Download
Privacy

Privacy policy

itokens runs AI on your Mac. What you type, your files and your models stay on your Mac. There is no advertising, and nothing tracks you as a person.

Effective 29 September 2026.

In short

  • Your prompts, chats, documents, photos and the answers your AI gives are processed and stored only on your Mac. They are never sent to us or to anyone else.
  • itokens asks what to call you so your AI can use your name; that name stays on your Mac. itokens never asks for your email address or payment details.
  • itokens contacts a few services to do its job, such as downloading the AI model it installs. Those are listed below.
  • Once a day, itokens checks in with a random number and basic facts about its version and your Mac, so we know how many people use it and on what. It carries nothing about you or your work.
  • Sharing anonymous usage counts is optional, and nothing is shared unless you say yes. What is shared is listed below, word for word.
  • We care about your experience and want itokens to keep getting better, so we study how people use the website and what people want from local AI. We do it without learning who you are.

How we learn what you want

We care about the experience of everyone who uses itokens, and we work hard to keep improving it. To do that we need to understand what people want, so we look at patterns of use, never at individuals:

  • On this website, Cloudflare Web Analytics shows which pages are visited and how fast they load, so we can see what people look for and what to explain better (details).
  • In the app, the daily check-in tells us how many copies of itokens are in use, on which versions and Macs (details).
  • In the app, only if you choose to: anonymous usage counts show which features and models people use and where things go wrong (details).
  • When you write to us from the app: feature suggestions tell us what to build next (details), and bug reports tell us what to fix (details).

What you do in itokens itself (your chats, documents, photos and models) stays on your Mac and is never part of this.

What the app contacts

itokens talks to these services only for the purpose given. Each of them sees your IP address, as any website you visit does, and handles it under its own privacy policy.

  • Web pages you link in a message, while Read links in messages is on in Settings: itokens reads them from their own sites, as your browser would, and sends them nothing else. Sign-ins you make for them in itokens stay on your Mac.
  • Brave Search (api.search.brave.com), only if you give itokens your own Brave Search API key in Settings: the words your AI searches for, with your key. Brave handles them under its own privacy policy. Remove the key and nothing more is sent.
  • Hugging Face (huggingface.co): the files of the AI models itokens installs (on Macs that can run it, this includes the small model that finds passages in your files by meaning), and, about once a day, the public list of models, to find newer ones that fit your Mac.
  • GitHub: checking for itokens updates and downloading them, and downloading uv and Python when itokens installs them. When updates are switched on for itokens (the daily check-in says so), a new version is downloaded, checked (Apple's signature and notarization) and installed when itokens opens, and itokens restarts by itself.
  • The Python Package Index (PyPI): installing MLX, Apple's AI framework, and the packages it needs.
  • The connections you add, if any: a connection is a program or service you choose, and it may contact its own service (a calendar connection, your calendar provider). itokens shows what a connection runs before you add it, and your AI asks before using one of its tools.
  • insights.itokens.app: the daily check-in; your anonymous usage counts, only if you agree to share them; and suggestions and bug reports you send (all below).

The daily check-in

When itokens opens, and about once a day while it runs, it sends a short check-in to insights.itokens.app, so we know how many people use itokens, on which versions, Macs and AI models, and can keep it working well for them. It contains:

  • a random number made on your Mac when itokens is first used, so that one copy of itokens is counted once;
  • the itokens and macOS versions, your Mac's model (for example "Mac Studio"), chip and memory size, and its AI capability rating;
  • the AI model running on your Mac, how many messages you have sent since you installed itokens, and, for today and yesterday, how many of your messages each model answered (model names and numbers only);
  • a fixed label for the kind of app (the same for everyone), and your answer to "Share anonymous usage".

The receiving server also records the country the request comes from, as reported by Cloudflare. Your IP address is not stored or logged. The answer to the check-in tells itokens whether to install updates by itself and when to check in next. That list is complete: the check-in never contains your name, what you write, what your AI answers, your chats or your files.

Anonymous usage (optional)

After setup, itokens asks once whether you want to share anonymous usage, which gives us a deeper picture than the check-in. Neither answer is chosen for you, and you can change it at any time in Help, Share anonymous usage. If you say yes, itokens counts on your Mac, and adds to the next day's check-in:

  • how many chat messages were sent;
  • the public names of the models that answered them (for example mlx-community/gemma-4-e4b-it-4bit), with a count for each;
  • how many times setup, a download, a model start, a model's first answer or a switch to another model failed;
  • whether you finished or skipped the guided tour;
  • how many times you added something to the Library.

These are names and numbers only: never what you write, what your models answer, your files or their names. Each day is sent once. If you change your answer to no, counting stops and counts not yet sent are deleted from your Mac.

Setup answers from earlier versions

itokens no longer shares setup answers. Earlier versions could share them anonymously if you ticked a box; to have such a record removed, write to [email protected].

What itokens keeps on your Mac

itokens stores its settings, the name you gave it, your chats, projects, skills, connections (with any keys in their setup), your Library and its logs in its own folder in your Library (~/Library/Application Support/itokens), readable only by your macOS user. Models go to your models folder (~/Models by default). A backup you make is a file on your Desktop, readable only by your macOS user; it holds the same things except the models, so keep it private. Removing everything is described in Uninstall.

The microphone in the message box uses Apple's speech recognition on your Mac only: itokens refuses to dictate when your Mac would need to send your voice to Apple's servers, and it listens only while the microphone button is on.

Feature suggestions (optional)

Help, Suggest a feature sends what you write only when you press Send, with the random number, the itokens version and the same fixed label as the check-in, to insights.itokens.app. Suggestions are read by the people who make itokens to decide what to build next; they are not published. To have one removed, write to [email protected]. Floods are refused the same way as bug reports (below).

Bug reports (optional)

Report a bug in the app sends a report only when you press Send, after showing you exactly what will be sent. It becomes a public issue on github.com/itokens-app/issues, so anyone can read it. A report contains what you wrote, the itokens and macOS versions, your Mac's model and its AI capability rating, the model in use and the last error, and, only if you leave the box ticked, the last lines of itokens's own logs. Before sending, itokens removes your home folder and user name, tokens and keys, email addresses and network addresses from everything that comes from your Mac.

To stop repeated sending, the receiving server keeps a count of reports per sender per day under a one-way code made from your IP address and a secret; it cannot be turned back into the address and is deleted after two days. To have a report removed, write to [email protected].

This website

itokens.app is hosted on Cloudflare Pages. It sets no cookies and has no advertising. It uses Cloudflare Web Analytics to count page views and measure how fast pages load; Cloudflare states that it does not collect or use visitors' personal data. It runs on this website only, not in the itokens app. The download page asks GitHub, from your browser, for the latest release so it can show the version and download link. Your light or dark theme choice is remembered only in your browser. Cloudflare, as the host, processes requests to the site under its own privacy policy.

Changes to this policy

We may update this privacy policy from time to time, for example when itokens gains a feature or the law changes. Changes take effect when they are posted on this page, and the effective date at the top shows when the policy last changed. If a change affects what itokens sends from your Mac, the app will tell you about it. By continuing to use itokens after a change, you accept the updated policy.

Contact

Questions about privacy: [email protected].