Token Cheat CLI sync & privacy

Summary

The Token Cheat CLI runs on your machine. Optional cloud sync sends anonymized summaries only — token counts, hashes, audit scores, and structured issue metadata — not your source code.

What may be transmitted

When you run tokencheat sync (or equivalent) with an organization API key:

  • Aggregated usage snapshots (tool name, model id, token totals, estimated cost).
  • Audit report payloads (health score, labels, structured issues/recommendations).
  • Optional OpenTelemetry batches if you configure the ingest endpoint.

What is not transmitted

  • Repository file contents (except what you explicitly paste into local-only tools).
  • Raw prompts from third-party tools unless you choose to include them in a report.

API authentication

Organization API keys are stored as one-way hashes server-side. Rotate keys from the dashboard if compromised.

Contact

For enterprise DPA or custom retention, contact your Token Cheat administrator.