Privacy Policy
Last updated: August 1, 2026
Summary: UsageScope keeps API keys, prompts, chats, account details, and AI usage totals on your device. The App uses limited first-party product analytics—controlled in Settings—to understand opens, page views, retention, and future sponsored-banner performance. These analytics use a random installation ID and never include your AI content or credentials. Advertisers receive aggregate reports only.
1. Overview
UsageScope ("the App") is a menu bar (macOS) / system tray (Windows) application that monitors your AI service usage quotas. We are committed to protecting your privacy. This policy explains how the App and the UsageScope website handle your data.
2. Local Monitoring Data
Your AI monitoring data remains local. The App operates primarily on your device. Specifically:
- API keys, OAuth tokens, prompts, chats, raw logs, account details, and AI usage totals are not sent to the product analytics service
- The App does not use an advertising identifier and does not track you across other companies' apps or websites
- No ranking data is sent unless you choose the optional "Check My Tier" flow
3. Product Analytics and Sponsored Content
Product analytics is enabled by default and can be disabled at any time in Settings → General → Privacy → Share Anonymous Product Analytics. Disabling it stops new collection immediately and clears unsent events from the device.
- Collected: a randomly generated installation ID, App version and build, macOS major version, language code, App launch, popover/floating-panel open, page viewed, and—if sponsored content is enabled in a future release—ad eligibility, impression, one-second viewability, click, load failure, and report events
- Not collected: name, email, IP address in stored analytics, account/provider identifiers, API keys, OAuth tokens, prompts, chats, filenames, local paths, token counts, quota values, or billing information
- Pseudonymous processing: the random installation ID is replaced with an HMAC hash before storage. Reinstalling the App creates a new ID
- Purpose: calculate DAU/WAU/MAU, engagement frequency, D1/D7/D30 retention, reliability, impression reach/frequency, viewable rate, fill rate, and click-through rate
- No cross-app tracking: analytics is first-party and is not combined with third-party data for advertising or shared as a user-level profile
Cloudflare processes these events on UsageScope's behalf. Event-level time-series data expires after Cloudflare's Analytics Engine retention window (currently three months). Hashed daily active/cohort rows and aggregate event counts are retained for up to 400 days, then automatically deleted. Aggregate, non-user-level business statistics may be retained longer.
Sponsored banners are currently disabled in production. If enabled later, they will be clearly labeled “Sponsored.” UsageScope will not send advertisers installation IDs or user-level activity; advertisers may receive aggregate figures such as impressions, viewable rate, and clicks.
4. Optional Ranking
If you choose to use "Check My Tier," UsageScope submits a minimal monthly usage summary so the ranking service can calculate your tier. After you join, opening Ranking can refresh that monthly summary up to 12 times per day.
- Uploaded: monthly token totals by board, app version, consent version, and masked email
- Never uploaded: API keys, OAuth tokens, prompts, responses, raw local logs, full email address, or local file paths
- Opt-in first: the first ranking submission happens only after you explicitly confirm it
5. API Keys
To function, UsageScope requires API keys from the AI services you choose to monitor (e.g., Codex, Anthropic, Google, xAI, Perplexity). These keys are handled as follows:
- Stored locally only: API keys are securely stored in your operating system's credential store — macOS Keychain or Windows Credential Manager, the same system your OS uses for passwords and certificates
- Never transmitted: Your API keys are never sent to any server other than the respective AI service's official API endpoint for usage queries
- Encrypted at rest: the OS credential store (macOS Keychain / Windows Credential Manager) encrypts stored credentials at rest
- User-controlled: You can add or remove API keys at any time through the App's settings
6. Network Communication
For usage monitoring, the App makes network requests to the official API endpoints of your connected AI services:
- Codex: api.openai.com
- Anthropic (Claude): api.anthropic.com
- Google (Gemini): generativelanguage.googleapis.com
- xAI (Grok): api.x.ai
- Perplexity: api.perplexity.ai
These requests are used to retrieve your usage and billing information. If product analytics is enabled, the App also contacts events.usagescope.com for the limited events in Section 3. If you opt into optional ranking, the App contacts the UsageScope ranking API for the monthly summary described above.
7. Local Data Storage
The App stores the following data locally on your Mac:
- App preferences: Settings such as polling interval, notification thresholds, and theme preference (stored via UserDefaults in the App's sandbox)
- Cached usage data: The most recent usage data and local token summaries from each service, enabling instant display on App launch (stored locally in the App's sandbox)
- API keys: Stored in the OS credential store (macOS Keychain / Windows Credential Manager, encrypted)
- Ranking participant credential: Stored locally to identify your optional ranking submissions without requiring an account
- Product analytics: A random installation ID and a bounded queue of up to 100 unsent allowlisted events. Turning analytics off clears that queue
All local data is contained within the App's sandbox (macOS) or per-user app data directory (Windows) and is removed when you uninstall the App.
8. Service Providers and Third Parties
The App communicates with third-party AI service APIs as listed above. Each service has its own privacy policy governing how they handle API requests:
- Codex Privacy Policy
- Anthropic Privacy Policy
- Google Privacy Policy
- xAI Privacy Policy
- Perplexity Privacy Policy
Cloudflare: Cloudflare Workers, D1, and Analytics Engine host UsageScope's first-party ranking and product analytics services. Cloudflare processes data on our behalf under its applicable data protection terms.
Website advertising measurement: The UsageScope website uses Reddit Pixel for limited advertising measurement. It measures visits to the website and clicks on links to the Mac App Store or Microsoft Store.
- Reddit technology: Reddit may use cookies or advertising identifiers when processing these events under its own privacy policy
- No directly identifying fields: UsageScope does not intentionally send email addresses, phone numbers, or other directly identifying fields through Reddit Pixel
- Advanced matching disabled: Reddit's automatic advanced matching feature is disabled
For more information about Reddit's data practices, see the Reddit Privacy Policy.
9. Children's Privacy
UsageScope is not directed at children under the age of 13. We do not knowingly collect any information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated revision date. Continued use of the App after changes constitutes acceptance of the updated policy.
11. Contact and Privacy Requests
If you have any questions about this Privacy Policy, please contact us at:
Email: support@usagescope.app
In short: UsageScope never sends your AI credentials or content to its analytics service. Limited first-party product analytics can be disabled at any time, and future advertisers receive aggregate performance reports only. Optional Ranking remains a separate opt-in feature.