Privacy Policy
ChatGPT & Codex Usage Tracker is local-first. It has no analytics, advertising, telemetry service, remote database, extension account, or third-party data backend.
chatgpt.com allowance
endpoints. No data is sent to the developer.
What Chrome means by data handling
Chrome requires an extension to disclose data that its code reads, uses, or stores even when that processing happens only on the user's device. Therefore, the words handled or collected in a Chrome Web Store disclosure do not mean that KC-IT or the developer receives the data. KC-IT has no server, analytics account, or telemetry service receiving extension data.
Single purpose
The extension provides local ChatGPT message and token-usage estimates
together with first-party, server-reported Codex allowance status,
renewal information, and related usage controls on
chatgpt.com and in the extension popup.
Data processed
While the user works on chatgpt.com, the extension
temporarily reads visible composer/message text and outgoing or streamed
conversation structures to calculate token and character counts. This
text is processed in browser memory and is not written to extension
storage.
The extension stores locally:
- message role, timestamp, visible model label, estimated token and character counts, attachment count, response duration, and capture source;
- salted SHA-256 hashes of message and conversation identifiers for deduplication;
- first-party Codex allowance percentages, renewal times, plan label, credit state, and aggregate token-profile statistics when available;
- the latest detected weekly-renewal cycle key and detection time, used only to prevent duplicate notifications;
- privacy-safe diagnostic events containing timestamp, severity, event name, and a short status message; and
- preferences such as tracker visibility and position, quota-warning and renewal-notification choices, badge mode, and retention limit.
Data not stored
The extension does not store prompts, assistant responses, conversation
titles, filenames, raw message or conversation identifiers, passwords,
cookies, bearer/access tokens, source code, file contents, or browsing
history outside chatgpt.com. Diagnostic messages do not
contain prompts, responses, credentials, filenames, or raw identifiers.
Authentication information
If a first-party Codex usage endpoint requires bearer authentication,
the extension obtains the ChatGPT access token transiently from
/api/auth/session and uses it inside the
chatgpt.com page context for that same-origin request. It
also derives the ChatGPT account identifier from the token when the
first-party endpoint requires an account header. The access token and
account identifier are never posted to the content script or service
worker and are not stored, logged, exported, shared with the developer,
or sent in a third-party request.
Credit information
When the first-party usage response supplies it, the extension stores and displays Codex credit availability and the returned credit balance. This account credit balance is conservatively disclosed in Chrome's financial and payment information category. The extension does not access payment-card details, bank details, billing addresses, transactions, payment history, financial statements, credit ratings, or lending information.
Chrome Web Store disclosure categories
For Chrome's standardized disclosure form, the current extension declares that it handles these categories:
- Personally identifiable information — only the transient ChatGPT account identifier described above;
- Financial and payment information — only first-party Codex credit availability and the returned account credit balance;
- Authentication information — only the transient access token used for the same-origin allowance request;
- Personal communications — prompt and reply text read temporarily in browser memory for numeric estimates;
- User activity — message-send events and locally stored numeric usage metadata; and
- Website content — visible ChatGPT composer/message text and same-origin conversation structures processed for estimates.
The unselected categories are Health information, Location, and Web history. The extension does not identify, extract, classify, or use text as health data; it does not access location; and it does not collect a list of visited pages, page titles, or visit history. Generic message text is disclosed under Personal communications and Website content regardless of its subject.
Network activity
The extension does not contact a developer-owned or third-party server.
Codex usage refreshes use only first-party, same-origin
https://chatgpt.com/backend-api/wham/ endpoints and, when
authentication is needed,
https://chatgpt.com/api/auth/session
from an already signed-in ChatGPT page. The optional BuyCoffee link
opens only after a user clicks it.
Storage, retention, and user control
Data is stored in the browser-managed extension store (chrome.storage.local
in Chromium and browser.storage.local in Firefox) within
the browser profile. The default history limit is 5,000 numeric message
records and can be changed from 1,000 to 10,000. Diagnostic logs are
limited to the latest 300 events. Users can export numeric history,
download logs, or clear history and logs independently. Uninstalling the
extension removes its browser-managed local storage.
Firefox installation disclosure
Firefox declares required data-collection permissions for authentication information and personally identifying information. These declarations cover only the transient access token and ChatGPT account identifier sent to ChatGPT itself for the first-party allowance request. Visible chat communications and website content are processed locally and are not transmitted outside the add-on or local browser by the extension.
Sharing, sale, and advertising
User data is not sold, shared with the developer, or transferred to third parties outside the approved uses described here. The only extension-facilitated transmission of authentication information and an account identifier is back to ChatGPT itself when required for the first-party allowance request. Data is not used for advertising, creditworthiness or lending, unrelated profiling, or generalized research. The developer and other humans do not receive or read user message content.
Browser store limited use
The extension's use of data complies with the Chrome Web Store User Data Policy, its Limited Use requirements, and Mozilla's Add-on Policies. Data is used only to provide or improve the extension's disclosed usage-tracking features, is not transferred to third parties outside the approved uses described here, is not used for advertising, and is not made available for human reading.
- User data is not sold or transferred to third parties outside the approved use cases.
- User data is not used or transferred for purposes unrelated to the extension's single purpose.
- User data is not used or transferred to determine creditworthiness or for lending purposes.
Accuracy and first-party interface limitations
The browser can see only part of the context processed by ChatGPT. Token values exclude hidden system instructions, internal reasoning, some retrieval or tool results, server-side summaries, and some attachment processing. OpenAI does not expose a fixed subscription token ceiling, so the extension does not convert weighted allowance percentages into token totals. Server-reported Codex activity totals are not allowance ceilings. First-party allowance interfaces may change or be unavailable for some accounts.
Changes
Material changes to data practices will be reflected here and disclosed in the extension interface or listing when required before the changed behavior is introduced.
Contact and support
For privacy questions or support, email 110kc3@gmail.com. General troubleshooting is available on the support page.