Legal

Privacy Policy

Last updated: July 17, 2026

1. Who We Are

Tokeven, LLC is a limited liability company organized under the laws of the State of Delaware. This Privacy Policy describes how Tokeven, LLC ("Tokeven," "we," "us," or "our") collects, uses, and protects information when you use the Tokeven platform, website, APIs, SDK wrappers, and related services (collectively, "the Service").

2. Information We Collect

Tokeven is built around a core principle: your instrumented AI traffic is metrics-only — we never see its prompts or completions, and we never touch your AI provider API keys. Two narrowly scoped opt-in tools that operate on prompt text you explicitly submit are described in Section 2.4. Here is exactly what we collect:

2.1 Account Information

When you create an account, we collect your email address and a bcrypt-hashed password. If you sign in via Google OAuth, we receive your email and display name from Google. We store your organization name, team role, and plan tier.

2.2 Usage Metadata

The Tokeven SDK wrapper and sidecar proxy run in your environment and send us usage metadata only: model identifier, provider name (Claude, ChatGPT, Gemini), token counts (input, output, cache-read, cache-write), modality (text, code, vision, audio), latency, computed cost estimate, session identifier, and whether the pre-send advisor was used. Prompt length is a local character count calculated on your machine.

2.3 What We Never Collect

We never collect, transmit, or store the content of prompts or completions from your instrumented traffic — the ingest schema has no field that could carry them. We never receive, hold, or process your AI provider API keys (Anthropic, OpenAI, Google). The only credentials Tokeven stores are your account password hash and SHA-256 hashes of your write-only ingest tokens.

2.4 Opt-In Prompt-Text Tools

Two optional tools process prompt text you explicitly submit. Neither touches your instrumented traffic, and both are inactive unless you invoke them. (a) Prompt Revision (dashboard tool): prompt text you paste is sent to Anthropic for rewriting via Tokeven's server; it is used only to produce the revision — do not paste secrets. (b) advisor.improve() / tokeven improve (SDK/CLI): sends the prompt you are improving directly to Anthropic using your own API key; the text never passes through Tokeven's servers.

3. How We Use Your Information

We use collected information to: (a) provide and operate the Service, including dashboards, analytics, cost calculations, and savings tracking; (b) calculate verified savings under the gainshare pricing model; (c) send transactional emails (account verification, password resets, weekly digest summaries); (d) detect and prevent abuse, fraud, or violations of our terms; and (e) improve the Service based on aggregate, anonymized usage patterns.

4. Cost and Savings Calculations

Tokeven calculates costs server-side using token counts from your usage events and our maintained model pricing registry. Savings are computed as the difference between actual cost and the recommended alternative cost for events where you accepted a recommendation. These calculations use metadata only and do not require or involve prompt content.

5. Data Storage and Security

Your data is stored in PostgreSQL on AWS RDS with encryption at rest (AES-256) and in transit (TLS). Passwords are hashed with bcrypt (cost factor 12). Ingest tokens are stored as SHA-256 hashes with a 16-character prefix for identification. JWT access tokens expire after 15 minutes; refresh tokens expire after 7 days. Authorization headers and ingest token values are scrubbed from all server logs.

6. Data Sharing

We do not sell, rent, or trade your information. We share data only with: (a) infrastructure providers (AWS) that host and operate the Service under standard data processing agreements; (b) payment processors (Stripe) to handle billing; and (c) law enforcement or regulatory bodies when required by applicable law, subpoena, or court order. We will notify you of such requests unless legally prohibited from doing so.

7. Data Retention

Usage metadata is retained for the duration of your account. When you delete your account, all associated data (usage events, analytics, savings records, ingest tokens, and team memberships) is permanently deleted within 30 days. Anonymized, aggregate statistics may be retained indefinitely for Service improvement.

8. Cookies and Local Storage

The Tokeven dashboard uses a session cookie containing your JWT access token for route protection. This cookie is set on login and cleared on logout. We use browser localStorage to persist your access token, refresh token, and user profile for the duration of your session. We do not use third-party tracking cookies or advertising pixels.

9. Your Rights

You may: (a) export your data at any time via the dashboard export feature (CSV or JSON); (b) revoke ingest tokens at any time to stop data collection; (c) delete your account and all associated data through the account settings page; and (d) request a copy of the personal data we hold about you by emailing hello@tokeven.com. We will respond within 30 days.

10. Children

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 16, we will delete it promptly.

11. International Transfers

The Service is hosted in the United States (AWS us-east-2). If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the Service. Continued use after changes constitutes acceptance of the updated policy.

13. Governing Law

This Privacy Policy is governed by the laws of the State of Delaware, without regard to conflict of law principles. Tokeven, LLC is organized under the laws of the State of Delaware.