Privacy Policy
Last updated: July 3, 2026
TokenCheat ("we," "us") operates tokencheat.com (the "Site") and the TokenCheat tools and services (the "Service"). This policy explains what we collect, why, who touches it, and your rights.
Plain-English summary: The free tools run in your browser — pasted configs never reach our servers. If you make an account we store your email and your saved audit results (your file content only if you opt in). The CLI sends us nothing unless you run sync, and never your source code. Analytics are cookieless until you accept the banner. We don't sell data, run ads, or profile you. Email us and we'll delete everything.
1. What we collect
Information you give us
| Data | When | Why |
|---|---|---|
| Email + name | Account signup, newsletter | Sign-in, transactional email, the newsletter you asked for |
| Passkey / 2FA credentials | If you enable them | Account security (public-key material only) |
| Saved audit inputs, scores, fix summaries | When you save an audit | So your reports exist |
| Instruction-file content | Only if you tick "include my optimized file" | So a saved/shared report can show the before/after file |
| Messages | Contact form | To respond |
| Payment details | Never by us | Payments run on a third-party hosted checkout; we never see card numbers |
Browser tools: content pasted into the free calculators and audit runs entirely client-side and is not transmitted to our servers.
Information collected automatically
- Essential cookies for sessions and sign-in (always on; they're how login works).
- Analytics (PostHog, US cloud): page views and product events (e.g. "audit completed" with the score). Cookieless by default — until you accept the consent banner, analytics persist only in memory and set no cookies or local storage. Accepting the banner enables persistent analytics storage. No advertising, no cross-site tracking.
- Server logs (IP address, user agent) held briefly for security and debugging.
CLI telemetry (opt-in only)
The CLI analyzes files on your machine locally. Nothing is transmitted unless you run its sync command with your workspace API key — and then only summary telemetry: token counts, scores, model identifiers, and workspace/ member attribution. Never your source code or file contents.
2. How we use it
Providing the Service; authenticating you; storing and displaying the reports you save; sending transactional email and the newsletter you signed up for; improving the product from aggregate usage; security and fraud prevention; legal compliance. We do not sell personal information, serve third-party advertising, or build advertising profiles.
Published research (like our config-corpus reports) uses aggregate statistics only; local/customer files included in any corpus are anonymized.
Legal bases (GDPR)
| Purpose | Basis |
|---|---|
| Accounts, saved reports, paid audits | Contract |
| Transactional email, security, aggregate product analytics | Legitimate interest |
| Newsletter, persistent analytics, opt-in file storage, CLI sync | Consent |
| Tax/accounting records | Legal obligation |
3. Who we share it with
Only service providers that run the Service (subprocessors), under data processing agreements:
| Provider | Role | Location |
|---|---|---|
| Vercel | Hosting | USA |
| Neon | Database (Postgres) | USA (us-east) |
| Resend | Email delivery | USA |
| PostHog | Product analytics | USA |
| Payment processor (hosted checkout) | Payments | USA |
We may also disclose information if legally required, or transfer it as part of a business sale — your rights under this policy would follow the data. We do not sell or share personal information for cross-context behavioral advertising.
4. Retention
| Data | Kept |
|---|---|
| Account + saved reports | Until you delete them or your account |
| Newsletter email | Until you unsubscribe |
| Analytics events | 12 months |
| Server logs | ≤ 30 days |
| Payment/tax records | As required by law (typically 7 years, held by the processor) |
Public share links you created are removed when you disable sharing or delete the report.
5. Security
TLS in transit, encrypted managed database at rest, API keys stored as salted hashes, passkey/2FA support, least-privilege access. No method is 100% secure; we will notify affected users of any breach as required by law.
6. Your rights — GDPR (EEA/UK)
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time — email hello@tokencheat.com and we will respond within 30 days. You may also complain to your local supervisory authority. Data is processed in the USA under Standard Contractual Clauses with the providers above.
7. Your rights — CCPA/CPRA (California)
You have the rights to know, delete, correct, and to non-discrimination for exercising them. We do not sell or share personal information as defined by the CCPA, so there is nothing to opt out of. Categories collected: identifiers (email, name, IP), commercial information (purchases), and internet activity (product usage events). Requests: hello@tokencheat.com.
8. Children
The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
9. Changes
We will post updates here and update the date above; material changes get email or prominent on-site notice.