@tokalator4.2.0…installs…downloads

Privacy

What we collect, which is very little, and your rights.

Last updated October 10, 2026

The short version

  • No accounts, no cookies, no advertising, and nothing is sold.
  • The website uses cookieless Vercel Web Analytics for aggregate page statistics.
  • The website tools, including the Claude Code log import, run entirely in your browser. Your files are never uploaded.
  • The VS Code extension works locally. It fetches the public pricing catalog from GitHub and nothing else, unless you turn on telemetry.
  • Telemetry is off by default. If you opt in, the extension sends anonymous daily counts. It never sends code, file names, paths, or prompts. You can see, export, and delete that data at any time.

Zero data retention

Tokalator never receives your work, so it never keeps it. Code, prompts, chats, file contents, file names, and paths stay on your machine, in the extension, the Claude Code plugin, the MCP server, and the website tools alike.

With telemetry off, which is the default, the extension, plugin, and MCP server send nothing about you to any server. If you opt in, only anonymous daily counts are kept, and they are deleted 13 months after their last update or as soon as you run Tokalator: Delete My Telemetry Data. Fonts are served from tokalator.ai itself, so loading the site does not contact third-party font services.

Who is responsible

The data controller is Vahid Farajijobehdar, Istanbul, Turkey, the maintainer of Tokalator. Contact: vfaraji89@gmail.com.

Website (tokalator.ai)

Vercel Web Analytics and Speed Insights

We use Vercel Web Analytics and Speed Insights to understand aggregate traffic and performance. They record the page visited, the referrer, country, device and browser type, and performance metrics. No cookies are set, visitors are not tracked across sites, and the data cannot identify you. You can switch either one off at any time with the Privacy choices button in the bottom-left corner; your choice is saved only in your browser. The legal basis is our legitimate interest in running and improving the site (GDPR Art. 6(1)(f)).

Tools and the Claude Code log import

Calculators, price comparisons, and the Claude Code usage import run in your browser. When you choose Claude Code log files, they are read locally to compute token, turn, and cost totals. They are not uploaded or stored anywhere.

Hosting logs

Our host, Vercel, processes IP addresses in short-lived request logs to deliver the site and protect it from abuse. We do not store IP addresses in our database.

VS Code extension

Local by default

Token counting, tab relevance, budget tracking, and Secure Workspace run on your machine. The agent usage card reads usage data that coding agents already keep on your machine: Claude Code session logs (~/.claude/projects), the GitHub Copilot Chat sessions VS Code stores for the open workspace, GitHub Copilot CLI session logs (~/.copilot), and OpenAI Codex CLI session logs (~/.codex). It uses token counts, model names and timestamps to show turns and usage, never sends any of it anywhere, and each source can be turned off (tokalator.claudeCode.enabled, tokalator.agents.copilot.enabled, tokalator.agents.codex.enabled). The agent memory panel lists the instruction, memory, skill and settings files your agents load (for example CLAUDE.md, ~/.claude, AGENTS.md, .github/copilot-instructions.md) and counts their tokens on your machine. Settings files are not read for content, and from MCP configs only server names are counted. None of it is sent anywhere. The hooks list reads your Claude Code settings files locally, and the tool-use view reads only tool and program names from the session logs. Dependency Check runs only when you start it (or daily if you turn on tokalator.dependencyCheck.auto): it sends the names and versions of the packages in your lockfiles to OSV.dev, the package registries (npm, PyPI, crates.io, the Go module proxy, RubyGems, Packagist) and endoflife.date, the same requests your package manager makes. Nothing is sent to Tokalator. Optional session logging (tokalator.enableSessionLogging) also writes aggregate counts to local files only.

Pricing catalog

Once a day the extension downloads the public model catalog from raw.githubusercontent.com. Like any web request, this exposes your IP address to GitHub. No usage data is sent.

Opt-in telemetry

Telemetry helps decide what to improve next. It is only active when both of these are true: you turned on tokalator.telemetry.enabled (the extension asks once, and the answer defaults to no), and VS Code's own telemetry setting is on. The legal basis is your consent (GDPR Art. 6(1)(a)). You can withdraw it at any time by turning the setting off. Doing so stops sending immediately and deletes anything buffered locally.

When telemetry is on, the extension sends one record per day containing:

  • A random installation ID, generated on your machine and not linked to your name, email, account, or IP address
  • The date, extension version, VS Code version, and operating system family (for example, darwin)
  • How many times each feature was used (for example, cmd:optimize: 2, chat:count: 5) and the catalog model IDs selected
  • Claude Code daily totals: number of turns, requests, and sessions, cache hit rate, and the split between the CLI and the VS Code extension
  • Answers to short fixed-choice questions, only if you answer them: what you mainly use Tokalator for, and the optional one-minute survey (role, team size, which coding agents you use, how you pay for AI coding, your biggest difficulty, and interest in team insights). There are no free-text fields.

It never sends source code, file or folder names, paths, repository names, prompts or chat content, environment variables, or credentials. Event names are restricted by the extension so that paths cannot be included.

Run Tokalator: Show Telemetry Data to see exactly what the next upload contains, Tokalator: Export My Telemetry Data to download everything stored for your installation, and Tokalator: Delete My Telemetry Data to erase it from the server and start over with a new ID.

Storage and retention

Telemetry and survey answers are stored in a Prisma Postgres database operated by Prisma Data, Inc., reached through our API on Vercel. Both act as processors on our behalf. Records are deleted automatically 13 months after their last update, or immediately when you use the delete command. Where data is processed outside your country, including in the United States, transfers rely on the providers' standard contractual clauses.

Feedback through GitHub

“Suggest an improvement” opens a prefilled GitHub issue that you review and submit yourself. What you post is public and governed by GitHub's privacy statement.

Your rights

Under the GDPR, UK GDPR, and Turkey's KVKK, you can access, export, correct, or delete your data, object to processing, and withdraw consent at any time without affecting earlier processing. The extension commands above handle access, portability, and erasure directly. You can also email vfaraji89@gmail.com with your installation ID, which is shown by Show Telemetry Data. You may lodge a complaint with your local data protection authority; in Turkey, that is the Personal Data Protection Authority (KVKK). We do not sell or share personal information, and we make no automated decisions or profiles about you.

Third-party services

ServicePurposeData
VercelWebsite hosting, API, Web Analytics, Speed InsightsAggregate page metrics; short-lived request logs
Prisma Data (Prisma Postgres)Storage for opt-in telemetry and survey answersAnonymous daily counts keyed by a random ID
GitHubSource code, issues, pricing catalog fileGoverned by GitHub's privacy statement
Visual Studio MarketplaceExtension distributionGoverned by Microsoft's privacy statement

Children

Tokalator is a developer tool and is not directed at children under 16.

Changes

Material changes will be announced in the extension changelog and reflected in the date at the top of this page. Telemetry stays off unless you turn it on, and a change in what is collected will ask for your consent again.

Also see the Terms of Service.