

2. Privacy principles

  • Local first: Account configuration, credentials, quota snapshots, and preferences are stored on your device. Necessary authentication information leaves the device only when you initiate a connection to the selected service.
  • Data minimization: The App processes only what is needed to show quotas, balances, reset times, and related alerts.
  • No tracking: The App contains no advertising SDK, third-party analytics SDK, or cross-app or cross-site tracking technology.
  • Read-only purpose: Credentials are used to query the relevant service for quota or balance information. The App does not send chat messages or request model-generated content on your behalf.

3. Data stored on your device

DataPurposeStorage
Access tokens, refresh tokens, or API keysAuthenticate and query quota or balance informationiOS Keychain with a device-only protection class
Account name, provider, region, and credential statusIdentify accounts, show status, and handle expired sign-inLocal app files and system preferences
Quota, balance, reset time, and refresh snapshotsDisplay information in the app, widgets, notifications, and Live ActivitiesApp sandbox and App Group shared container
Appearance, notification, region, and feature settingsRemember your preferencesUserDefaults on your device

The TokenWise developer cannot remotely access this local data. Widgets and Live Activities receive only the limited display snapshot they need, never your credentials.

If you install the TokenWise Apple Watch app, the iPhone app may send a limited display snapshot to your paired Apple Watch through Apple’s WatchConnectivity service. This snapshot may include the provider name, account display name, quota windows, usage percentages, reset times, credential status, language, and Pro entitlement status. It never includes access tokens, refresh tokens, API keys, authorization codes, or raw provider responses.

4. Network requests and third-party services

When you sign in, validate a credential, or refresh quota information, the App connects directly from your device to the service you selected. The exact recipients and request data are listed below.

Selected serviceDestinationData sent
Claudeclaude.com, platform.claude.com, and api.anthropic.comOAuth authorization data (authorization code, redirect URI, client identifier, requested scopes, PKCE challenge or verifier, and state), access token, or refresh token, as required for sign-in, renewal, or a quota request
Codexauth.openai.com and chatgpt.comOAuth authorization data (authorization code, redirect URI, client identifier, requested scopes, PKCE challenge or verifier, and state), access token, refresh token, and the ChatGPT account identifier when required
GLMapi.z.ai or open.bigmodel.cn, according to the region you selectAPI key
DeepSeekapi.deepseek.comAPI key
MiniMaxapi.minimax.io or api.minimaxi.com, according to the region you selectAPI key
OpenRouteropenrouter.aiAPI key
Moonshotapi.moonshot.ai or api.moonshot.cn, according to the region you selectAPI key
Kimiapi.kimi.comAPI key

The sole purpose of these requests is to authenticate your existing account and retrieve quota, usage-limit, balance, plan, credential-status, and reset-time information. TokenWise does not submit prompts, send chat messages, upload user-created content, or request model-generated content.

This information travels between your device and the selected service; it does not pass through a server operated by the TokenWise developer. The selected service may also receive technical information normally generated by an internet connection, such as your IP address, request time, and network details. A response may contain an account name, plan, quota, balance, credential status, and reset time, which TokenWise processes and stores locally.

Each service is an independent third-party service with which you have an existing account or credential. It processes the request under its own privacy policy, terms, security practices, and your relationship with that service. These services are not TokenWise advertising or analytics partners, and TokenWise does not direct them to use requests for TokenWise advertising, tracking, or user profiling. TokenWise connects only to the service you deliberately select and never sends one service’s credential to another service.

5. Data collection by the developer

The TokenWise developer does not receive or remotely access your personal data, credentials, quota data, or usage behavior and does not sell or rent such data. We operate no backend, user account system, advertising network, or analytics SDK, and we do not build user profiles. Direct, user-initiated requests to a selected service are described in Section 4 and are not routed through or made accessible to the TokenWise developer.

This legal information website sets no custom cookies and loads no analytics or advertising scripts. Its hosting provider, GitHub Pages, may process necessary technical information such as access logs under GitHub’s own privacy statement; GitHub is independently responsible for that processing.

6. Permission, retention, deletion, and your choices

TokenWise makes no provider authentication or quota request until you select a service and affirmatively initiate the first connection by tapping the applicable sign-in, validation, or add control. That action instructs the App to send the authentication information described in Section 4 to the selected service for the stated read-only purpose. While the account remains added, TokenWise may make the same read-only requests when you refresh manually or when iOS grants the App background refresh time. If you do not want these transfers to occur, do not connect the service or delete the account after connecting it.

Account metadata, quota snapshots, and settings generally remain on your device until you delete the relevant account, change a setting, or remove the App. Keychain credentials follow the separate deletion behavior described below. You may at any time:

  • Choose “Delete account and credentials” in account details to remove that account’s metadata and Keychain credential and stop future requests for that account;
  • Disable notifications, background refresh, or Live Activities in iOS Settings; and
  • Revoke a token, delete an API key, or terminate authorization with the relevant third-party service.

Deleting an account in TokenWise is also how you withdraw your instruction for TokenWise to make future requests for that account. Revoking the credential with the relevant service prevents its further use outside TokenWise as well.

Before uninstalling: Removing the App ordinarily removes its sandbox data, but iOS Keychain items may remain after an app is removed. To ensure credentials are cleared, delete the relevant accounts and credentials inside TokenWise before uninstalling the App.

Because the developer does not hold your App data on a server, we cannot export or delete it remotely. Deletion is performed by you on your device or with the relevant third-party service.

7. System features and permissions

TokenWise may use notifications, background refresh, widgets, Live Activities, WatchConnectivity, and StoreKit to update or display quota status, synchronize a limited display snapshot with your paired Apple Watch, and provide in-app purchases. Apple may process system-level information required to provide these services under Apple’s own privacy terms. You can disable applicable system features in iOS Settings at any time. Declining notifications does not prevent you from using the App’s core quota-viewing functionality.

8. Children

TokenWise is intended for people managing developer tools and AI service accounts and is not designed specifically for children. We do not knowingly collect personal information from children; in fact, the developer does not collect user data through the App.

9. Changes to this policy

If TokenWise’s data practices change, we will update the “Last updated” date on this page and, when appropriate, notify you through release notes or an in-app notice. We will provide reasonable notice before material changes take effect.

10. Contact us

For questions about this Privacy Policy, email boxing.support@gmail.com. Do not include access tokens, API keys, or other sensitive credentials in your message.

© 2026 TokenWise
PrivacyTermsSupport