Sheet 1/1Privacy promiseExhibit A
Tokenbreak draws ads next to your prompt. It doesn't read what you're working on, and ads never go into Claude's context, so they cost zero tokens. Below is the complete list of what leaves your machine.
Sheet 2/3What is sentComplete list
Five fields. That's the payload.
| Field | What it is | Example |
|---|---|---|
| adId | Which ad was on screen | house-rent |
| format | banner, theater or status | banner |
| at | When, in milliseconds | 1791063354000 |
| turnId | Claude Code's opaque id for the turn, so one turn counts once | t_91 |
| deviceId | A random id made on install, not tied to you | 7f3c… |
The mod also downloads ads, which means our server sees your IP address like any website would. We use it only to stop abuse and don't store it with impressions. Clicking an ad goes through a redirect that counts the click for that ad, with no device id and no cookie.
Sheet 3/3What is never sentRedacted by design
Never read, never sent.
- Your code or any file on disk
- Your prompts
- Claude's replies
- Tool calls: file reads, edits, shell commands
- File names, repo names, branch names
- Environment variables and secrets
- Your terminal history
You can check all of this: the mod is open source, and its test suite fails if it ever hooks the prompt, the conversation or tool calls. Read the source. The legal version is the privacy policy.
what our server receives
> refactor the billing webhook to be idempotent⏺ Read(app/api/webhooks/stripe/route.ts)⏺ Update(app/api/webhooks/stripe/route.ts)⏺ Bash(npm test -- webhooks)⏺ Done. Webhook dedupes on event id now.{"adId":"house-rent","format":"banner","turnId":"t_91"}