Docs / Privacy & data
What Tokenade sends and stores
Updated
Tokenade compacts your agent's tool output on your machine. The output itself, your code, your files and your prompts are never sent to tokenade.net. What is sent is a stream of usage counts that meters your plan, plus the login, update and model-download requests described below. This page lists every field.
Usage events: what is sent
Each compaction writes one row to ~/.tokenade/gain.jsonl. A background reporter sends new rows to tokenade.net over HTTPS, in batches. Each request carries your license key, your machine id, the Tokenade version, and a list of events. Each event has these fields and no others:
| Field | Content |
|---|---|
ts | Time of the compaction (Unix milliseconds). |
op | Name of the compactor or mechanism that acted (for example a compactor name, or dedup). |
beforeTokens, afterTokens | Token counts before and after compaction. |
saved | Tokens saved, after the corrections described in How savings are measured. |
source | Which channel produced the row (hook, wrap, proxy…). |
agent | Which agent it was for, e.g. claude-code. |
model | The model that dominated that day in your local transcripts, so savings are priced at its rates. |
cmd | For shell commands only: the program name (git, cargo). Never its arguments, never a path. |
covered | Whether a command-specific compactor handled it, or a generic one. |
class | A row tag such as dedup or mcp-uncompacted. |
io | Whether the saving is on input or output tokens. |
est | true for estimated rows (brevity, batching), which do not count against your quota. |
Not sent: the output that was compacted, file contents, file names and paths, command arguments, prompts, the session id, your username or hostname.
Why it is sent
Quotas are enforced by tokenade.net, so these events are how your plan is metered. They cannot be turned off: no setting or environment variable stops them while Tokenade compacts. If the reporter cannot reach tokenade.net for more than 72 hours, Tokenade pauses compaction on that machine and tells your agent:
Tokenade retests the connection by itself every 15 minutes and resumes on the first answer. tokenade healthcheck or tokenade login forces the test immediately. While paused, your agent keeps working with its normal tools; nothing is blocked. See Troubleshooting.
Other requests Tokenade makes
| When | Destination | What is sent |
|---|---|---|
tokenade login | tokenade.net | A SHA-256 hash of the machine identity, a hostname hint and a platform hint (so you can recognise the machine in your dashboard), and the referral code if you installed with --ref. Then the device code being approved. |
| License and quota refresh | tokenade.net | License key, machine id, Tokenade version. |
| Update check, at most every 24 h | downloads.tokenade.net | A request for the signed manifest. Turn it off with tokenade upgrade --off. |
First semantic or --prompt | Hugging Face, else downloads.tokenade.net | A one-time download of the embedding model (about 132 MB). |
| Dollar estimates | LiteLLM's public price table on GitHub, Helicone's cost list | Downloads of model price lists, cached 24 h. Nothing about you is sent. |
tokenade web, tokenade search | The pages and search engines you asked for | Your URL or query, as your browser would send it. Disable search with TOKENADE_NO_WEBSEARCH=1. |
Requests to tokenade.net identify themselves as tokenade/<version> (<os>). The LLM proxy, when you enable it, forwards your agent's requests to the provider the agent already uses; it does not send them to tokenade.net.
What stays on your machine
- The dashboard is 100% local.
tokenade gain,tokenade dashboardand the status line read~/.tokenade/and render locally. - The stash (
~/.cache/tokenade/stash/) holds the full outputs that were folded, soexpand-refcan return them. Entries expire after 7 days. - The debug log (
~/.tokenade/debug.log) records hook events, including command lines, with secrets redacted. It never leaves the machine unless you include it in a report. Install with--no-debug-logto keep it off. - Indexes and caches (
index.db,semantic.db,dedup.db) describe your code for local search.
The full list is in Files and paths. tokenade uninstall deletes all of it.
Secrets
Before any output reaches your agent, Tokenade masks credentials it recognises (cloud keys, tokens, private keys, card numbers, high-entropy strings). E-mail addresses, phone numbers, IP and MAC addresses are only masked if you set TOKENADE_REDACT_PII=1. If a credential landed in a cache before you noticed, tokenade scrub-secret <substring> purges that exact string from every Tokenade file, and tokenade scrub-cache re-applies the redaction patterns to the stash and dedup.db.
Bug reports (tokenade report)
tokenade report is the only command that uploads content, and only with your explicit consent:
- It shows a data-use contract and asks you to type an exact phrase:
i accept the terms(j'accepte les conditionsin French). A y/n answer does not count. - In a non-interactive shell it refuses unless you pass
--accept "<phrase>", so an agent cannot submit your data on its own. - It then collects Tokenade's own logs and your agents' transcripts (Claude Code, Codex, Cursor…) since install, redacts secrets as well as it can, keeps the most recent data under a 200 MB raw cap, and zips it.
- It uploads the zip to tokenade.net, where it is used for automated compression analysis, with no human review, and kept 30 days at most.
Transcripts contain the code and text your agent saw. Check before you send:
--dry-run collects, redacts and zips locally into ~/.tokenade/last-report.zip, prints a summary, and uploads nothing. Open the archive and decide. The command requires an activated machine.
Unlinking a machine
To stop a machine from reporting, run tokenade uninstall, which deletes ~/.tokenade/ including the license, or remove the machine from your dashboard at tokenade.net. A removed machine is told so on its next report (MACHINE_REVOKED), wipes its local license and stops compacting.