Privacy Policy
Summary. TokenMaxxer has no developer server. The API keys, login tokens and session cookies you add, and the usage data the app fetches, are stored only on your device. The developer never receives or keeps them. To check usage, your device talks directly to the AI services you chose. The app has no ads, analytics or tracking.
Minjun Kim ("the developer") operates the TokenMaxxer app ("the app") and this website, and handles your information as described below, in line with the Korean Personal Information Protection Act and other applicable laws.
01Information processed and how
The app processes the following information only on your device. The developer does not collect or receive it.
| Category | Items | When |
|---|---|---|
| Credentials | API keys, OAuth access and refresh tokens, web-login session cookies and tokens, provider-specific settings (e.g. region, organization ID) | When you add an account or finish a provider login |
| Account display data | Account label, sign-in method, enabled state | When you enter or change them |
| Usage data | Usage percentages, reset times, credits, balance and cost, plus the account email, plan and organization name a provider includes in its response | When the app fetches usage from a provider |
| Widget summary | Provider name, account label (which can be the login email if you left the label empty), usage percentage, reset time, error summary; never credentials | After each refresh, to show widgets and Live Activities |
| App settings | Auto-refresh interval, app icon choice | When you change a setting |
The app has no sign-up and does not collect your name, phone number, location, contacts, photos or advertising identifier.
02Purpose
The information is used only to fetch the usage, limits and balance of the AI service accounts you added and show them in the app, home and lock screen widgets, and Live Activities. It is never used for anything else or combined with other data.
03Storage and retention
- iOS: credentials are encrypted in the iOS Keychain. Keychain items may be included in iOS encrypted device backups according to iOS backup rules.
- Android: credentials are stored in an app-private file encrypted with an Android Keystore key. App data is excluded from device backups.
- Fetched usage is kept in memory while the app runs; the widget summary keeps only the latest snapshot in the app's private shared container.
- Data is kept until you delete the account in the app or delete the app.
04Deletion
Deleting an account in the app immediately removes its credentials and usage records from device storage. Deleting the app lets the operating system remove the app's data. iOS Keychain items can remain on the device after the app is deleted, so delete your accounts inside the app first if you want them fully removed.
05Communication with AI service providers
The developer does not share your information with third parties. The app does, however, send requests that carry an account's credentials directly to the servers of the AI services you added (for example OpenAI, Anthropic, Google, GitHub, Cursor, OpenRouter; "providers"). This happens between your device and the provider at your request and never passes through the developer.
- What a provider receives: the credentials for that provider account and the usual connection data of a request (IP address, device and app information).
- When: when you refresh, save an account, or when auto-refresh or background refresh runs (iOS Background App Refresh; on Android, a 15-minute job while a widget is in use).
- Provider servers may be located outside Korea, such as in the United States. Each provider handles what it receives under its own privacy policy.
OAuth sign-in happens on the provider's own login page. Web login runs in a separate temporary browser session per account; when it finishes, only that provider domain's cookies or token are stored for that account.
06Processors and international transfer
The app does not use processors, and the developer does not transfer personal information abroad. This website is served on Cloudflare, Inc. infrastructure, and Cloudflare may process connection records such as IP addresses to deliver and secure the pages. The website uses no cookies and no analytics.
07Automatic collection
The app contains no advertising, analytics, crash reporting or tracking SDKs and does not use advertising identifiers (IDFA or Android advertising ID). Cookies handled in the web-login screen exist only for provider sign-in as described in section 05 and are never sent to the developer.
08Information you share yourself
The "flex" share card and brag text are created on your device only when you tap share, and go to the app you pick. They contain provider names, an account label (omitted if it looks like an email), usage percentages and account counts, never credentials or emails. Device-code copy and text copy write to the clipboard only when you tap them.
09Security measures
- Encrypted storage in the operating system's secure storage (iOS Keychain, Android Keystore)
- Credentials and web-login sessions are separated per account
- HTTPS for provider communication, except local or private addresses you configure yourself (such as a self-hosted model server)
- No credentials in widget summaries, share cards or logs
10Your rights
Because everything stays on your device, you can view, edit, delete or disable your accounts directly in the app. The developer does not hold this data and therefore cannot view or delete it for you, but questions are welcome at the contact below. You may also exercise your rights through a legal representative.
11Children
The app is not directed to children under 14 and does not knowingly process their personal information.
12Privacy officer
Minjun Kim (developer) · mtmt906@gmail.com
13Remedies
For reports or advice about privacy infringement in Korea you can contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), the KISA Privacy Infringement Report Center (118, privacy.kisa.or.kr), the Supreme Prosecutors' Office (1301, spo.go.kr) or the Korean National Police Agency (182, ecrm.police.go.kr).
14Changes
Changes are posted on this page with a new effective date. Changes that matter for your rights are announced at least 7 days in advance. If the Korean and English versions differ, the Korean version prevails.