The short version

The native AgentsEye app analyzes AI-provider usage on your Mac. It does not upload prompts or responses to AgentsEye, does not sell personal information, and contains no product telemetry. Optional features communicate directly with services you choose, such as a provider usage endpoint, Discord, or the opt-in encrypted iPhone companion relay.

The Models screen checks AIDataHub’s public release feed about every 15 minutes. The request exposes your network address to AIDataHub and its hosting provider. It sends no provider usage, prompts, credentials, sessions, or workspace names. New-model notifications are off until you enable them and may also reach a connected iPhone through the encrypted companion relay.

Information processed on your Mac

Depending on what you enable, AgentsEye may process:

  • Usage percentages, quota windows, reset times, plans, and collector status.
  • Session timestamps, model names, token counts, request counts, cost estimates, and harness attribution.
  • Preferences, alert settings, provider selections, and outcome feedback.
  • User-authored prompt text only when you explicitly enable prompt history.
  • Local sign-in material only after explicit approval for a connection that needs it.

Prompt history is off by default. When enabled, supported prompt text is redacted for common secret patterns and encrypted locally using a key held in macOS Keychain. AgentsEye excludes recognized app-injected context and indexes user-authored text only. Provider responses are never indexed. Prompt text is excluded from telemetry, diagnostics, reports, alerts, and Discord messages.

Provider connections and Discord

When a provider exposes authenticated quota information, AgentsEye may contact that provider directly from your Mac after you enable it. Provider credentials are not sent to Codeshpere Innovations. Those requests remain subject to the provider’s own terms and privacy policy.

For Claude, AgentsEye checks an approved on-device Claude Code credentials file when available. It may also read Claude Code’s existing macOS Keychain sign-in. Background refresh never opens Keychain permission dialogs or runs Claude commands. Choose Connect Claude Code to grant macOS access explicitly. AgentsEye never saves those credentials. If you explicitly enable browser-based quota access, AgentsEye may read a current Claude session from a supported local browser profile and send it only to Claude’s organization and usage endpoints. It does not scan unrelated browser credentials. The browser session is not copied into the AgentsEye database, diagnostics, logs, or cloud storage.

If you configure Discord alerts, your Mac sends derived quota details directly to the webhook you provide. The webhook is stored locally with restrictive file permissions and is never sent to AgentsEye.

Optional iPhone companion

Connecting an iPhone explicitly enables encrypted quota summaries, recommendations, and alerts through the companion relay. Credentials, prompts, responses, code, workspace labels, and session history stay on the Mac. Encryption keys stay in device-only Keychain storage.

The relay receives public keys, connection identifiers, hashed authentication tokens, delivery timing, encrypted payloads, and the phone push token. Apple receives generic push notifications without quota or provider details. Network addresses are exposed to the hosting provider during normal requests.

The relay retains the latest encrypted summary and up to 20 alerts until replacement or revocation. It serves only readings and alerts younger than 24 hours. Inactive connections expire after 90 days; unfinished pairings expire after five minutes. Expired records are deleted asynchronously, while the API enforces expiry immediately. Operational logs retain invocation metadata for seven days; request bodies and tokens are not logged.

The iPhone stores a protected local summary for the app and widget. Disconnecting online deletes the relay connection and phone cache. Offline revocation must be retried before it is complete. Your Mac must remain running and online for fresh readings.

Diagnostics and notifications

Diagnostic reports are created only when you explicitly export one. They exclude prompts, responses, credentials, webhook URLs, token-usage counts, workspace names, session labels, identifiers, and raw source paths. Reports are never uploaded automatically.

If enabled, native alerts use macOS notifications. Their lock-screen visibility follows your system settings.

This website

Website analytics run only when both public PostHog configuration values are enabled during deployment. When enabled, PostHog records page visits, page exits, and clicks on buttons marked for measurement. Events may include the referring page, browser and device details, and approximate location derived from the network request. PostHog also assigns an anonymous browser identifier using browser storage. AgentsEye does not identify website visitors by name or connect website activity to native app usage.

Website analytics are separate from the native app. The native AgentsEye app does not contain PostHog or transmit product telemetry.

Retention, security, and contact

Local AgentsEye information remains on your Mac until you remove it. Prompt history supports 7, 30, or 90-day retention and in-app deletion. You can also disconnect providers, remove optional secrets, reset local data, or uninstall the app and its Application Support folder. Normal Mac backup software may copy local data according to your settings.

Support messages, purchase records, and legally required business records may be retained as necessary for support, fraud prevention, tax, accounting, and legal compliance. No storage or transmission method is completely secure; keep macOS updated and review diagnostics before sharing.

AgentsEye is a developer utility and is not directed to children under 13. This policy may change as the product evolves; material changes will update the effective date. Privacy questions can be directed through the support page.