Your accounts. Clear answers.
Understand the connection before you make it.
Connecting an AI account means trusting an app with access. Here is exactly what our protection does—and where that protection ends.
Your provider password stays with your provider
We do not ask you to type your Claude or OpenAI password into How Much Usage. Provider sign-in or the connection helper shares authorization tokens with this app. These tokens are sensitive: they can have permissions beyond reading usage, so treat them like login credentials.
Encrypted in storage and protected in transit
The hosted app uses HTTPS for connections. Account tokens are encrypted on the server with AES-256-GCM before they are written to the database. The encryption secret is held separately in the server configuration. This protects token contents if the database alone is exposed.
What the server can access
The app decrypts tokens on its server to connect accounts, fetch usage when you request a refresh, and renew expiring authorization. This is server-side encryption, not end-to-end encryption. Someone with access to both server secrets and stored data could decrypt the tokens. We cannot honestly promise that nobody could ever read them or that any system is risk-free.
What appears in the business dashboard
The owner dashboard shows signup email, plan, dates and the number of linked accounts. It does not display provider credentials or usage contents. Our advertising events exclude connected-account credentials, usage readings and AI conversations. Usage refreshes are user initiated; widgets display saved readings.
How to end access
Remove a connection from your dashboard to stop using it here. For complete revocation, also revoke the relevant session or authorization in your provider account. Removing a connection here does not revoke its token with the provider. Encrypted recovery snapshots or infrastructure backups can retain earlier records, so removal is not a promise of immediate deletion from every backup.
Try it before sharing access
The interactive demo uses fictional accounts and needs no connection. The open-source foundation is also available if you prefer to self-host; its features differ from this hosted app.