Token Cheat CLI sync & privacy
Summary
The Token Cheat CLI runs on your machine. Optional cloud sync sends anonymized summaries only — token counts, hashes, audit scores, and structured issue metadata — not your source code.
What may be transmitted
When you run tokencheat sync (or equivalent) with an organization API key:
- Aggregated usage snapshots (tool name, model id, token totals, estimated cost).
- Audit report payloads (health score, labels, structured issues/recommendations).
- Optional OpenTelemetry batches if you configure the ingest endpoint.
What is not transmitted
- Repository file contents (except what you explicitly paste into local-only tools).
- Raw prompts from third-party tools unless you choose to include them in a report.
API authentication
Organization API keys are stored as one-way hashes server-side. Rotate keys from the dashboard if compromised.
Contact
For enterprise DPA or custom retention, contact your Token Cheat administrator.