Privacy Policy
Last updated: 18 August 2026
tokencheat ("tokencheat", "we", "us") is the service operated at tokencheat.com. This policy explains what we collect, why, and what you can do about it.
We have written it to describe what our software actually does, not what a template assumes it does. Where a practice does not apply to us, we say so rather than reserving the right to it.
Contact: privacy@tokencheat.com
1. The short version
- The free tools on tokencheat.com run entirely in your browser. Text you paste into the token calculator, cost calculators, instruction-file auditors, context scorers, and estimators is processed locally by JavaScript. It is not transmitted to us, not logged, and not stored. We never receive it.
- We do not run advertising or third-party analytics on the marketing site. No Google Analytics, no Meta pixel, no session recording, no fingerprinting.
- We do not sell or share personal information, and we do not process it for cross-context behavioural advertising.
- Accounts, billing, and saved work exist only in the authenticated application. If you have not created an account, we hold essentially nothing about you.
2. What we collect
2.1 Public site visitors (no account)
| Data | Why | Retention |
| :------------------------------------------------------------------------------------------------------ | :----------------------------------------------------------------- | :------------------------------------------------------- |
| A NEXT_LOCALE cookie recording your language choice | So the site renders in the language you picked | Until you clear it |
| Standard server request logs generated by our hosting provider (IP address, user agent, timestamp, URL) | Delivering the site, security, abuse prevention, diagnosing faults | Per our hosting provider's retention, typically ~30 days |
NEXT_LOCALE is strictly functional. We set no advertising, targeting, or analytics cookies on
the marketing site, which is why you are not asked to consent to any.
Content you paste into a tool is not in this table because we do not receive it. You can verify this: open your browser's network inspector and use any calculator. No request is made.
2.2 Account holders
If you register for the application, we process:
- Identity and account data — name, email address, profile image, email-verification status, locale, role, and account status.
- Authentication data — session records (including IP address and user agent), OAuth identifiers where you sign in with Google or GitHub, passkey credentials, and two-factor settings. We never receive your Google or GitHub password.
- Organisation and membership data — teams you belong to, your role, and invitations.
- Content you submit — instruction files, configuration, repository context, audit inputs and results, generated packs, and related work product you deliberately save.
- Billing data — subscription and purchase records, and a payment-processor customer identifier. We never receive or store your full card number; card data goes directly to our payment processor.
- Support correspondence — what you send us when you contact us.
2.3 What we do not collect
We do not knowingly collect special-category data (health, biometrics, precise geolocation, racial or ethnic origin, religious belief, sexual orientation, trade-union membership), and you should not submit it. We do not use automated decision-making that produces legal or similarly significant effects.
3. Why we process it
We use the data above to deliver the website and tools, create and secure accounts, store work you choose to save, process payments and prevent fraud, send service and security email, send marketing email only where you opted in (unsubscribe any time), and meet tax, accounting, and legal obligations. We do not use your data for anything else.
4. Service providers
We use the following processors. Each is bound by contract to process personal data only on our instructions.
| Provider | Role | Location | | :------------------------- | :-------------------------------------------------------------------- | :------------------ | | Vercel Inc. | Application hosting, CDN, request logs | USA | | Neon Inc. | PostgreSQL database | USA (AWS us-east-2) | | Stripe, Inc. | Payment processing and subscription billing | USA | | Mailgun Technologies, Inc. | Transactional and notification email | USA | | Google LLC / GitHub, Inc. | OAuth sign-in, only if you choose it | USA | | OpenAI, L.L.C. | Powers optional AI features inside the authenticated application only | USA | | Vercel Inc. | Hosting, and anonymous cookieless pageview analytics | USA |
OpenAI processing applies solely to authenticated users who invoke an AI feature. Nothing you type into a public marketing tool is sent to OpenAI or any other model provider. The tools run entirely in your browser and send nothing you type anywhere — not to us, and not to a third party.
The site records anonymous pageviews through Vercel Web Analytics: a route, a referrer, a country, a device type. It is first-party and cookieless, it sets no identifier that follows you between sites, and it never receives the contents of anything you paste into a tool.
We do not sell personal information, and we have not sold or shared it for cross-context behavioural advertising in the preceding twelve months.
5. Retention
- Account and content data: for the life of your account, then deleted or irreversibly anonymised within 90 days of closure, unless we must keep it longer.
- Billing and tax records: 7 years, as required by US tax law.
- Session records: expire automatically and are purged on expiry.
- Marketing subscriptions: until you unsubscribe, plus a suppression record so we do not email you again.
- Server logs: per our hosting provider's retention schedule, typically ~30 days.
6. Your rights
If you are a California resident, you have the right to know, delete, correct, and opt out of sale or sharing, and not to be discriminated against for exercising those rights. We do not sell or share personal information, so there is no opt-out to exercise. We do not use or disclose sensitive personal information beyond the purposes permitted by CPRA §7027(m).
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have comparable rights.
To exercise any right, email privacy@tokencheat.com. We respond within 30 days (45 days for California requests, extendable once where permitted). We will ask you to verify your identity, usually by confirming control of the account email. Authorised agents may act for you with written permission.
7. Security
We use TLS in transit and encryption at rest, scoped database access, hashed credentials, optional two-factor authentication and passkeys, and row-level access controls. API keys are stored as peppered HMAC hashes rather than recoverable values.
No system is perfectly secure. We do not claim ours is. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant regulator as required by law.
8. Children
The service is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, email privacy@tokencheat.com and we will delete it.
9. Changes
We will post any revised policy here with a new "last updated" date. For material changes that reduce your rights or expand our processing, we will give notice by email or an in-product notice before the change takes effect.
10. Language
This English version is authoritative. Translations are provided for convenience; if they conflict, the English text controls.