tokenstat
tokenstat

Privacy

Privacy notice

Short version: tokenstat does not sell your data and does not fingerprint you. An account exists so you can sign in and sync counters. Cookies are only for staying signed in, keeping forms safe, and remembering light or dark. Here is the longer version.

What is collected

tokenstat does not use advertising cookies, marketing pixels, or browser fingerprinting. Sign-in and sync are the product; tracking people across the web is not.

Anonymous counters are kept on this server: how many people open a page, which links get clicked, how far down a page people read, what was typed into the on-site search box, and which paths return errors. These are counts and nothing else. There is no visitor ID, no profile of browsers, and no way to tell one person's visits apart from another's. Nothing is stored in your browser for this, so it does not call for a cookie consent banner. If your browser sends Do Not Track or Global Privacy Control, those client events are not recorded.

The web server also logs each request with an IP address, timestamp, and URL, the same as any web server, to diagnose errors and catch abuse. Those logs stay on the operator's server and are not sold.

Cloudflare

The site sits behind Cloudflare. Request traffic passes through their network for DNS, TLS, and DDoS protection. Cloudflare Web Analytics / RUM is also used for aggregate performance and traffic numbers (page load timing and visit counts). It sets no cookies, does not fingerprint you, and is not used to build a profile or to serve ads, so it likewise does not need a consent banner. Cloudflare's own privacy policy covers what they process as a processor for that hop.

Accounts and OAuth

If you sign in, the identifier your chosen provider supplies is stored (GitHub, Google, X, or Apple), along with a display name and the fact that a sign-in exists. No password is received or stored. An email address is stored only where a provider supplies one it has verified, and no email is sent. Two accounts are never merged because they share an address.

Signing in is OAuth with that provider. They see that you authorised tokenstat; only what is needed to recognise you next time is kept. Linking another provider only happens from your settings, from a session you already control.

Sessions record when they were created, when they expire, and when they were last used. They deliberately do not record an IP address or a browser fingerprint.

When you sync from the CLI, daily usage counters are stored: dates, token totals, model and harness ids, and opaque project hashes. Never a prompt, a file path, a repository name, or a readable project name.

You can download everything held about your account as a single JSON file, and delete the account, from settings. Deletion is immediate and permanent.

Cookies

An anonymous visit sets no session cookie. Cookies appear only when you sign in, or for the theme preference:

One keeps you signed in: a random value and nothing else, deleted when you sign out. Another is short-lived and protects the forms in your account from cross-site requests. Short-lived cookies also appear during OAuth (to finish sign-in) and to carry one-time secrets such as a fresh API token. A separate preference cookie records light or dark so pages arrive already in that theme; the same choice is kept in your browser's localStorage. It may be written from your system appearance setting before you touch the toggle.

Under GDPR and the ePrivacy rules these count as strictly necessary (sign-in, security, completing a flow you started) or as a first-party preference you asked the site to remember. None track you across sites, none are shared for advertising, and there are no analytics or marketing cookies of our own. That is why there is no cookie consent banner.

Payments

If you buy a paid tier, checkout is run by Paddle.com as Merchant of Record. Paddle processes the payment and related buyer details (card, invoice, tax). pueev OÜ does not receive or store your card number. We keep only what we need to apply your plan: that a subscription exists, which tier it is, and its status. During checkout Paddle may set its own cookies as part of running payment; those belong to Paddle, not to tokenstat. Paddle's own privacy policy covers what they process as Merchant of Record.

What is not done

No ad networks. No selling lists. No silent third-party scripts for marketing. No fingerprinting to recognise you without a cookie. The CLI on your machine does not phone home unless you run a sync or login command yourself.

Your rights

Under GDPR you have the right to access, correct, or delete personal data held about you. For an account, export and delete are on the settings page. For anything else, or any question, contact gyorgy@pueev.com.

Data controller

pueev OÜ

Narva mnt 5, 10117 Tallinn, Harju, Estonia

Registry code: 14469383  ·  VAT: EE102062975

← Back to homeTerms of use