Privacy Policy
Last updated: 8 October 2026
AI Quota Tool is a Chrome extension and a VS Code extension. The Chrome extension shows your remaining AI quota for Claude, Codex, Copilot, Grok, Gemini, and Cursor, and the balance, spend, or usage of API keys that you add, in one side panel.
Chrome extension: what it reads
The extension reads data only for the providers that you turn on and the API keys that you add.
- It reads your own quota from claude.ai, chatgpt.com, grok.com, gemini.google.com, and cursor.com. It uses your own logged-in browser session.
- It reads your GitHub Copilot seat status from api.github.com. It uses an OAuth token that you approve.
- It reads the data of each API key that you add, only from the provider of that key.
- DeepSeek key: the account balance, from api.deepseek.com.
- Kimi key: the account balance, from api.moonshot.ai.
- Anthropic key: the org spend this month, from api.anthropic.com. It uses an Admin key.
- OpenAI key: the org spend this month, from api.openai.com. It uses an Admin key.
- xAI key: the prepaid credit, from management-api.x.ai. It uses a management key and a team ID.
- Cursor Team key: the team spend, from api.cursor.com. It uses a team Admin key.
- Copilot premium key: the premium requests this month, from api.github.com. It uses a fine-grained GitHub token with read access to the Plan permission.
- Before it saves a key, it makes one test call to the provider of that key.
- The extension asks for access to api.anthropic.com, api.openai.com, management-api.x.ai, and api.cursor.com only when you add a key for that provider.
Chrome extension: what it stores
All data stays on your device in local extension storage. Nothing is synced.
- Quota readings for the providers that you turn on.
- The list of providers that you turn on.
- The GitHub OAuth token. The extension removes this token when you disconnect.
- Each API key that you add, with its name and its team ID (xAI only). The panel shows only the last 4 characters. The extension removes a key when you remove it.
Chrome extension: what it never does
- It does not send your data to a server of ours. There is no server. Requests go only to the services you connect.
- It does not store session cookies or session keys.
- It does not read your chats, your prompts, or your browsing history.
- It does not use analytics, tracking, ads, or remote code.
- It does not sell or share your data.
Chrome extension: how to revoke access
- Any plan provider: turn it off in the Providers screen. The extension stops all requests to that provider.
- Any API key: remove it on the API keys tab. The extension stops all requests with that key.
- Claude, Codex, Grok, Gemini, and Cursor: sign out on the service website.
- Copilot: disconnect in the extension. To revoke the GitHub grant fully, visit https://github.com/settings/applications.
- To revoke an API key everywhere, delete it in the console of its provider. For example: https://platform.deepseek.com, https://platform.kimi.ai, https://console.anthropic.com, https://platform.openai.com, https://console.x.ai, https://cursor.com/dashboard, or https://github.com/settings/tokens.
- To delete everything, remove the extension from Chrome.
VS Code extension
The VS Code extension shows your remaining quota for Claude, Codex, Copilot, and Grok. It also shows the balance or the spend of API keys that you add (Keys).
- It reads your own quota from claude.ai, chatgpt.com, grok.com, gemini.google.com, and cursor.com. It uses a session cookie.
- Sign-in: the extension opens Chrome or Edge with a new, temporary profile in the VS Code extension storage folder. You sign in on the provider site. Then the extension reads only these cookies from that profile: `sessionKey` for claude.ai; `__Secure-next-auth.session-token` (and its parts `.0` and `.1`) for chatgpt.com; `sso` and `sso-rw` for grok.com; `__Secure-1PSID`, `__Secure-1PSIDTS`, and `__Secure-1PSIDCC` for google.com (Gemini, sent only to gemini.google.com); `WorkosCursorSessionToken` for cursor.com. Each cookie goes only to its own host. It does not read other cookies, your browsing history, your chats, your prompts, your passwords, or your own browser profile. It deletes the temporary profile after the read, and also on an error or a cancel.
- You can also paste a session cookie yourself.
- It reads your GitHub Copilot quota from api.github.com (`copilot_internal/user`, the same source that VS Code uses). If that fails, it reads your Copilot seat status. It uses the VS Code built-in GitHub sign-in. VS Code keeps that token. The extension keeps only a flag that says you connected Copilot.
- It reads the balance or the spend of each Key from its own provider: api.deepseek.com (DeepSeek), api.moonshot.ai (Kimi), openrouter.ai (OpenRouter), api.anthropic.com (Anthropic Admin key), and api.openai.com (OpenAI Admin key). It uses the API key that you add.
- An Admin key can manage your whole org. The extension uses it only to read the cost report of the current month. You confirm that it is an Admin key before the extension saves it.
- It stores these secrets in VS Code SecretStorage on your device: the Claude session key, the ChatGPT session token, the Grok sso cookie, and each API key.
- It stores the list of Keys (name, provider, and the last 4 characters) in VS Code extension storage. This list holds no secret.
- It sends each secret only to its own service. There is no server of ours.
- It does not read your chats, your prompts, or your files.
- It does not use analytics, tracking, ads, or remote code.
- It does not sell or share your data.
- The extension keeps each secret until you remove it, sign in again, or uninstall the extension.
- To remove an Account secret, click Sign out on the Accounts tab. To remove a Key, click Remove on the Keys tab. To delete everything, uninstall the extension.
- An optional local connection on 127.0.0.1 can receive quota readings. Any program on your device can send to it.
Contact
Open an issue at https://github.com/BasantPandey/AIQuotaTool/issues.