Docs / Privacy & data

What Tokenade sends and stores

Updated

TL;DR — Compaction runs locally; your code, file contents, command arguments and paths never leave the machine. Tokenade sends one small row per compaction (token counts, compactor name, agent, model, program name) to meter your plan. Bug reports upload only after you type a consent phrase and are kept 30 days at most.

Tokenade compacts your agent's tool output on your machine. The output itself, your code, your files and your prompts are never sent to tokenade.net. What is sent is a stream of usage counts that meters your plan, plus the login, update and model-download requests described below. This page lists every field.

Usage events: what is sent

Each compaction writes one row to ~/.tokenade/gain.jsonl. A background reporter sends new rows to tokenade.net over HTTPS, in batches. Each request carries your license key, your machine id, the Tokenade version, and a list of events. Each event has these fields and no others:

FieldContent
tsTime of the compaction (Unix milliseconds).
opName of the compactor or mechanism that acted (for example a compactor name, or dedup).
beforeTokens, afterTokensToken counts before and after compaction.
savedTokens saved, after the corrections described in How savings are measured.
sourceWhich channel produced the row (hook, wrap, proxy…).
agentWhich agent it was for, e.g. claude-code.
modelThe model that dominated that day in your local transcripts, so savings are priced at its rates.
cmdFor shell commands only: the program name (git, cargo). Never its arguments, never a path.
coveredWhether a command-specific compactor handled it, or a generic one.
classA row tag such as dedup or mcp-uncompacted.
ioWhether the saving is on input or output tokens.
esttrue for estimated rows (brevity, batching), which do not count against your quota.

Not sent: the output that was compacted, file contents, file names and paths, command arguments, prompts, the session id, your username or hostname.

Why it is sent

Quotas are enforced by tokenade.net, so these events are how your plan is metered. They cannot be turned off: no setting or environment variable stops them while Tokenade compacts. If the reporter cannot reach tokenade.net for more than 72 hours, Tokenade pauses compaction on that machine and tells your agent:

tokenade — this machine hasn't been able to reach tokenade.net for over 3 days, so tokenade tools are paused (usage can't be metered, which works like an exhausted quota).

Tokenade retests the connection by itself every 15 minutes and resumes on the first answer. tokenade healthcheck or tokenade login forces the test immediately. While paused, your agent keeps working with its normal tools; nothing is blocked. See Troubleshooting.

Other requests Tokenade makes

WhenDestinationWhat is sent
tokenade logintokenade.netA SHA-256 hash of the machine identity, a hostname hint and a platform hint (so you can recognise the machine in your dashboard), and the referral code if you installed with --ref. Then the device code being approved.
License and quota refreshtokenade.netLicense key, machine id, Tokenade version.
Update check, at most every 24 hdownloads.tokenade.netA request for the signed manifest. Turn it off with tokenade upgrade --off.
First semantic or --promptHugging Face, else downloads.tokenade.netA one-time download of the embedding model (about 132 MB).
Dollar estimatesLiteLLM's public price table on GitHub, Helicone's cost listDownloads of model price lists, cached 24 h. Nothing about you is sent.
tokenade web, tokenade searchThe pages and search engines you asked forYour URL or query, as your browser would send it. Disable search with TOKENADE_NO_WEBSEARCH=1.

Requests to tokenade.net identify themselves as tokenade/<version> (<os>). The LLM proxy, when you enable it, forwards your agent's requests to the provider the agent already uses; it does not send them to tokenade.net.

What stays on your machine

  • The dashboard is 100% local. tokenade gain, tokenade dashboard and the status line read ~/.tokenade/ and render locally.
  • The stash (~/.cache/tokenade/stash/) holds the full outputs that were folded, so expand-ref can return them. Entries expire after 7 days.
  • The debug log (~/.tokenade/debug.log) records hook events, including command lines, with secrets redacted. It never leaves the machine unless you include it in a report. Install with --no-debug-log to keep it off.
  • Indexes and caches (index.db, semantic.db, dedup.db) describe your code for local search.

The full list is in Files and paths. tokenade uninstall deletes all of it.

Secrets

Before any output reaches your agent, Tokenade masks credentials it recognises (cloud keys, tokens, private keys, card numbers, high-entropy strings). E-mail addresses, phone numbers, IP and MAC addresses are only masked if you set TOKENADE_REDACT_PII=1. If a credential landed in a cache before you noticed, tokenade scrub-secret <substring> purges that exact string from every Tokenade file, and tokenade scrub-cache re-applies the redaction patterns to the stash and dedup.db.

Bug reports (tokenade report)

tokenade report is the only command that uploads content, and only with your explicit consent:

  1. It shows a data-use contract and asks you to type an exact phrase: i accept the terms (j'accepte les conditions in French). A y/n answer does not count.
  2. In a non-interactive shell it refuses unless you pass --accept "<phrase>", so an agent cannot submit your data on its own.
  3. It then collects Tokenade's own logs and your agents' transcripts (Claude Code, Codex, Cursor…) since install, redacts secrets as well as it can, keeps the most recent data under a 200 MB raw cap, and zips it.
  4. It uploads the zip to tokenade.net, where it is used for automated compression analysis, with no human review, and kept 30 days at most.

Transcripts contain the code and text your agent saw. Check before you send:

tokenade report --dry-run

--dry-run collects, redacts and zips locally into ~/.tokenade/last-report.zip, prints a summary, and uploads nothing. Open the archive and decide. The command requires an activated machine.

Unlinking a machine

To stop a machine from reporting, run tokenade uninstall, which deletes ~/.tokenade/ including the license, or remove the machine from your dashboard at tokenade.net. A removed machine is told so on its next report (MACHINE_REVOKED), wipes its local license and stops compacting.