Skip to content

Privacy Policy

Last updated:

Table of contents
  1. Information We Collect
  2. How We Use Information
  3. Visibility and Sharing
  4. Cookies and Local Storage
  5. Data Retention
  6. Security
  7. Your Rights and Choices
  8. International Processing
  9. Children's Privacy
  10. Updates to This Policy
  11. Contact Us

This Privacy Policy explains how Tokitoki collects, uses, stores, and shares information about you. Tokitoki is operated by an independent developer and is built for developers who want to track AI coding time, token usage, and project activity.

If you do not agree with this policy, please do not use Tokitoki. You can contact us at [email protected] for privacy-related requests.

Information We Collect

Account Information

When you sign up or sign in, we may collect your email address, display name, avatar, password hash, email verification status, sign-in sessions, and account creation time. If you sign in with Google, GitHub, LINE, or X, we receive the account identifier and display name provided by that platform; where you authorize it and the platform supports it, we may also receive a platform-verified email address. This information is used only for sign-in, account creation, and account linking.

Usage Data

When you upload records through a desktop client, plugin, or API key, we collect data about your AI coding sessions, including tool name, model, session time, project name, hashed project path, language, operating system, client version, token counts, cost estimates, and a device installation identifier.

Tokitoki is designed to measure coding activity, not to read your source code. By default, we do not ask clients to upload file contents, code, or the text of AI conversations. Project paths are stored as hashes; however, project names, languages, models, and usage statistics may appear in your dashboard.

Device, Log, and Region Information

For security, troubleshooting, and service operation, we may process request timestamps, request status, browser or client information, essential cookies, API key usage records, and error logs. When events are uploaded, we may resolve a country or region code from the request IP, but we do not store raw IP addresses as a user-profile field.

Payment Information

If you purchase paid features, payments are processed by third-party payment services such as Stripe. We do not store full card numbers. We may store subscription status, order numbers, payment times, plan, and billing email for activating the service and handling support requests.

How We Use Information

We use information for the following purposes:

  • Creating, signing in to, and protecting your account.
  • Receiving, deduplicating, aggregating, and displaying your coding time, token usage, project activity, and leaderboard data.
  • Providing data sync, usage analytics, badges, leaderboards, and paid-feature support.
  • Sending essential service emails, such as email verification, password resets, billing notices, and important service changes.
  • Preventing abuse, investigating anomalous requests, and maintaining service security and stability.
  • Improving the product and diagnosing issues, preferring aggregated or de-identified data.
  • Meeting legal, tax, accounting, or compliance obligations.

Visibility and Sharing

By default, your personal dashboard and project data are not public. Information may become public or be shared in these situations:

  • You enable public leaderboards, a public profile, public project badges, or share links.
  • We use necessary service providers for hosting, databases, email delivery, sign-in identity, payments, logging, and analytics.
  • To comply with legal process, protect the safety of Tokitoki, its users, or the public, or address fraud and abuse.
  • If the service is involved in a merger, acquisition, asset transfer, or similar transaction, information may be transferred as part of that transaction and remain subject to this policy or an equivalent one.

We do not sell your personal information. We do not use your source code, file contents, or AI conversation text to train models.

Cookies and Local Storage

Tokitoki uses essential cookies to keep you signed in, protect sessions, and remember interface preferences. Essential cookies are required for the service to operate. If we add non-essential analytics or advertising cookies in the future, we will provide additional notice or choices as required by applicable law.

Data Retention

We keep your information for as long as needed to provide the service. Account, project, and usage records are generally retained until you delete your account or request deletion; some backup, billing, audit, and security records may be kept for a reasonable period afterward to meet legal, financial, security, or dispute-handling needs.

You can delete some data through in-product features, or email [email protected] to request access, correction, export, or deletion of account data. We will handle requests within a reasonable time and may need to verify your identity first.

Security

We use reasonable technical and organizational measures to protect information, including password hashing, restricted access, secure session-cookie settings, API key authentication, and data minimization. No internet service can guarantee absolute security. Keep your password and API keys safe; if you believe your account or a key has been compromised, reset it as soon as possible and contact us.

Your Rights and Choices

Depending on the laws that apply where you live, you may have the right to access, correct, delete, export, restrict, or object to the processing of your personal information, and the right to withdraw consent or lodge a complaint with a supervisory authority. We handle these requests in accordance with applicable law.

You can also:

  • Turn off public leaderboards or public badges.
  • Delete API keys or stop client uploads.
  • Unsubscribe from emails; essential service emails may still be sent.
  • Delete your account or ask us to delete data associated with it.

International Processing

Tokitoki serves developers worldwide. Your information may be processed and stored outside your country or region. We take reasonable measures to protect it in accordance with applicable law.

Children's Privacy

Tokitoki is not directed at children under 13, or under any higher minimum age required by the law where you live. If you believe a child has provided us personal information, contact us and we will delete it.

Updates to This Policy

We may update this policy from time to time. Material changes will be announced via the website, in-product notices, or email. Continuing to use Tokitoki means you accept the updated policy.

Contact Us

For privacy questions, requests, or complaints, email [email protected].