Skip to content
UsageAtlasDesktop
ProductProvidersPrivacyDownload
Download
UsageAtlas home

Privacy, mapped

Privacy policy

A plain-language account of what UsageAtlas reads, what stays on your device, and where optional analytics and network requests go.

Effective August 1, 2026

On this page

01Overview02Data the desktop app processes03How that data is used04Optional anonymous analytics05Network requests and third parties06Website data07Storage and retention08Your choices09Security10Changes to this policy

01

Overview

UsageAtlas is a local-first desktop application for viewing AI-provider capacity and usage. This policy explains what the desktop application and this website process.

Dashboard processing happens on your device and no separate UsageAtlas account is required. Anonymous product analytics are optional and remain off unless you consent.

02

Data the desktop app processes

Depending on the providers you enable, the desktop app may process:

  • provider identity and plan information;
  • quota windows, remaining capacity, credits, and reset times;
  • token counts, request counts, model names, timestamps, project and session labels;
  • estimated costs calculated from bundled pricing data; and
  • local preferences and redacted diagnostics.

For Codex and Claude, UsageAtlas can read supported credential files and local session logs. For Cursor, it can read the signed-in desktop session from a local read-only database and request bounded usage history. For OpenCode, it reads the local OpenCode database and, where available, clearly labelled local quota estimates.

03

How that data is used

UsageAtlas uses provider and local-activity information only to authenticate supported provider requests, calculate usage aggregates, render the dashboard, remember settings, check for desktop updates, and diagnose errors on your device.

The renderer receives bounded dashboard aggregates. It does not receive provider credentials, raw event rows, database rows, log contents, prompts, or response bodies. Optional analytics never include provider credentials, provider identities, prompts, response content, file paths, project names, usage totals, costs, or quota values.

04

Optional anonymous analytics

If you opt in, the website may send page paths and download-button events. The desktop app may send first-run, app-open, settings, and update events with the app version, operating system, and processor architecture. Session recording and automatic click capture are disabled.

A random installation or browser identifier is stored in the app preferences or browser local storage so visits can be counted without a UsageAtlas account. Events are sent to PostHog through a Cloudflare proxy that removes cookies and replaces the forwarded IP address. PostHog processes the events on UsageAtlas's behalf.

05

Network requests and third parties

When you refresh a supported provider, the desktop app sends requests directly to that provider's service using the provider session already available on your device. Those requests are governed by the provider's own privacy terms.

Packaged Windows and macOS builds periodically contact the Cloudflare-hosted UsageAtlas update service. The website, downloads, and release files are also delivered by Cloudflare. Standard technical request data may be processed by Cloudflare to deliver, protect, and observe those services. Consented product events are processed by PostHog.

06

Website data

This website does not require an account and does not use advertising analytics. It does not initialize PostHog unless you choose “Allow anonymous analytics.” The choice and, if allowed, a random browser identifier are stored in browser local storage rather than an advertising cookie.

Cloudflare may process ordinary delivery and security logs, including IP addresses, request times, requested pages, and browser information. The edge service also records aggregate download and update-request counters without provider or dashboard data.

07

Storage and retention

Desktop preferences are stored locally and remain until you remove the application data or your operating system clears it. Dashboard snapshots and provider responses are held in memory and end when the application process ends.

Anonymous product events and infrastructure logs are retained only as long as reasonably needed for product measurement, delivery, security, abuse prevention, and legal obligations. Retention may vary between Cloudflare and PostHog.

08

Your choices

You can disable individual providers, turn anonymous analytics on or off in desktop settings, reopen the website's Analytics choices from the footer, remove local app or browser data, or uninstall the app. A browser Do Not Track signal is treated as a denial.

Depending on where you live, you may have rights over personal data, including access, correction, deletion, restriction, or objection. Requests can be sent to privacy@usageatlas.com. You may also contact your local data-protection authority.

09

Security

UsageAtlas uses a sandboxed renderer, context isolation, narrow typed operations, navigation restrictions, bounded provider responses, diagnostic redaction, a separate utility process for provider access, HTTPS security headers, and streamed private release storage. No system can be guaranteed completely secure, but the app is designed to reduce the amount and exposure of sensitive data.

10

Changes to this policy

This policy may change as UsageAtlas evolves. Material changes will be reflected by a new effective date on this page. Review the current policy when you install a new release or use a new website feature.

UsageAtlas

One private view of your AI capacity, activity, and spend.

Product

OverviewProvidersLocal-first designDownload

Legal

Privacy policyTerms of use

© 2026 UsageAtlas contributors.

Codex, Claude, Cursor, and OpenCode are trademarks of their respective owners.

Help improve UsageAtlas?

Share anonymous page and download events. No prompts, provider credentials, usage totals, or session recordings are collected. Analytics stays off unless you allow it.