Privacy
Last updated 16 August 2026
Who is responsible
UsageFleet is operated by Artur Rok, an individual based in Poland, who is the controller of the personal data described here. Questions, requests and complaints go to [email protected].
This page covers the hosted service at usagefleet.com. If you run the server yourself, you are the controller of your own instance and none of the data reaches us.
What the collector sends
The CLI reads the log files Claude Code, Claude Desktop and the pi agent already write on your machine, and uploads one record per assistant message:
- 01Token counts: input, output, cache creation and cache read.
- 02The model name, the service tier, and the message, request and session identifiers.
- 03The timestamp of the message.
- 04The working directory path and the git branch checked out in it.
- 05The machine hostname, the operating system, and the collector version.
- 06The Claude account identifier from your local Claude config, so usage lands on the right subscription.
- 07The 5-hour and weekly utilization percentages Anthropic returns in its own response headers.
It never sends prompts, responses, file contents, file names, environment variables or anything else from the session. The uploader has no code that can read them.
The working directory and branch are the exception worth naming twice: a path can carry a client or project name. They are stored so the dashboard can attribute spend to a project, and they are deleted with the device.
What the account stores
- 01Your email address and display name, from GitHub, Google or the address you signed up with.
- 02A password hash, if you signed up with an email and password.
- 03Session records so you stay signed in.
- 04The device and group names you type, and a SHA-256 hash of each device token. The token itself is shown once and never stored.
- 05Your Stripe customer and subscription identifiers, plan and status. Card details never touch our server.
Why we are allowed to hold it
Usage records, devices, groups and account details are processed to deliver the service you signed up for, which is performance of a contract under Article 6(1)(b) GDPR. Rate limiting, token hashing and abuse prevention rest on our legitimate interest in keeping the service working, Article 6(1)(f). Billing records are kept because tax law says to, Article 6(1)(c).
Who else sees it
- 01Stripe, for payments and the billing portal.
- 02Resend, to deliver verification and password reset email.
- 03GitHub and Google, only if you choose to sign in with them, and only the sign-in exchange itself.
- 04The infrastructure the server and its database run on.
That is the whole list. There are no analytics scripts, no advertising pixels and no third-party trackers on this site, and your data is never sold or shared for marketing. Some of these providers operate in the United States, under the standard contractual clauses their terms include.
Cookies
One cookie, for your session. It is what keeps you signed in, and there is no version of the app that works without it. Your theme choice is kept in your browser and never sent to us.
How long it is kept
Usage records stay until you delete the device they came from, or the account. Deleting a device removes its records; deleting a group leaves its devices ungrouped rather than deleting anything. Invoices and payment records live in Stripe for as long as accounting rules require.
Deleting everything
Settings has a delete button. It removes the account and, by cascade, every device, group, usage record, limit sample and session attached to it. An active paid plan has to be cancelled first: nothing on our side can cancel a Stripe subscription for an account that no longer exists, so the delete is refused rather than leaving a card being charged.
To stop reporting without deleting anything, run usagefleet uninstall on the machine, or delete the device in the dashboard, which makes its token useless immediately.
Your rights
You can ask for a copy of your data, correct it, have it erased, restrict or object to processing, and receive it in a portable format. Email [email protected] and you get an answer within a month. If the answer is unsatisfactory you can complain to the Polish data protection authority, the Prezes Urzędu Ochrony Danych Osobowych.
Changes
If this page changes in a way that affects what is collected, the date at the top changes with it and account holders are told by email. Everything else is a wording fix.