Tokens
Privacy Policy
Summary
Tokens is a quota-tracking app for iPhone. We do not collect, sell, rent, or share your personal data with anyone. Your credentials and usage data stay on your device. Tokens talks directly to the Codex and Gemini APIs on your behalf — there is no intermediary server operated by us.
Who we are
Tokens is developed by AppsDev, an independent iOS developer.
- Contact email: dev.play.apps@gmail.com
- Website: https://apps.dev.kz
In this Policy, "we," "us," and "our" mean AppsDev as the developer of Tokens. "You" means the user of the app.
Information the app handles
When you use Tokens, the app stores the following data locally on your device:
- OAuth credentials — Access and refresh tokens for your Codex (OpenAI) and Gemini (Google) accounts, obtained through browser-based OAuth with PKCE. These are stored in the iOS Keychain and in the on-device App Group shared preferences used by the app and its widgets.
- Usage snapshots — Quota percentages, limits, and timestamps fetched from the Codex and Gemini APIs. Stored in the App Group shared container for widget access.
- Usage history — Local history of quota readings used for charts and analytics. Stored on device.
- Notification preferences — Your chosen alert thresholds and settings. Stored on device.
- Subscription tier — Your plan type (Free, Pro, etc.) as reported by the provider APIs. Stored on device.
We do not send any of this information to any server operated by us. We do not have servers that store your data.
How the app communicates
Tokens makes direct HTTPS requests to:
- OpenAI (chatgpt.com) — to fetch your Codex quota usage
- Google (cloudcode-pa.googleapis.com) — to fetch your Gemini quota usage
These requests use your stored OAuth tokens and go directly from your device to the provider. No data passes through any server operated by AppsDev.
Widgets and Live Activities
Tokens provides home screen widgets, gauge widgets, an advisor widget, and Live Activities. These display your most recent usage snapshot, which is read from the on-device App Group shared container. Widget refresh uses App Intents that run on your device. No network request is made by a widget to any server of ours.
Background refresh
Tokens uses iOS Background App Refresh (BGAppRefreshTask) to periodically update your quota data. These background fetches communicate directly with the Codex and Gemini APIs from your device. No data is sent to us.
Notifications
All notifications in Tokens are local notifications scheduled on your device. They are triggered by quota thresholds you configure. No push notification server is involved. No notification data is sent to us.
Information we do NOT collect
Tokens does not:
- Use any third-party analytics (no Firebase, Amplitude, Mixpanel, etc.)
- Use any advertising or ad-tracking SDK
- Use any third-party crash reporting service
- Collect your IDFA or any advertising identifier
- Use App Tracking Transparency prompts — because the app does not track you
- Share data with data brokers
- Sell your personal information
Children's privacy
Tokens is a developer-oriented utility and is not directed at children under 13. We do not knowingly collect personal information from children under 13.
International users, GDPR and CCPA
We want to respect your rights wherever you live.
- Legal basis (GDPR / UK GDPR). The minimal data processing that happens locally on your device is based on performance of our contract with you (providing the app you installed) and your consent (for optional OAuth sign-in).
- Your rights. Because Tokens stores your data on your own device, you can view usage data in the app and disconnect accounts to remove their stored credentials and history. You can contact us with questions about your data.
- California residents (CCPA / CPRA). We do not "sell" or "share" personal information as those terms are defined under California law.
If you wish to exercise your rights or have a question, email dev.play.apps@gmail.com.
Data retention and deletion
- Disconnect an account in Settings to remove its OAuth tokens from Keychain and all associated usage data.
- Uninstalling the app removes its app container, but iOS may retain Keychain entries after uninstall. Disconnect your accounts in Settings before uninstalling to remove the credentials stored by Tokens.
Security
We protect your information by not collecting it on our servers. Credentials are stored in the iOS Keychain and in local App Group shared preferences for widget access. Keep your device protected with a strong passcode and up-to-date software. All API requests use HTTPS.
Third-party services
Tokens communicates with these third-party services on your behalf:
- OpenAI — for Codex quota data, governed by OpenAI's Privacy Policy
- Google — for Gemini quota data, governed by Google's Privacy Policy
Tokens has no other third-party SDKs or services.
Changes to this Policy
We may update this Privacy Policy over time. When we do, we will change the "Last updated" date at the top and note material changes in the app's release notes. Your continued use of Tokens after an update means you accept the revised Policy.
Contact
- Email: dev.play.apps@gmail.com
- Developer: AppsDev