Usage for Claude

Privacy Policy

Last updated 16 September 2026

Your Claude account stays between you and Anthropic. You sign in to claude.ai inside the app, and your usage is read straight from Anthropic by your own device. We run no server in the middle, and we never see your password or your session.

Your usage history is yours. It is kept on your device and, if you use iCloud, in your own private iCloud database — which we cannot read.

No advertising, no tracking, no data for sale. No advertising identifier is read, no tracking permission is asked for, and nothing you do here goes to an ad network or a data broker.

Usage for Claude ("the app") is made by Amir Hayek ("we"). It is an independent app and is not affiliated with, endorsed by, or certified by Anthropic. This policy explains what the app collects, what it deliberately never collects, who else is involved, and how to delete what exists. It covers the Mac app, the iPhone app, the Apple Watch app and all of their widgets.

Signing in to Claude

To show your usage, the app needs to be signed in to your own Claude account. You sign in to claude.ai in a web view inside the app, using Anthropic's own email-code login. We never receive, and never ask for, your Claude password.

The session cookies that sign-in produces are stored in your device's Keychain, which is encrypted by the operating system. If you have iCloud Keychain switched on, Apple may sync them to your other devices in the same way it syncs your other passwords. They are used for one thing: asking claude.ai for your own usage figures.

Those requests go directly from your device to Anthropic. What Anthropic sees is what it would see from a browser signed in to your account, and what it does with that is covered by Anthropic's privacy policy. Signing out from the Accounts screen deletes the stored cookies.

What stays on your device

Your usage history — the sessions, the weekly totals, the charts and the activity grid — is written to a private container on your device that the app and its widgets share. It keeps up to 365 days and older entries are pruned automatically. Your settings, your notification rules and your account list live there too.

If you are signed in to iCloud, history and settings also sync through your own private iCloud database and Apple's key-value store, so your Mac, iPhone and Apple Watch agree. That data belongs to your Apple Account and is handled by Apple under Apple's privacy policy. We have no access to it. If you are signed out of iCloud the app simply does not sync, and nothing else changes.

On the Mac, the Claude Code statistics feature reads Claude Code's own files in your home folder, after you grant access to that folder. Those files are parsed on your device and the results stay there. Their contents are never uploaded to us.

What the app fetches

Besides your usage, the app makes a small number of ordinary web requests. Each one lets the server on the other end see your device's IP address and the usual request details, as any website visit does:

Diagnostics and analytics

The app uses Firebase Analytics and Crashlytics from Google to understand which features are used and to receive crash reports. The iPhone app also uses Firebase Performance Monitoring.

What is sent is limited by an internal rule that the app's own tests enforce. It covers things like which screen or setting was used and the value it was set to, a category for a failure (an HTTP status, "network", "rate limited"), your device model, OS version, app version and region, and counts and buckets — your plan family, for example, rather than your account.

Two identifiers travel with that: a random install identifier created by the app, and an account hash. The account hash is the first 16 hexadecimal characters of a SHA-256 digest of your lowercased Claude account email. It is one-way — the email cannot be recovered from it — and it exists so that when you write in about a problem, we can find the diagnostics for your own installation instead of guessing. Your email address itself is never sent to analytics.

What is never sent, in any event: your Claude password or session cookies, your email address in readable form, the text of anything you type into the app, or the contents of your Claude Code files.

No advertising identifier (IDFA) is read, no tracking permission is requested, and nothing is shared with advertising networks.

Feedback you send us

Sending feedback from inside the app creates an entry in a private issue tracker hosted on GitHub, containing what you wrote plus your app version, build number, device model and OS version. There is an optional field for an email address so we can reply; leave it empty and we have no way to contact you, which is fine.

You can attach screenshots or files to a report. Anything you attach goes to that same private tracker, so attach only what you mean to send.

The Codex beta sign-up

The What's New page offers a form for joining a future TestFlight beta of Codex usage support. It is entirely optional and no feature of the app depends on it.

If you choose to use it, the email address you type — and the wishlist text, if you write any — are sent to the same private GitHub issue tracker described above. Your email is used for one purpose: sending you the TestFlight invitation when the beta opens. It is not added to a mailing list, not used for marketing, and not shared with anyone. Ask us at any time and the entry is deleted.

TestFlight itself is Apple's service. Once you accept an invitation, your participation in the beta is handled by Apple under Apple's privacy policy.

Purchases

Purchases and subscriptions are made through Apple. We never see your payment details — Apple handles the transaction and tells the app only whether you are entitled to the paid features. There is no third-party purchase service and no account to create.

Who else is involved

ServiceWhat it handlesWhat it receives
Anthropic (claude.ai)Your Claude account and your usage figuresRequests from your device, signed in as you
Apple (iCloud, Keychain, App Store, TestFlight)Private sync, credential storage, payments, betasYour history in your own private database; payment; beta participation
Google FirebaseAnalytics, crash reports, performanceDiagnostics, the install identifier and the account hash
GitHubFeedback inbox and the Codex beta sign-upOnly what you send from those forms
GitHub Pages (amirhayek.dev)Announcements, schema and pricing filesYour IP address when the app downloads a file

Nothing on this list receives your data for its own advertising.

Your choices and how to delete things

Requests about your own data, including a copy of what we hold or its erasure, go to the address at the bottom of this page, and are answered in a reasonable time.

Children

The app is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has sent us personal information, write to us and we will delete it.

Changes

This policy may be updated when the app's data handling changes. The date at the top of the page changes with it, and the previous versions of this page remain in the site's public commit history.

Contact

Questions about privacy, or a request about your own data: hayek_dev@icloud.com.