Privacy policy
Last updated 2 October 2026
showmytokens turns your local AI coding usage into a shareable receipt. This page explains, in plain words, what we collect, what we do not, who can see it and how to remove it. The short version: we only ever see daily counts, never your prompts, replies or code.
What the command line tool sends
When you run npx showmytokens it reads the usage logs Claude Code keeps on your computer and uploads, per day:
- the number of messages and sessions, and the length of your longest session;
- token totals per model (input, output and cache);
- how many messages you sent in each hour of the day;
- a random machine id, so that several computers on one account add up correctly.
It never sends prompts, replies, code, file names, project names or file paths. You can run npx showmytokens sync --dry-run to see the exact payload without sending anything, and the whole script is one readable file at /cli.
What we store
- Your account link. When you sign in, our sign-in provider (Clerk) handles your login and holds your email address (and profile details, if you use a social login). We store only your Clerk user id next to your chosen handle, and a flag for whether the handle was verified against an X account.
- Your receipt. Your handle and the daily counts above, plus whether you chose to appear on the leaderboard.
- Sign-in tokens for your computers, stored as one-way hashes, so we cannot read them back.
- Short-lived technical records, such as rate-limit counters keyed by IP address, that expire within an hour.
- Private notes and flags the site owner may add while keeping the service safe, for example marking an account that looks like abuse.
What is public
Your receipt page at /your-handle is public to anyone with the link: your handle, your usage numbers, and the charts built from them. Turning off the leaderboard switch removes you from the leaderboard and from our sitemap and asks search engines not to index your page, but the page itself remains reachable by its link until you delete it. Numbers are self-reported and are not verified by us.
Analytics and cookies
We use PostHog, loaded through our own domain, to understand how the site is used (page views, where visitors come from, which buttons are used). It runs in a cookieless mode: it sets no cookies and uses no browser storage. To count visitors without them, it derives an anonymous identifier from your IP address and browser details that changes every day. We also keep a few anonymous daily counters of our own, for example how many handles were claimed.
Signing in uses cookies set by our sign-in provider to keep you logged in. We use no advertising cookies and we do not sell your data.
Who else handles your data
- Clerk, for sign-in.
- MongoDB Atlas, where our database lives.
- Vercel, which hosts the site and keeps standard server logs, including IP addresses.
- PostHog, for analytics (see above).
- unavatar.io, which supplies X profile pictures for handles verified against an X account.
Deleting your data
Signed in, open your receipt page and use Delete my data. It removes your receipt, your usage history and your handle straight away. Running npx showmytokens logout removes the tool from your computer and revokes that computer's token. Your sign-in account itself is held by Clerk; to remove that as well, contact us.
Children
showmytokens is not meant for children under 13, and we do not knowingly collect their data.
Changes
If this page changes in a way that matters, we will update the date at the top.
showmytokens is an independent project. It is not affiliated with or endorsed by Anthropic.
Contact
Questions, or want something deleted? Use the contact details on the site's home page or repository.