tokenstat
tokenstat

Privacy

Privacy notice

Effective 10 September 2026.

tokenstat does not sell your data or use browser fingerprinting. An account supports usage sync and hosted services, including remote connections between approved devices. The sections below describe account data, connection metadata, storage, and retention.

What is collected

tokenstat does not use advertising cookies, marketing pixels, or browser fingerprinting. Sign-in and sync are the product. Tracking people across the web is not.

Anonymous counters are kept on this server: how many people open a page, which links get clicked, how far down a page people read, what was typed into the on-site search box, and which paths return errors. These are counts and nothing else. There is no visitor ID, no profile of browsers, and no way to tell one person's visits apart from another's. Nothing is stored in your browser for this, so it does not call for a cookie consent banner. If your browser sends Do Not Track or Global Privacy Control, those client events are not recorded.

The web server also logs each request with an IP address, timestamp, and URL, the same as any web server, to diagnose errors and catch abuse. Those logs stay on the operator's server and are not sold. Web and relay operational logs are kept only through the server's ordinary security-log rotation. They may be isolated for longer only when needed to investigate a specific security, fraud, or abuse event, and are deleted when that purpose ends.

Cloudflare

The site sits behind Cloudflare. Request traffic passes through their network for DNS, TLS, and DDoS protection. Cloudflare Web Analytics / RUM is also used for aggregate performance and traffic numbers (page load timing and visit counts). It sets no cookies, does not fingerprint you, and is not used to build a profile or to serve ads, so it likewise does not need a consent banner. pueev OÜ does not run that hop. What Cloudflare sees there (the request, the IP, timing) is held by them under their own privacy policy and terms.

Accounts and OAuth

If you sign in, the identifier your chosen provider supplies is stored (GitHub, Google, X, or Apple), along with a display name and the fact that a sign-in exists. No password is received or stored. An email address is stored only where a provider supplies one it has verified, and no email is sent. Two accounts are never merged because they share an address.

Signing in is OAuth with that provider. They see that you authorised tokenstat. That grant, and the account you already have with them, is held by them under their own policy: GitHub, Google, X, or Apple. Only what is needed to recognise you next time is kept here. Linking another provider only happens from your settings, from a session you already control.

For Sign in with Apple, an Apple refresh token is retained solely so tokenstat can revoke that authorization if you unlink Apple or delete the account. It is encrypted at rest and is not used to read Apple account data. Unlinking or deletion requests revocation from Apple before the local identity is removed. If Apple is temporarily unavailable, the encrypted credential is kept in a separate revocation queue and retried. It is deleted as soon as Apple accepts the request.

Sessions record when they were created, when they expire, and when they were last used. They deliberately do not record an IP address or a browser fingerprint.

When you sync from the CLI, the desktop app, or the mobile client, daily usage counters are stored: dates, token totals, model and harness ids, and opaque project hashes. Never a prompt, a file path, a repository name, or a readable project name. The device can also send the last plan-limit figures it already read from a vendor on that machine. Vendor credentials stay on the device.

Hosted profile data and synced usage history are kept while the account is active. For a Free account, if none of its linked devices has synced for more than 30 consecutive days, we may remove that hosted data. Paid tiers are not subject to this inactivity removal while the paid plan is active. The local archive on your device is not affected. Account deletion remains available from settings at any time.

A Legend account can mint a read-only API token in settings. Tokens are shown once and stored hashed. They can only read the counters the account already holds. They cannot sync, and they cannot read another account.

You can download a JSON export of your profile, linked sign-in identities, sessions, synced usage counters, and encrypted SSH vault from settings. Contact us for access to other account records, including billing or relay-usage metadata. You can also delete the account from settings. Deletion is immediate and permanent once confirmed. If an App Store subscription is active, the deletion screen warns that deleting tokenstat does not cancel it and asks you to acknowledge the risk of continuing Apple charges. You may still delete immediately. Use Apple ID subscriptions separately to stop renewal.

Remote management

On Patron and Legend, a phone or another computer you have signed in on can reach a machine you already control. Remote screen viewing and control is a Legend feature. The two devices authenticate each other and establish an end-to-end encrypted session. The app tries a direct connection first. A direct session does not carry its contents or relay-usage metadata through tokenstat. When network conditions prevent a direct connection, tunnel.tokenstat.ai forwards the already-encrypted bytes. The relay has no session key and cannot decrypt terminal contents, screen images, file contents, or keystrokes.

What is stored for remote is the fact of it: that a machine is registered, the public key used as its routing address, whether it is online, and when it last connected. Short-lived tunnel tokens are stored hashed, the same way API tokens are. When the relay is used, daily totals record the channel purpose from a fixed list (such as screen, SSH, or SFTP), the host machine being reached, encrypted bytes carried, connection seconds, and session count. Those totals enforce plan limits, protect the service from abuse, and measure capacity. Operational logs can also contain connection times, account and shortened machine identifiers, channel events, byte counts, and refusal reasons. They do not contain the session payload or a decryption key. Relay usage totals remain attached to the account until the account is deleted. Deleting the account deletes those totals with it.

SSH vault sync is end-to-end encrypted. It is encrypted on your device before upload and decrypted only on a signed-in device after local unlock. The server stores an opaque encrypted snapshot, revision metadata, password and recovery salts, and opaque encrypted key wraps. A device that you unlock is enrolled automatically by adding a key wrap for that device. It never receives SSH passwords, private keys, snippets, the vault master key, vault password, or recovery code. The password and recovery code are processed locally. If they and every device able to open the vault are lost, neither tokenstat nor pueev can reset or recover the vault. You can still retrieve or export an existing encrypted vault after a plan downgrade.

Notifications

If you enable notifications in the mobile app, tokenstat stores the APNs device token Apple assigns, the platform and Apple environment, an optional tokenstat machine id, and creation and last-seen times. The token is used only to ask Apple Push Notification service to deliver account notifications to that device. Turning notifications off or signing out unregisters it. A token not seen for 180 days is deleted automatically, and account deletion deletes it immediately.

Notification text is composed from a fixed list of events and may include the machine label you chose. It does not include prompts, responses, file paths, folder names, commands, or remote-session contents. Apple processes delivery under its privacy policy.

Cookies

An anonymous visit sets no session cookie. Cookies appear only when you sign in, or for a preference the page needs before it paints:

One keeps you signed in: a random value and nothing else, deleted when you sign out. Another is short-lived and protects the forms in your account from cross-site requests. Short-lived cookies also appear during OAuth (to finish sign-in) and to carry one-time secrets such as a fresh API token. A preference cookie records light or dark so pages arrive already in that theme. The same choice is kept in your browser's localStorage. It may be written from your system appearance setting before you touch the toggle. Another holds the IANA name of your timezone (for example Europe/Budapest, never a city and never coordinates) so the signed-in greeting is the same words on first paint as after the page becomes interactive.

Under GDPR and the ePrivacy rules these count as strictly necessary (sign-in, security, completing a flow you started) or as a first-party preference you asked the site to remember. None track you across sites, none are shared for advertising, and there are no analytics or marketing cookies of our own. That is why there is no cookie consent banner.

Payments

If you buy a paid tier on the website or in the desktop app, checkout is run by Paddle.com as Merchant of Record. Paddle processes the payment and related buyer details (card, invoice, tax). pueev OÜ does not receive or store your card number. We keep only what we need to apply your plan: that a subscription exists, which tier it is, and its status. During checkout Paddle may set its own cookies as part of running payment. Those belong to Paddle, not to tokenstat. What they hold is under Paddle's privacy policy and buyer terms. After account deletion, tokenstat may retain Paddle's event identifier, event type, and receipt time solely to reject a duplicate webhook. The tokenstat user identifier is removed from that record. Paddle retains its own transaction and tax records independently under its policy.

If you buy a paid tier in the iOS app, Apple is the seller. Apple handles the payment, tax, and refunds under Apple's terms. We never see your Apple ID password or card number. We receive a signed App Store receipt so we can apply the same plan on this account: the product you bought, Apple's subscription identifier, when it renews or ends, and a derived account token that ties the purchase to the signed-in tokenstat user. That token is not your Apple ID. Apple's own collection is under Apple's privacy policy.

Where you install from

You can get the CLI and the apps from this site, from GitHub, or from an app store when the app is listed there (Mac App Store, App Store, Google Play). A download from GitHub or from a store is handled by that host. They see the request under their own policy: GitHub, Apple, Google. We do not receive your GitHub account or your Apple or Google store account from those downloads. The apps themselves are free. Paid plans are sold on this site through Paddle, and in the iOS app through the App Store, as above.

What is not done

No ad networks. No selling lists. No silent third-party scripts for marketing. No fingerprinting to recognise you without a cookie. The software on your device sends nothing for tracking. Local usage collection does not upload conversation text. Network features include release checks and updates, price and catalog refreshes, vendor usage or plan-limit connections, account services, and pages you open. Setup enables scheduled updates by default. Agents and workflow steps may connect to their configured providers or services. Linked devices can sync counters and, when enabled, share plan-limit readings. Remote management, when you turn it on, tries an end-to-end encrypted direct connection first. If that cannot connect, the relay receives encrypted session bytes and the limited routing and usage metadata described above. Vault sync sends only ciphertext and opaque device key wraps.

Your rights

Under GDPR you have the right to access, correct, or delete personal data held about you. Account export and deletion are on the settings page. The self-service export is not the limit of your right of access. For other records or any question, contact gyorgy@pueev.com.

Data controller

pueev OÜ

Narva mnt 5, 10117 Tallinn, Harju, Estonia

Registry code: 14469383  ·  VAT: EE102062975

← Back to homeTerms of use