Privacy

Privacy Policy

What UsageMeter collects, why, and how to get it back or get rid of it.

Last updated: August 31, 2026

Your conversations never leave your browser

UsageMeter reads the usage percentages Claude already shows you, and measures how much each message costs you. It never reads, stores or transmits the content of your conversations — not a prompt, not a reply, not a title. What does reach our servers is the numbers, your settings, and the identity of your account: this page lists all of it, field by field.

01Who we are

UsageMeter is a browser extension and a web dashboard published by PiloteCode. This policy covers the extension (Chrome, Edge, Firefox), the usagemeter.app website and the UsageMeterLink desktop companion. UsageMeter is an independent third-party tool: it is not affiliated with, endorsed by or sponsored by Anthropic, PBC.

Data controller: PiloteCode, contactable at contact@usagemeter.app. For any question about this policy or to exercise your rights, that address reaches a human. We do not have a designated Data Protection Officer — our processing does not meet the thresholds of art. 37 GDPR.

02What we collect

Only what the features need. Everything below is either kept on your device, or sent to our servers as described in the next section:

  • Usage percentages and reset times — read from the same claude.ai endpoint the interface uses (5-hour window, weekly windows, per-model window). Numbers and timestamps only.
  • Measured message cost — for each message you send, the percentage jump it caused, plus the token counts the Claude stream itself reports. This is what powers "messages left" and the token estimates; it contains no text.
  • Claude account identity — email, display name, organisation ID, account UUID and plan tier, so the multi-account switcher can label and switch between accounts.
  • Claude session cookie — read and re-set locally to switch accounts. It stays on your device and is stripped before anything is sent to our servers.
  • Your settings — language, theme, font, meters, notification and feature preferences.
  • Device identifier — a random UUID generated on install, used to attach synced data to an installation before you sign in. It is not derived from your hardware or your browser.
  • UsageMeter account — if you create one: email, name, optional avatar, plan, and the subscription identifiers Stripe gives us.
  • Anonymous activity ping — every few minutes the extension sends its random identifier and its version number so the site can display a live count of active installs. No page, no URL and no usage figure is attached to it.
  • Third-party AI meters — if you enable the ChatGPT or Grok meters, the same kind of usage numbers for those services, read the same way.
  • Claude Code statistics — if you install the UsageMeterLink companion: per-day token totals, model names and project names read from your local Claude Code transcripts. The transcripts themselves are never uploaded.

We do not fingerprint your browser. Earlier versions derived the device identifier from a canvas render and your GPU; since v1.4.11 it is a plain random UUID, and the fingerprinting code has been removed from the extension.

03What we never collect

These are not "disabled by default" — the code to do them does not exist:

  • The content of your conversations: prompts, replies, attachments, titles, projects.
  • Your browsing history, or anything at all from pages other than claude.ai, chatgpt.com and grok.com (and only when you enable those meters).
  • Advertising or profiling trackers. There is no Google Analytics, no Meta pixel, no session recorder, anywhere in the extension or on the site.
  • Your payment card. Stripe handles checkout on its own pages; we only ever see the resulting subscription identifier.
  • Your Claude password, or any Claude API key.

04Cloud sync

Since v1.4.11 sync is part of the product and has no on/off switch: the web dashboard, the desktop companion and multi-device continuity are all built on it. It runs against your UsageMeter account when you have one, and against your random device identifier when you do not. What travels:

  • Settings, feature preferences, meter and indicator choices, themes and customisations.
  • Notification preferences.
  • Claude / provider account list: email, name, organisation ID, plan tier. The session cookie is removed before sending and is additionally stripped again server-side.
  • Usage cache and usage history: percentages, reset times and timestamps.
  • Calibration: the measured percentage-per-message deltas, so a new browser inherits your calibration instead of starting over.
  • Your saved "Ask Claude" prompt presets.

No conversation content is ever synced. Before you sign in, the data is attached to your device identifier only; when you sign in, the device is linked to your account so your other devices see the same state. You can ask for a copy of all of it, or for its deletion, from your account's privacy page — each request is confirmed by a member of the team.

05Why we are allowed to process it (legal bases)

Under art. 6 GDPR, each purpose has its own basis:

  • Performance of a contract (art. 6.1.b) — running the meters, syncing your settings and history across your devices, managing your account and your subscription.
  • Legitimate interest (art. 6.1.f) — the anonymous active-install count, protecting the service against abuse, and keeping the licence check honest. These use a random identifier and no profile is built.
  • Legal obligation (art. 6.1.c) — keeping invoices for the period tax law requires.
  • Consent (art. 6.1.a) — the optional ChatGPT / Grok meters and the desktop companion, which do nothing until you turn them on or install them. You can withdraw that at any time by turning them off.

06What stays on your device

The extension keeps a full local copy of everything it shows, in your browser's extension storage. It is not readable by websites or by other extensions:

  • Your settings, themes, meters and feature preferences.
  • Usage history for the charts (capped, and compacted on write).
  • The Claude session cookies of your saved accounts — needed to switch between them, and never sent anywhere.
  • Your measured calibration and per-turn token log.
  • Your UsageMeter access token, if you signed in.

07Cookies

usagemeter.app sets two cookies, both strictly necessary, so no consent banner is required under art. 5(3) of the ePrivacy directive. We do not set a single analytics, advertising or profiling cookie:

  • Session cookie (Better Auth) — set only after you sign in, keeps you signed in. Expires with the session.
  • NEXT_LOCALE — set only when you pick a language, remembers it. Expires after one year.
  • Stripe cookies — set by Stripe on Stripe's own checkout pages when you subscribe, under Stripe's policy, never on ours.

The extension itself sets no cookie of its own. It reads and re-sets the claude.ai session cookie locally, and only to switch between your own accounts. The small notice at the bottom of the site is informational: with nothing but strictly necessary cookies there is nothing to consent to, and offering a fake "reject" button would be misleading.

08Browser permissions, one by one

Each permission the extension requests, and what it is actually for:

  • storage — save your settings, history and meters locally.
  • cookies — read and switch the claude.ai session cookie for the multi-account switcher.
  • tabs — reload claude.ai after an account switch and open the pages the buttons point to.
  • notifications — the session-full alert and the connection-expiry reminder, both optional.
  • alarms — schedule the periodic usage refresh and the sync.
  • contextMenus — the "Ask Claude" right-click entry.
  • scripting — inject the meters and tools into the claude.ai pages.
  • webRequest — detect the rate-limit response Claude returns, so the countdown is accurate.
  • Host access to claude.ai — read usage and display the interface.
  • Host access to usagemeter.app — sign in, check your plan and sync.
  • Optional host access to chatgpt.com and grok.com — requested only if you enable those meters, and revocable from your browser.

09How we read Claude usage

The extension calls the same usage endpoint claude.ai calls, from your own logged-in browser session, and reads the percentages back. It never uses the Claude API on your behalf, never sends a prompt, and never acts as a proxy. When a reply finishes, it re-reads that endpoint to measure the percentage the message cost — that measurement is a number, produced entirely on your machine.

10No data sharing with Anthropic

UsageMeter is an independent third-party tool. We do not share, sell or transmit any Claude-related data to Anthropic, PBC, or to anyone else, beyond what your own browser session already does when you use claude.ai. Specifically:

  • We do not forward conversations, prompts or responses to Anthropic or to any other server.
  • We do not transmit Claude authentication cookies or session tokens to any third-party service.
  • We do not access Claude API keys on your behalf.
  • We do not proxy Claude and do not redistribute Claude-generated content.

11Who else touches your data (sub-processors)

The complete list. None of them receives conversation content:

  • Hetzner Online GmbH (Germany, EU) — hosting for the site, the API and the database.
  • Stripe Payments Europe (Ireland, EU) — subscriptions and payments. Stripe is its own controller for payment data; we never see your card.
  • Resend (email delivery) — account emails: verification, password reset, subscription notices.
  • Gravatar / Automattic (United States) — the popup builds an avatar URL from an MD5 hash of your account email. That hash reaches Gravatar when the popup opens. It is only used to display a picture, and it stops if you set an avatar on your account.
  • Google (United States) — only if you choose "Sign in with Google": Google then tells us your email and name.

12International transfers

Your data is hosted in the European Union (Hetzner, Germany) and stays there. Three of our providers may process limited data in the United States: Gravatar (an MD5 hash of your email, only to show an avatar), Google (only if you sign in with Google), and Stripe's global infrastructure for payments. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

13How long we keep it

Nothing is kept longer than it is useful:

  • Account and synced data — for as long as your account exists, then deleted immediately when you delete it.
  • Usage history and token statistics — rolling 24 months, then deleted.
  • Anonymous activity pings — the individual pings are pruned after 10 minutes; only aggregate hourly counts, which identify nobody, are kept.
  • Local data on your device — until you clear it or uninstall the extension; you are in control of that copy.
  • Invoices — kept for the period accounting and tax law requires (10 years in France), independently of your account.

14Your rights

Under the GDPR you have the right to:

  • Access your data and get a copy of it (art. 15 and 20) — file the request from your account's privacy page; once a member of the team confirms it, the full JSON export is downloadable there for a week.
  • Correct it (art. 16) — from your account, or by writing to us.
  • Erase it (art. 17) — file the request from the same page; once confirmed, your account and every row attached to it are deleted.
  • Restrict or object to processing (art. 18 and 21), including our legitimate-interest processing.
  • Withdraw consent at any time, for anything based on consent, without affecting what was done before.
  • Lodge a complaint with a supervisory authority — in France, the CNIL (cnil.fr).

Every export or deletion request is reviewed by a human before anything is produced or erased — a safeguard against a stolen session wiping an account, not a hurdle. We answer within one month, as art. 12 requires, and usually within a few days; you are emailed at each step.

15Deleting everything

Go to usagemeter.app/account/privacy and file a deletion request (you will be asked to type DELETE). A member of the team confirms it; you are emailed, and only then are your account, synced settings, usage history, token statistics, linked accounts, devices and referrals erased. Nothing changes in the meantime, and you can withdraw the request by writing to us. Cancel an active subscription first, so Stripe stops billing. To clear the local copy in your browser, uninstall the extension. If you would rather we handled everything by email, write to contact@usagemeter.app.

16Children

UsageMeter is not aimed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, write to contact@usagemeter.app and we will delete it.

17Security

The measures that protect what we hold:

  • Everything travels over HTTPS; the database is not reachable from the public internet.
  • Claude session cookies are stripped before sync leaves your browser, and stripped again server-side — they are never written to our database.
  • Access tokens are scoped to the extension and expire; passwords are hashed, never stored in clear.
  • Every public API endpoint is rate-limited.
  • In the event of a breach affecting your rights, we notify the supervisory authority within 72 hours and inform you directly when the risk is high.

18Changes to this policy

We may update this policy. The date at the top of this page is the date of the current revision, and material changes are announced in the extension's changelog. If we ever start collecting something new that requires your consent, we will ask for it before collecting anything.

In short

  • Your conversations are never read, stored or transmitted
  • No advertising trackers, no analytics, no browser fingerprinting
  • Sync carries numbers and settings — never text — and only ever to servers in the EU
  • Export or delete everything from your account page — each request confirmed by a human, within the month
  • Only strictly necessary cookies, so nothing to consent to

For any question about this privacy policy, or to exercise your rights, get in touch.