Security and privacy
itokens runs a local server for its window, so it is locked down by default.
What stays on your Mac
What you write, what your AI answers, and your files. Your AI runs locally. itokens contacts Hugging Face (the files of the model it installs), GitHub (update checks, and uv and Python when it installs them), the Python Package Index (installing MLX) and insights.itokens.app (the daily check-in below; anonymous usage only if you agree; suggestions and bug reports you send). The full privacy policy has the details.
The daily check-in
When itokens opens, and about once a day, it sends insights.itokens.app a random number made on your Mac (the only id: itokens never reads your Apple Account), the itokens and macOS versions, the Mac model, chip, memory size and AI capability rating, your answer to "Share anonymous usage", the public name of the model you use, the total number of chat messages you have sent, and for today and yesterday how many chats each model answered. Numbers and public model names only: never what you write. The answer tells itokens whether to install updates by itself (verified as in Updates) and when to check in next. No IP address is stored or logged. The privacy policy lists it word for word.
Anonymous usage (optional)
Asked once after setup, with no answer chosen for you; change it in Help, Share anonymous usage. With yes, itokens counts on your Mac, and sends one day at a time: chat messages, the public names of the models that answered, failures (setup, downloads, model starts, first answers, model switches), whether you finished or skipped the tour, and use of the Library. Names and numbers only. With no, counting stops and unsent counts are deleted. The privacy policy lists it word for word.
The local server
- Listens on
127.0.0.1only. A random 256-bit session token is created at each launch and exchanged once, through a single-use link, for an HttpOnly, SameSite=Strict cookie; every API call needs it. - A Host allow-list against DNS rebinding, an Origin check on every change, a strict Content Security Policy, and no CORS.
- itokens needs no administrator rights: everything it installs goes into its own folder.
Downloads
Model downloads fetch safetensors, config and tokenizer files only, never Python code or pickles, and trust_remote_code is never enabled. itokens only downloads models from its own checked list. Updates are installed only after the signature, notarization and checksum checks described in Updates.
Your data on disk
App data lives in a folder only you can read (0700); the database, logs and Library files are 0600. Every state-changing request is recorded in itokens's log.
Reporting a problem
Please report security issues privately to info@itokens.app, not in public issues. Other problems: use Report a bug in the app, or open an issue on itokens-app/issues.