Skip to content

OpenUsage Privacy Policy / OpenUsage 隐私政策

English

1. Overview

OpenUsage is a usage-display and optional notification companion for iPhone, iPad, and Mac. It displays ChatGPT/Codex quota windows, reset times, token statistics, and related usage history. On Mac, you can also choose to pair a mobile device and receive limited Codex task-event notifications.

OpenUsage is provided by JustToday. It is an independent application and is not affiliated with, endorsed by, or operated by OpenAI. ChatGPT, Codex, and OpenAI services are provided by OpenAI and are governed by OpenAI's own terms and privacy policy.

This policy explains what OpenUsage processes locally, what is sent directly to OpenAI or Apple, and what the optional JustToday notification relay processes.

2. Information processed and stored locally

OpenUsage processes or stores the following information on your device as needed to provide its features:

  • ChatGPT device authorization on iPhone and iPad: a temporary device-authorization code and authorization state, followed by the ID, access, and refresh tokens returned after you approve the login. These credentials are stored in the operating system Keychain with device-only protection.
  • Account and usage information: the account email address, account identifier where available, plan type, quota windows, used or remaining percentages, reset times, model or limit names, cumulative token statistics, streaks, peak usage, and daily token totals returned by OpenAI or the local Codex service.
  • Local usage cache: a usage snapshot is stored in the app's local Application Support storage so the most recently loaded information can be displayed when appropriate. This snapshot can include the account information and usage data listed above, but it does not contain your ChatGPT access or refresh token.
  • App preferences: appearance, language, notification choices, and related settings are stored locally.
  • Built-in sample data: when you choose “View Sample Data,” OpenUsage renders a bundled, fictional usage snapshot entirely on the device. Sample mode does not sign in to OpenAI, use an OpenAI account, save the sample snapshot to the local cache or Widget, or send sample values to JustToday.
  • Pairing credentials: when you enable Mac-to-device notifications, random source or pairing bearer tokens are stored in the Keychain. The relay stores only hashes of these bearer tokens.
  • Mac Codex integration: on Mac, OpenUsage starts the locally installed official codex app-server process and requests account and usage information through its local JSON-RPC interface. OpenUsage does not use the notification relay to obtain Mac usage data.
  • Optional Codex Hook inbox: when you enable the Codex notification listener, Codex Hook events are written temporarily to OpenUsage's local Application Support directory. OpenUsage reads the event only to create an eligible notification and removes the local event file after successful relay submission or when the event is not supported. A file may remain temporarily when delivery fails so that the app can retry it. Disabling and uninstalling the OpenUsage Hook removes OpenUsage's Hook helper and inbox.

OpenUsage does not use these local files or credentials for advertising or cross-app tracking.

3. ChatGPT authorization and usage requests

On iPhone and iPad, the device-authorization flow connects directly to OpenAI's authentication service. After you approve the device, OpenUsage sends the access token and account identifier directly to OpenAI as needed to request your account profile, quota, and usage statistics. These requests do not pass through the JustToday notification relay.

On Mac, the locally installed Codex app-server communicates with OpenAI under your existing Codex or ChatGPT login and returns account and usage information to OpenUsage locally. OpenUsage does not receive your OpenAI password.

OpenAI may process device, account, authentication, network, and usage information under its own policies. See the OpenAI Privacy Policy. The availability and format of these OpenAI interfaces may change independently of JustToday.

4. Widget and App Group data

The OpenUsage app and its Widget extension use an Apple App Group. The Widget can read only a reduced usage snapshot needed to render the Widget: the plan type, model or limit name, remaining percentage, quota-window duration, reset time, and snapshot update time. The Widget snapshot does not contain your email address, OpenAI account identifier, ChatGPT tokens, pairing bearer tokens, full token history, conversations, or prompts.

The App Group also stores shared appearance and language preferences. This information remains on the device and is available only to OpenUsage components entitled to the same App Group.

5. Optional Mac-to-device notifications

Mac-to-device notifications are optional. When you enable them, OpenUsage uses a Cloudflare-hosted JustToday relay and Apple Push Notification service (APNs) to pair your Mac with one or more iPhones or iPads and deliver Codex event notifications.

The relay may process:

  • A random source ID, pairing ID, one-time pairing-session identifiers, hashes of one-time secrets or codes, and status timestamps
  • The computer name and mobile-device name shown in the pairing interface
  • Hashed source and pairing bearer tokens
  • The APNs device token, encrypted at rest, and whether the token is for the sandbox or production APNs environment
  • The event type (turn.completed, turn.failed, turn.interrupted, or input.requested), an event identifier, and optional Codex thread and turn identifiers
  • A notification title and limited message used for delivery
  • Delivery status, delivery timestamps, and a bounded error message when delivery fails
  • IP address, request time, counters, and basic network request information needed for rate limiting, abuse prevention, security, and service reliability

The notification title may include a task title derived locally from the Codex task name or the beginning of the first user message. The notification message may include a truncated part of the last assistant message, a requested question, or an approval description or command. The current Mac app limits this event message to 240 characters, and the relay database keeps only a shorter summary of up to the first 160 characters. APNs receives the title and message needed to deliver the notification. Notification content may appear on a device's Lock Screen according to your system notification-preview settings.

The relay does not accept or store your ChatGPT or Codex access token, refresh token, ID token, OpenAI password, full conversation, full prompt body, transcript file, workspace files, or source-code contents. It does not start, continue, stop, or approve Codex tasks.

Pairing QR secrets and eight-digit pairing codes expire after ten minutes and can be claimed only once. The relay stores their hashes rather than the original values.

6. How information is used

OpenUsage and the optional relay use information only as needed to:

  • Authorize your device with OpenAI at your request
  • Load, cache, and display account and usage information
  • Update the OpenUsage Widget
  • Create, authenticate, display, revoke, and protect optional device pairings
  • Deliver the limited Codex event notifications you enable
  • Prevent duplicate delivery, enforce rate limits, diagnose failures, and protect the relay
  • Respond to support, privacy, security, or deletion requests

OpenUsage does not contain a third-party advertising SDK, does not sell personal information, and does not use third-party analytics or advertising identifiers. It does not request contacts, precise location, photos, microphone access, or payment information for the features described in this policy. Camera access is requested only when you choose to scan an OpenUsage pairing QR code; the image is analyzed on the device and is not uploaded to the relay.

7. Third-party services

OpenUsage relies on the following service providers for the functions you choose to use:

  • OpenAI: provides ChatGPT device authorization, the ChatGPT/Codex account, usage information, and the Codex app-server. OpenAI receives the authentication, account, device, network, and usage information necessary to provide those services. See the OpenAI Privacy Policy.
  • Cloudflare: hosts the optional JustToday Worker, D1 database, Durable Objects, and Queues used for pairing, rate limiting, event delivery, and retries. Cloudflare may process network and service data as an infrastructure provider. See the Cloudflare Privacy Policy.
  • Apple: provides Keychain, App Groups, WidgetKit, camera permission controls, APNs, and operating-system notification delivery. Apple processes the APNs device token and push payload as needed to deliver a notification. See the Apple Privacy Policy.

These providers may process information in countries or regions other than your own according to their policies and legal obligations.

8. Sharing and disclosure

JustToday does not sell your information and does not share it for advertising. Information is disclosed only:

  • To OpenAI, Cloudflare, and Apple for the functions described above
  • To infrastructure or support providers when reasonably necessary to operate, secure, or troubleshoot the service and subject to appropriate obligations
  • When required by applicable law, legal process, or a valid governmental request
  • When reasonably necessary to protect users, JustToday, service providers, or the public from fraud, abuse, security threats, or harm

9. Retention, deletion, and your choices

Local account and usage caches remain until they are replaced, you sign out, you clear the relevant app data, or the operating system removes them. Signing out of ChatGPT in OpenUsage deletes the ChatGPT credentials, pending device authorization, local usage cache, and Widget usage snapshot managed by OpenUsage. Keychain behavior after uninstalling an app is controlled by the operating system, so uninstalling alone may not immediately remove every Keychain item.

Local Hook event files are removed after successful processing or when unsupported. A failed event may remain locally for retry. Removing the OpenUsage Hook deletes its helper and Hook inbox. You can disable notification previews or OpenUsage notifications in system settings.

Turning off mobile pairing, removing a paired device on Mac, or disabling the Mac notification source revokes the related relay access and stops future delivery. Relay records may remain marked as expired or revoked, and event, delivery, security, and abuse-prevention records may be retained for as long as reasonably necessary to operate and protect the service, diagnose delivery, resolve disputes, comply with law, and enforce this policy. A revoked record is not treated as an active pairing.

To request deletion of relay records associated with your pairing or source, or to ask a privacy question, email oneleafdev@qq.com. Include enough non-secret pairing context to identify the record. Do not email ChatGPT tokens, pairing bearer tokens, passwords, complete transcripts, or other credentials. OpenAI, Apple, and Cloudflare retain information according to their own policies; requests concerning an OpenAI account should be directed to OpenAI.

10. Security

OpenUsage uses operating-system Keychain protection for credentials, HTTPS for network requests, hashed relay bearer tokens and pairing secrets, encrypted APNs device tokens at rest, short-lived one-time pairing codes, input limits, rate limiting, and revocation controls. No security measure can guarantee absolute protection. Keep your devices and accounts secure, and use system notification-preview settings if task summaries may be sensitive.

11. Children's privacy

OpenUsage is not designed to collect personal information from children. If you believe a child has provided personal information to JustToday through the optional relay or a support request, contact us so that we can take appropriate action.

12. Changes and contact

We may update this policy when OpenUsage features, service providers, or legal requirements change. The last-updated date will be revised when a new version is published, and this policy URL will remain stable.

For privacy questions or deletion requests, contact:

JustToday
oneleafdev@qq.com

简体中文

1. 概述

OpenUsage 是一款适用于 iPhone、iPad 和 Mac 的用量展示与可选通知辅助应用。它会展示 ChatGPT/Codex 额度窗口、重置时间、Token 统计和相关用量历史。你也可以在 Mac 上主动配对移动设备,接收内容有限的 Codex 任务事件通知。

OpenUsage 由 JustToday 提供,是独立开发的应用,与 OpenAI 不存在隶属、授权、背书或联合运营关系。ChatGPT、Codex 及 OpenAI 服务由 OpenAI 提供,并适用 OpenAI 自己的条款和隐私政策。

本政策说明 OpenUsage 在设备本地处理哪些信息、哪些信息会直接发送给 OpenAI 或 Apple,以及可选的 JustToday 通知中继会处理哪些信息。

2. 在设备本地处理和保存的信息

为了提供相应功能,OpenUsage 会按需在你的设备上处理或保存以下信息:

  • iPhone 和 iPad 上的 ChatGPT 设备授权: 临时设备授权码和授权状态,以及你确认登录后返回的 ID Token、Access Token 和 Refresh Token。这些凭据使用操作系统钥匙串保存,并采用仅限本设备的保护方式。
  • 账号和用量信息: OpenAI 或本机 Codex 服务返回的账号邮箱、可用时的账号标识、套餐类型、额度窗口、已用或剩余百分比、重置时间、模型或额度名称、累计 Token 统计、连续使用天数、单日峰值和每日 Token 总量。
  • 本地用量缓存: OpenUsage 会在应用的本地 Application Support 存储中保存一份用量快照,以便按需展示最近一次加载的信息。该快照可能包含上述账号与用量信息,但不包含 ChatGPT Access Token 或 Refresh Token。
  • 应用偏好: 外观、语言、通知选择和相关设置保存在设备本地。
  • 内置示例数据: 当你选择“查看示例数据”时,OpenUsage 会完全在设备本地展示一份随 App 提供的虚构用量快照。示例模式不会登录 OpenAI、不会使用 OpenAI 账号、不会将示例快照写入本地用量缓存或 Widget,也不会把示例值发送给 JustToday。
  • 配对凭据: 启用 Mac 到移动设备的通知后,随机生成的 source 或 pairing bearer token 会保存在钥匙串中;中继服务只保存这些 bearer token 的哈希值。
  • Mac Codex 集成: 在 Mac 上,OpenUsage 会启动本机已安装的官方 codex app-server 进程,并通过本地 JSON-RPC 接口读取账号和用量信息。Mac 用量信息不会通过通知中继获取。
  • 可选的 Codex Hook 收件箱: 启用 Codex 通知监听后,Codex Hook 事件会暂时写入 OpenUsage 的本地 Application Support 目录。OpenUsage 仅在生成符合条件的通知时读取事件;提交中继成功或确认事件不受支持后,会删除对应本地文件。若投递失败,文件可能临时保留以便重试。停用并卸载 OpenUsage Hook 会移除 OpenUsage 的 Hook 辅助程序和收件箱。

OpenUsage 不会将这些本地文件或凭据用于广告或跨应用跟踪。

3. ChatGPT 授权与用量请求

在 iPhone 和 iPad 上,设备授权流程会直接连接 OpenAI 的身份验证服务。你确认设备授权后,OpenUsage 会按需将 Access Token 和账号标识直接发送给 OpenAI,用于请求账号资料、额度和用量统计。这些请求不会经过 JustToday 通知中继。

在 Mac 上,本机安装的 Codex app-server 会基于你已有的 Codex 或 ChatGPT 登录与 OpenAI 通信,并在本地向 OpenUsage 返回账号和用量信息。OpenUsage 不会获取你的 OpenAI 密码。

OpenAI 会依据自己的政策处理提供上述服务所需的设备、账号、身份验证、网络和用量信息。请参阅 OpenAI 隐私政策。相关 OpenAI 接口的可用性和数据格式可能独立发生变化。

4. 小组件与 App Group 数据

OpenUsage 应用与其 Widget 扩展使用 Apple App Group。Widget 只能读取用于展示的精简用量快照,包括套餐类型、模型或额度名称、剩余百分比、额度窗口时长、重置时间和快照更新时间。Widget 快照不包含邮箱、OpenAI 账号标识、ChatGPT Token、配对 bearer token、完整 Token 历史、对话或提示词。

App Group 还会保存共享的外观和语言偏好。这些信息留在设备本地,只有具有同一 App Group 权限的 OpenUsage 组件能够访问。

5. 可选的 Mac 到移动设备通知

Mac 到移动设备通知为可选功能。启用后,OpenUsage 会使用由 Cloudflare 托管的 JustToday 中继和 Apple 推送通知服务(APNs),将 Mac 与一台或多台 iPhone、iPad 配对,并投递 Codex 事件通知。

中继可能处理:

  • 随机 source ID、pairing ID、一次性配对会话标识、一次性 secret 或数字码的哈希值,以及状态时间戳
  • 配对界面展示的电脑名称和移动设备名称
  • source 与 pairing bearer token 的哈希值
  • 加密保存的 APNs device token,以及该 token 对应测试环境或生产环境的信息
  • 事件类型(turn.completedturn.failedturn.interruptedinput.requested)、事件标识,以及可选的 Codex thread ID 和 turn ID
  • 用于通知投递的标题和有限长度的消息
  • 投递状态、投递时间戳,以及投递失败时受长度限制的错误信息
  • 用于限频、防滥用、安全保护和服务稳定性的 IP 地址、请求时间、计数及基础网络请求信息

通知标题可能包含由 Codex 任务名称或首条用户消息开头在本地生成的任务标题。通知消息可能包含末条助手回复、待回答问题、审批说明或命令的截断片段。当前 Mac 应用会将该事件消息限制在 240 个字符以内,中继数据库只保留更短的摘要,最多为前 160 个字符。APNs 会接收完成通知投递所需的标题和消息。通知内容是否显示在锁屏上,取决于你的系统通知预览设置。

中继不会接收或保存 ChatGPT/Codex Access Token、Refresh Token、ID Token、OpenAI 密码、完整对话、完整提示词正文、转录文件、工作区文件或源代码内容。中继不会创建、继续、停止或批准 Codex 任务。

配对二维码中的 secret 和 8 位数字配对码会在 10 分钟后失效,且只能认领一次。中继保存的是它们的哈希值,而不是原始内容。

6. 信息的使用方式

OpenUsage 和可选中继仅在以下用途所需的范围内使用信息:

  • 按你的操作向 OpenAI 发起设备授权
  • 加载、缓存和展示账号与用量信息
  • 更新 OpenUsage Widget
  • 创建、验证、展示、撤销和保护可选的设备配对
  • 投递你主动启用的有限 Codex 事件通知
  • 防止重复投递、执行限频、诊断故障并保护中继服务
  • 响应支持、隐私、安全或删除请求

OpenUsage 不包含第三方广告 SDK,不出售个人信息,也不使用第三方分析服务或广告标识符。针对本政策描述的功能,OpenUsage 不会请求通讯录、精确位置、照片、麦克风或支付信息。只有当你主动扫描 OpenUsage 配对二维码时才会请求相机权限;图像在设备本地识别,不会上传到中继。

7. 第三方服务

OpenUsage 会根据你选择使用的功能依赖以下服务提供商:

  • OpenAI: 提供 ChatGPT 设备授权、ChatGPT/Codex 账号、用量信息和 Codex app-server。OpenAI 会接收提供相关服务所需的身份验证、账号、设备、网络和用量信息。请参阅 OpenAI 隐私政策
  • Cloudflare: 托管用于可选配对、限频、事件投递与重试的 JustToday Worker、D1 数据库、Durable Objects 和 Queues。Cloudflare 作为基础设施提供商可能处理网络与服务数据。请参阅 Cloudflare 隐私政策
  • Apple: 提供钥匙串、App Group、WidgetKit、相机权限控制、APNs 和操作系统通知投递。Apple 会处理完成通知投递所需的 APNs device token 和推送载荷。请参阅 Apple 隐私政策

这些服务提供商可能依据各自政策和法律义务,在你所在国家或地区之外处理信息。

8. 共享与披露

JustToday 不出售你的信息,也不会为了广告共享信息。信息只会在以下情况下披露:

  • 为实现上述功能而向 OpenAI、Cloudflare 和 Apple 提供必要信息
  • 在运营、保护或排查服务问题确有必要时,向承担适当义务的基础设施或支持服务提供商提供必要信息
  • 适用法律、法律程序或有效政府要求规定必须披露时
  • 为保护用户、JustToday、服务提供商或公众免受欺诈、滥用、安全威胁或伤害而合理必要时

9. 保留、删除与选择

本地账号和用量缓存会保留至被新数据替换、你退出登录、清除相关应用数据,或由操作系统移除。你在 OpenUsage 中退出 ChatGPT 登录时,OpenUsage 会删除其管理的 ChatGPT 凭据、待完成设备授权、本地用量缓存和 Widget 用量快照。卸载应用后的钥匙串行为由操作系统控制,因此仅卸载应用不一定会立即移除所有钥匙串项目。

本地 Hook 事件文件会在成功处理或确认不受支持后删除;投递失败的事件可能在本地保留以便重试。移除 OpenUsage Hook 会删除其辅助程序与 Hook 收件箱。你可以在系统设置中关闭 OpenUsage 通知或通知预览。

在移动设备上关闭配对、在 Mac 上移除已配对设备,或停用 Mac 通知 source,都会撤销对应的中继访问并停止后续投递。中继记录可能继续以“已过期”或“已撤销”状态保留;事件、投递、安全和防滥用记录可能在运营与保护服务、诊断投递问题、解决争议、遵守法律和执行本政策所合理需要的期限内保留。已撤销记录不会被视为有效配对。

如需删除与你的 pairing 或 source 相关的中继记录,或咨询隐私问题,请发送邮件至 oneleafdev@qq.com。请提供足以定位记录的非敏感配对信息。请勿通过邮件发送 ChatGPT Token、配对 bearer token、密码、完整转录或其他凭据。OpenAI、Apple 与 Cloudflare 会按照各自政策保留信息;涉及 OpenAI 账号的请求应直接向 OpenAI 提出。

10. 安全保护

OpenUsage 使用操作系统钥匙串保护凭据,网络请求使用 HTTPS;中继对 bearer token 和配对 secret 进行哈希处理,对 APNs device token 加密保存,并采用短时效一次性配对码、输入长度限制、限频和撤销控制。任何安全措施都无法保证绝对安全。请保护好你的设备与账号;如果任务摘要可能包含敏感内容,请调整系统通知预览设置。

11. 儿童隐私

OpenUsage 并非为了收集儿童个人信息而设计。如果你认为儿童通过可选中继或支持请求向 JustToday 提供了个人信息,请联系我们,以便采取适当措施。

12. 政策更新与联系

当 OpenUsage 功能、服务提供商或法律要求发生变化时,我们可能更新本政策。新版本发布时会修改更新日期,本政策网址将保持稳定。

如有隐私问题或删除请求,请联系:

JustToday
oneleafdev@qq.com