Yes, token use can be tracked the same way, just have to MITM everything. The ToS is a non-issue as it's not a legal issue, unless you plan to do business with Anthropic, not really an issue as you can always go to API later-on, in which case, Anthropic can't supposedly "ban you" as they are saying they don't record prompts.
This is probably the fact that Anthropic's website serves different ToS based on your source IP. European ToS for the subscriptions forbids commercial use.