tokenstat
tokenstat

Terms

Terms of use

Effective 18 September 2026.

Short version: the CLI and the apps are free to use. An account on this site is optional, private by default, and exists so you can sync counters and, if you want, publish a profile. Paid plans are sold here through Paddle, on iOS through the App Store, and on Android through Google Play. Patron includes a three-day trial. Cancel auto-renewal during it and nothing is charged. After a charge, purchases are final. The sections below contain the full terms.

Operator

tokenstat is operated by pueev OÜ (Narva mnt 5, 10117 Tallinn, Estonia). Questions: gyorgy@pueev.com.

The software

The tokenstat CLI, desktop apps, and mobile clients are licensed, not sold, to you, regardless of how you obtain them. Official builds are free to use for any purpose and on as many machines as you like under the tokenstat Source-Available Licence. These service terms do not replace that software licence or the separate licence supplied by an app store.

The source code for everything that runs on your device is published so you can review exactly what it does with your data. The software runs on your device and does not need an account. It makes a network connection only when you request or enable a network feature, for example sign-in, sync, update checks, push registration, vault sync, or direct and relayed remote access.

Where you get the software

You can install the CLI and the apps from this site, from our GitHub releases, and, when the app is listed there, from the Mac App Store, the App Store, and Google Play. Each distribution platform has its own terms. A free download is not a purchase. GitHub is where the source and the release files live. It is not a payment processor.

Paid plans on this site and in the desktop app are sold through Paddle, on the iOS app through the App Store, and on the Android app through Google Play. A download, from any store or from GitHub, is not a purchase. The trial is the evaluation period. After a charge, purchases are final under the refund policy below.

The iOS and iPadOS apps are additionally licensed under Apple's Standard Licensed Application End User License Agreement. That agreement governs the Apple-distributed app itself. These terms continue to govern the tokenstat account, hosted services, remote relay, and paid plan. If the two conflict about the licensed app, Apple's standard agreement controls for that app.

Accounts and profiles

Signing in creates an account so you can sync usage counters and, if you choose, publish a public profile at tokenstat.ai/your-handle. An account is private until you claim a handle and turn the profile on. You are responsible for what you put on a public page: display name, bio, avatar, and outbound links.

Your data is not sold. See the privacy notice for what is stored.

Signing in

Sign-in is handled by a third-party provider: GitHub, Google, X, or Apple. There is no password to create here, because none is received or stored. You authorise tokenstat with the provider you pick, and they tell us only enough to recognise you next time. The account you already have with them stays under their own terms and privacy policy: GitHub terms / privacy, Google terms / privacy, X terms / privacy, Apple terms / privacy.

More than one provider can be linked to the same account, always from settings and from a session you already control. The last one cannot be unlinked, since that would leave the account with no way back in. If a provider you used stops being offered, or you lose access to it, link another one first.

Moderation

A public profile is a page on a domain we operate, so we keep the right to act on what appears there. Content that is abusive, illegal, spam, impersonates someone else, or is otherwise inappropriate may be edited or removed, and the account behind it restricted or suspended. That covers the display name, the handle, the bio, the picture, and outbound links.

It also covers the numbers. Usage counters are meant to reflect what a device did. Deliberately submitting fabricated or inflated figures, including by forging a sync payload, is grounds for resetting the profile or suspending the account, and any leaderboard or aggregate standing derived from it will be removed.

Where it is reasonable, you get notice and a chance to fix it first. Where the content is clearly illegal or is actively harming someone, action comes first. Suspension does not delete your data: export and hard delete stay available from settings. To report a profile, write to tokenstat-abuse@pueev.com.

Paid tiers

Supporter, Patron, and Legend are optional plans for the hosted profile, extra devices, remote management, and, on Legend, the read API. Prices and what each tier includes are on the pricing page (/pricing). A published price change applies at the next renewal for everyone on that plan. The year already paid is not re-billed. Paying never unlocks anything in the CLI. The desktop app, the mobile client, and every local source, report, and export stay in the free tier. Paid tiers change the hosted profile, remote reach, and, on Legend, the hosted read API.

Remote management (Patron and Legend) lets a signed-in phone or computer reach one of your machines. Remote screen viewing and control is a Legend feature. Each connection is end-to-end encrypted and authenticated between those two devices. tokenstat tries a direct connection first. When network conditions do not permit one, the hosted relay forwards ciphertext and cannot read the terminal, screen, files, or keystrokes. You are responsible for who can unlock the devices that hold those keys.

Relay access is for ordinary use of your own machines and is subject to reasonable technical and usage limits so one account cannot exhaust a shared service. Direct connections do not use the hosted relay allowance. tokenstat tries a direct path first. When a relay is needed, all relayed traffic shares one rolling 30-day allowance of 100 MiB on Free, 1 GiB on Supporter, 5 GiB on Patron, and 20 GiB on Legend. The window is the current UTC day plus the previous 29 UTC days. Capacity returns as older daily totals leave that window. This is not a daily refill and not a calendar-month reset. Remote screen viewing and control remains a Legend feature, with one relayed screen session per account at a time. A relayed screen session may run for up to ten minutes before reconnecting and may be closed sooner if the viewer disconnects or stops sending its presence signal. The published limits are generous abuse protection, not a promise of unlimited relay capacity. Any material reduction will be published before it applies to a new paid period.

SSH vault sync is available on Supporter, Patron, and Legend. The vault is end-to-end encrypted: encryption, password unlock, and recovery happen on your devices, and the service stores ciphertext, salts, and encrypted key material, not usable SSH credentials. Unlocking on a signed-in device enrolls it automatically. There is no operator reset if every device able to open the vault and the vault password and recovery code are lost.

The read API is a Legend feature. It returns the counters you have already synced, as JSON or CSV. It cannot write, and it cannot reach another account. The endpoints are listed on the API page (/api).

Web and desktop checkout is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for those orders. Paddle handles checkout, invoices, tax, card data, and payment support. See Paddle's buyer terms and Paddle's privacy policy. Paddle's buyer terms govern that transaction. Paddle does not grant the tokenstat software licence. A paid plan buys time-limited access to the hosted features described here, not ownership of the software. iOS checkout is sold by Apple as an in-app subscription. Apple handles that payment, tax, and the App Store refund process. Android checkout is sold by Google as a Google Play subscription. Google handles that payment, tax, and the Play refund process.

A first Patron yearly checkout includes a three-day trial, once per account. That covers all three stores: Paddle, the App Store, and Google Play. If you have already used the trial on this account, a later checkout is billed from day one. Cancel auto-renewal before the trial ends and you are not charged. After a charge, the purchase is final.

Plans renew on the schedule you picked, monthly or yearly, until cancelled. Cancel a Paddle plan from the receipt they send, from account settings, or by writing to gyorgy@pueev.com or to Paddle support. Cancel an App Store plan from your Apple ID subscriptions, and a Google Play plan from your Google Play subscriptions. Cancelling stops the next charge. Access for the period already paid stays until it ends.

Refunds

The three-day trial is the evaluation period. Cancel auto-renewal from account settings, your Paddle receipt, or Paddle support before the three-day trial ends and nothing is charged. After a charge, purchases are final. We do not offer refunds for unused time, a change of mind, cancellation, or moving to a lower plan. A downgrade, a cancel, or a switch from yearly to monthly takes effect at the next renewal. You keep the plan you already paid for until that date. Switching from monthly to yearly on the website starts a new year now, with unused monthly time credited. Rights that cannot legally be waived still apply.

We do not offer refunds after a charge. Paddle is the Merchant of Record for web and desktop purchases, Apple is the seller for App Store purchases, and Google is the seller for Google Play purchases. If a store must process a refund under a rule that cannot legally be waived, use that store's process. A refund, where one is legally required and issued, ends the paid plan. Synced data and the account stay unless you delete them. Nothing here limits rights you have that cannot be waived under Estonian or EU law.

If a Paddle charge looks wrong, write to gyorgy@pueev.com or contact Paddle through the receipt or at paddle.net. If an App Store charge looks wrong, use Apple's report-a-problem page. If a Google Play charge looks wrong, use Google Play's request-a-refund page.

What you agree not to do

  • Scrape or overload the service or other people's profiles.
  • Publish illegal content, malware links, or harassment on a profile.
  • Impersonate another person or claim a handle to mislead users.
  • Submit fabricated or inflated usage figures, or forge a sync payload.
  • Attempt to gain unauthorized access to accounts, devices, or the sync API.
  • Use remote reach to access a machine you do not own or control.
  • Resell, share, automate, or use the relay as general-purpose bandwidth, hosting, proxy, VPN, or infrastructure.

Availability

tokenstat is a small product, not a guaranteed SLA. Reasonable effort is made to keep it available, but uninterrupted access is not promised. The public site is delivered through Cloudflare. That hop is theirs: see their terms and privacy policy. Sync data can be exported and deleted from settings. The local archive on your device is never on this server.

Hosted data retention

We keep hosted profile data and synced usage history while the account is active. For a Free account, if none of its linked devices has synced for more than 30 consecutive days, we may remove the hosted profile data and synced history associated with it. Paid tiers are not subject to this inactivity removal while the paid plan is active. Your local archive remains on your device and is not affected. Sync at least once every 30 days if you want to keep the hosted copy of a Free account.

Liability

The service is provided as-is. To the extent the law allows, pueev OÜ is not liable for indirect or consequential loss from using the site, the CLI, the desktop app, or the mobile apps. Nothing here limits rights you have that cannot be waived under Estonian or EU law.

Changes

These terms may be updated. The page here is the current version. A published price change applies at the next renewal.

← Back to homePrivacy notice