# Privacy Token Maxxer Hub is local-first. It does not run its own cloud service, create an account, collect analytics, send telemetry, or run a listening server. All data collection is either reading local files/databases already on this machine, or making direct requests to the AI providers you explicitly connect an account to. ## Network activity For each remote provider account you configure (Anthropic Admin API, Z.AI, OpenRouter, DeepSeek, Kimi, Kilo, Novita, Moonshot, Grok, MiniMax), the worker polls that provider's own API in the background roughly every five minutes, using a fixed per-provider HTTPS host allowlist, request timeouts, and exponential backoff after repeated failures. No other host is ever contacted for these accounts. For local-usage providers (SuperGrok, Kiro), the worker shells out to that provider's own local CLI. For Cursor, it reuses the login token Cursor's own editor already stores locally and calls Cursor's usage API directly. For Antigravity, it calls a loopback-only HTTP endpoint you configure yourself — the worker refuses any endpoint that doesn't resolve to `127.0.0.1`, `localhost`, or `::1`, so this setting can't be pointed at a remote host. OpenCode, Codex, and Claude accounts make no network requests at all: their data comes entirely from local session databases/files already on disk. ## Stored data Preferences, account configuration, and cached usage/quota results are stored under `$XDG_STATE_HOME/omarchy/ai-hub` (normally `~/.local/state/omarchy/ai-hub`), in a directory created with owner-only permissions. **API keys and credentials are never written to that state.** A stored credential is kept either in the system keyring via Secret Service (`secret-tool`) or as an environment variable you manage yourself; the plugin's own state only ever holds an opaque reference like `secret-service:jalv13.token-maxxer-hub:`. A secret you type into the account editor is sent to the worker once, over its stdin protocol channel, to be stored in the keyring — it is never included in the panel's snapshot data, worker logs, command-line arguments, or any cache file. Removing an account clears its stored credential from the keyring (for keyring-backed accounts) along with its cached results and history. Token Maxxer Hub does not send prompts, session transcripts, or file contents anywhere — see [README.md](README.md#session-handoff) for what the "resume in native terminal" action does and does not do.