Privacy policy
Short version: out of the box, the Agent Ledger software collects nothing and sends nothing about you anywhere. Two things are optional and off until you turn them on: an end-to-end encrypted backup, and anonymous usage stats.
The software
- What it reads. Session logs that Claude Code, Codex and Gemini CLI write on your computer. These can contain your prompts, code and file paths. They are read locally and never uploaded.
- What it stores. Your settings, and a history file of parsed token counts, timestamps, working folders and session titles, kept in your user folder (locations). With a backup, also
cloud.json(sync state) andcloud-history.json(daily totals restored from your other computers). Delete those folders to remove everything on this computer. - Network. The dashboard server only accepts connections from your own computer (127.0.0.1). Without a backup or stats, the only outgoing request is the optional price update, which downloads a public file from GitHub (raw.githubusercontent.com). No identifiers, usage data or log contents are sent. GitHub, like any web host, can see the IP address that downloads the file.
- No telemetry by default. No analytics, crash reporting or usage tracking unless you turn on anonymous stats (below).
Optional encrypted backup
If you sign in (Settings → Backup and sync, or agent-ledger cloud login), Agent Ledger backs up to the Agent Ledger sync service. Without an account, nothing below applies.
- What is backed up. Your settings: plan fees, pace, price overrides, budgets, and project renames, merges and budgets (these include project folder paths such as
~/code/storefront). If "Also back up daily totals" is on (it is by default once you sign in, and you can turn it off), also token counts, request counts, active time, lines added and API-equivalent cost per day, tool, project and model. - What is never backed up. Your logs, prompts, AI responses, code, session titles,
history.json, log folder locations, budget-alert state and the price cache. - Encryption. Everything is encrypted on your computer (AES-256-GCM) with a key that only your passphrase or your recovery key can unlock, before it is uploaded. The service stores only scrambled data and cannot read it, and neither can we. The passphrase and recovery key never leave your computer.
- No reset. If you forget your passphrase and lose your recovery key, your backup can't be recovered, by you or by us.
- What the service can see. Your email address (used only to send sign-in codes; it is not linked to anything inside your encrypted data), that you have an account, how many backup items you have and their sizes, when they change, and the devices you signed in on (named "Agent Ledger on your computer's name") with when each was last used. Like any web service, it also sees the IP address each request comes from; it does not log it.
- On your computer. The sign-in token and the unlocked key are kept in the macOS Keychain. On other systems the key is held in memory only, and the sign-in token is saved in
cloud.jsonin the settings folder, readable only by your user. - Leaving. "Sign out" removes this computer's access and keeps your local data. "Delete cloud backup" deletes the account and everything stored for it on the service. Neither touches your logs or local settings.
Optional anonymous stats
Off by default, and separate from the backup. If you turn on "Share anonymous usage stats", Agent Ledger sends at most once a day: a random install ID made only for this purpose (not your account, device or email), the app version, and how many internal errors the dashboard hit since the last report. It is sent without any sign-in token, the service stores only a hash of the install ID, and it keeps no IP addresses. No projects, costs, settings or log contents are included.
This website
This website sets no cookies and runs no analytics or third-party scripts. The hosting provider may keep standard server logs, such as IP addresses and requested pages.
npm
Installing through npx or npm downloads the package from the npm registry, which is governed by npm's own privacy policy.
Changes
If this policy changes, the updated version will be posted on this page.