What data Tokenize collects
See what the desktop app and provider connections send to Tokenize, how to limit prompt content, and how long data is kept.
Tokenize collects records of AI assistant work so it can show usage, cost, and opportunities to improve. Data comes from two places: the Tokenize desktop app on each computer, and the provider connections an admin adds in Settings → Providers. You control how much session content is included.
From the desktop app
The desktop app reads the session data your AI tools already save on the computer: Claude Code, Claude Desktop and Cowork, OpenAI Codex, and Cursor. It also fetches Claude Code and Codex cloud sessions for the signed-in person. It sends:
- Usage details. Which tool and model ran, when, token counts, estimated cost, session and request IDs, tool calls, errors, and the person's email from the AI tool's sign-in.
- Prompt text. What people typed and the parameters of tool calls, unless prompt text is turned off for the device.
- Full session content. Complete requests and responses. For Claude Code this includes the copies of files it saves before editing them.
- Setup inventory. Which MCP servers and skills are installed. MCP credentials are never sent. See Privacy and redaction.
The app only sends data out. It opens no inbound connections and never runs anything it reads from a session. It does not search your computer for documents or repositories. File contents reach Tokenize when they are part of an AI session, such as a file an assistant read or edited, or when they are part of an installed skill.
Limit prompt text and session content
Two managed preferences control content on each device. Both are on by default.
| Preference | When it's off |
|---|---|
ShipPromptText | Prompt text and tool parameters are not sent. Tokenize records the prompt length instead. The setting also controls prompt logging in the Claude Code and Codex telemetry the app sets up. |
ShipBodies | Full requests and responses and file contents are not sent. |
Set them through your device management tool: on Macs, in a configuration profile for the dev.palindromelabs.transcript-shipper preference domain; on Windows, in the registry policy described in Deploy on Windows. Cost, token, and usage numbers stay available with both off.
If you send Claude Code telemetry with environment variables instead, the content comes from these lines in the snippet Tokenize gives you. Remove them to send usage details only:
OTEL_LOG_USER_PROMPTS=1
OTEL_LOG_ASSISTANT_RESPONSES=1
OTEL_LOG_TOOL_DETAILS=1
OTEL_LOG_TOOL_CONTENT=1
OTEL_LOG_RAW_API_BODIES=1
See OpenTelemetry for the full setup.
From provider connections
When an admin connects a provider, Tokenize uses that key to read your organization's usage and cost reports from the provider. If you also add a Compliance API key for Anthropic or OpenAI, Tokenize reads activity records through that API. See Connect Anthropic, Connect OpenAI, Connect Cursor, and Connect OpenRouter.
How long data is kept
Prompt text and full session content are deleted automatically on a rolling schedule. For retention details, see the Data Processing Addendum. To delete data sooner, see Delete your data.
For how Tokenize protects your data, see Security and our Privacy Policy.