Privacy Policy
Last updated: April 1, 2026
Introduction
TokensAI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our AI usage tracking service at tokensai.dev.
Information We Collect
Account Information
- Email address (from OAuth providers like Google or GitHub)
- Username and display name
- Profile information from OAuth providers
AI Provider Credentials
- API keys for OpenAI, Anthropic (Claude), xAI, and Google Gemini
- Service account credentials for Google Cloud (Gemini)
- These credentials are encrypted using industry-standard encryption
Usage Data
- AI API usage statistics (tokens, requests, costs)
- Integration sync history
- Badge customization preferences
How We Use Your Information
We use your information to:
- Provide and maintain the TokensAI service
- Authenticate your account via OAuth
- Fetch and aggregate your AI usage data from connected providers
- Generate usage badges and analytics
- Send service-related notifications
- Improve our service and user experience
Data Security
We take data security seriously:
- Encryption: All API keys and credentials are encrypted at rest using per-user encryption keys
- Secure Storage: Data is stored in Supabase with enterprise-grade security
- HTTPS: All data transmission uses encrypted HTTPS connections
- Access Control: Strict access controls limit who can access your data
Data Sharing and Disclosure
We do NOT sell, trade, or rent your personal information. We may share data only in these limited circumstances:
- With Your Consent: When you choose to make your profile public
- Service Providers: With trusted third-party services (Supabase for hosting, AI providers for fetching usage data)
- Legal Requirements: If required by law or to protect our rights
Public Profiles and Badges
If you enable your public profile, the following information will be visible to anyone:
- Username and display name
- Total AI token usage
- Total API requests
- Usage breakdown by provider (if enabled)
- Generated usage badges
You can disable your public profile at any time in your settings.
Your Rights
You have the right to:
- Access: View all data we have about you
- Update: Modify your account information and preferences
- Delete: Request deletion of your account and all associated data
- Export: Request a copy of your data
- Opt-out: Disable public profile visibility
Data Retention
We retain your data for as long as your account is active. If you delete your account, we will permanently delete all your data within 30 days, except where we are required to retain it by law.
Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party tracking or advertising cookies.
Third-Party Services
TokensAI integrates with:
- Supabase: Authentication and database hosting
- Google OAuth: Account authentication
- GitHub OAuth: Account authentication
- AI Provider APIs: OpenAI, Anthropic, xAI, Google Gemini (to fetch your usage data)
Each service has its own privacy policy. We recommend reviewing them.
Children's Privacy
TokensAI is not intended for users under 13 years of age. We do not knowingly collect information from children under 13.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. Your continued use of TokensAI after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
Email: guptaa.pavan@gmail.com
Website: https://tokensai.dev