Privacy policy
What we collect, what we never collect, and how to make us delete it.
Last updated:
Who we are
TokenPolice is a spend firewall for apps that call large language models. It is operated by its founder as an individual, not a company. We run tokenpolice.ai, the dashboard at app.tokenpolice.ai and the API behind them. Write to hello@tokenpolice.ai about anything here — a person answers.
Signing in with Google
If you sign in with Google, we receive your name, email address, profile picture and Google account ID. We use them only to sign you in to your TokenPolice account. Clerk, our sign-in provider, holds them for us, and they are deleted when your account is. We never share or sell them, and never use them for advertising or to train models.
What the SDK sends
The SDK runs inside your application and sends metadata about each LLM call: model and provider, token counts, the cost we compute, the identifiers you attach, and a content fingerprint — a one-way hash, never text — that loop detection compares. Raw prompt and completion text never leaves your servers. Neither do your provider API keys. Field-by-field list in the data and privacy docs.
Our coding-agent skill reports integration progress to our API — your app’s name, the packages it found, its own notes. Never code, secrets or prompts.
This website
We use PostHog to count page views and clicks here and in the dashboard; it sets an ID cookie on tokenpolice.ai so one visit across both counts once. Those requests go to our own subdomain, edge.tokenpolice.ai, and pass through Cloudflare, a PostHog subprocessor, on their way to PostHog. No ads, no session replay, no tracking across other sites. If your browser sends Global Privacy Control, PostHog is not loaded at all. Cloudflare Web Analytics stores nothing on your device.
Who else sees it, and for how long
Clerk, Amazon Web Services, Cloudflare, PostHog, Sentry and Resend process data on our instructions and for nothing else. Our servers are in the United States. Call telemetry is deleted automatically one year after the call — a database rule, not a chore. Account data stays until you close your account, and is gone within 30 days of your asking.
Your rights
Email hello@tokenpolice.ai to see, correct, export or delete what we hold. It is free, we answer within 30 days, and you can complain to your data protection authority. We do not sell personal information, share it for advertising, or train models on your data.
The rest
Everything moves over TLS, and API keys are stored as hashes we cannot reverse. TokenPolice is not for anyone under 16. When this policy changes we update the date above, and email account holders if it is material. See also our terms of service.

