Privacy
Placeholder · not yet drafted
01What we collect
Placeholder. Tokematic reads usage and spend signals from the AI subscriptions and API keys a person connects. It does not read prompts, completions or the content of anyone's work.
- Account details: name, email, team membership
- Spend and quota signals per connected subscription or key
- Basic product telemetry
02What we never collect
Placeholder, but this section should be explicit and prominent: Tokematic does not collect the substance of what people are doing with AI — no prompts, no responses, no files.
03What a team owner can see
Placeholder describing exactly what becomes visible to a manager when someone joins a team with a code, and what stays private to the individual. This should be written plainly enough that a team member can read it and understand it in under a minute.
04Why we process it
Placeholder for lawful bases and purposes: providing the service, billing, support, and aggregate product research.
05Aggregate and anonymised data
Placeholder covering the aggregate statistics published for research and marketing, and the steps taken so no individual or customer can be identified from them.
06Sharing
Placeholder for sub-processors, hosting, payments and any analytics providers.
07Retention
Placeholder for how long data is kept, what happens on cancellation, and export rights.
08Your rights
Placeholder for access, correction, deletion, portability and objection, plus how to exercise them.
09Contact
Placeholder for the data protection contact and complaint route.