Privacy Policy

Last updated: July 3, 2026

TokenCheat ("we," "us") operates tokencheat.com (the "Site") and the TokenCheat tools and services (the "Service"). This policy explains what we collect, why, who touches it, and your rights.

Plain-English summary: The free tools run in your browser — pasted configs never reach our servers. If you make an account we store your email and your saved audit results (your file content only if you opt in). The CLI sends us nothing unless you run sync, and never your source code. Analytics are cookieless until you accept the banner. We don't sell data, run ads, or profile you. Email us and we'll delete everything.

1. What we collect

Information you give us

DataWhenWhy
Email + nameAccount signup, newsletterSign-in, transactional email, the newsletter you asked for
Passkey / 2FA credentialsIf you enable themAccount security (public-key material only)
Saved audit inputs, scores, fix summariesWhen you save an auditSo your reports exist
Instruction-file contentOnly if you tick "include my optimized file"So a saved/shared report can show the before/after file
MessagesContact formTo respond
Payment detailsNever by usPayments run on a third-party hosted checkout; we never see card numbers

Browser tools: content pasted into the free calculators and audit runs entirely client-side and is not transmitted to our servers.

Information collected automatically

  • Essential cookies for sessions and sign-in (always on; they're how login works).
  • Analytics (PostHog, US cloud): page views and product events (e.g. "audit completed" with the score). Cookieless by default — until you accept the consent banner, analytics persist only in memory and set no cookies or local storage. Accepting the banner enables persistent analytics storage. No advertising, no cross-site tracking.
  • Server logs (IP address, user agent) held briefly for security and debugging.

CLI telemetry (opt-in only)

The CLI analyzes files on your machine locally. Nothing is transmitted unless you run its sync command with your workspace API key — and then only summary telemetry: token counts, scores, model identifiers, and workspace/ member attribution. Never your source code or file contents.

2. How we use it

Providing the Service; authenticating you; storing and displaying the reports you save; sending transactional email and the newsletter you signed up for; improving the product from aggregate usage; security and fraud prevention; legal compliance. We do not sell personal information, serve third-party advertising, or build advertising profiles.

Published research (like our config-corpus reports) uses aggregate statistics only; local/customer files included in any corpus are anonymized.

Legal bases (GDPR)

PurposeBasis
Accounts, saved reports, paid auditsContract
Transactional email, security, aggregate product analyticsLegitimate interest
Newsletter, persistent analytics, opt-in file storage, CLI syncConsent
Tax/accounting recordsLegal obligation

3. Who we share it with

Only service providers that run the Service (subprocessors), under data processing agreements:

ProviderRoleLocation
VercelHostingUSA
NeonDatabase (Postgres)USA (us-east)
ResendEmail deliveryUSA
PostHogProduct analyticsUSA
Payment processor (hosted checkout)PaymentsUSA

We may also disclose information if legally required, or transfer it as part of a business sale — your rights under this policy would follow the data. We do not sell or share personal information for cross-context behavioral advertising.

4. Retention

DataKept
Account + saved reportsUntil you delete them or your account
Newsletter emailUntil you unsubscribe
Analytics events12 months
Server logs≤ 30 days
Payment/tax recordsAs required by law (typically 7 years, held by the processor)

Public share links you created are removed when you disable sharing or delete the report.

5. Security

TLS in transit, encrypted managed database at rest, API keys stored as salted hashes, passkey/2FA support, least-privilege access. No method is 100% secure; we will notify affected users of any breach as required by law.

6. Your rights — GDPR (EEA/UK)

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time — email hello@tokencheat.com and we will respond within 30 days. You may also complain to your local supervisory authority. Data is processed in the USA under Standard Contractual Clauses with the providers above.

7. Your rights — CCPA/CPRA (California)

You have the rights to know, delete, correct, and to non-discrimination for exercising them. We do not sell or share personal information as defined by the CCPA, so there is nothing to opt out of. Categories collected: identifiers (email, name, IP), commercial information (purchases), and internet activity (product usage events). Requests: hello@tokencheat.com.

8. Children

The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

9. Changes

We will post updates here and update the date above; material changes get email or prominent on-site notice.

10. Contact

hello@tokencheat.com · tokencheat.com/contact