TokenMeter

Privacy Policy

Version 2026-08-31-en · effective 2026-08-31

What we process

TokenMeter processes usage metadata: the account, device, team, tool and model behind a request, the token counts, the timestamps, the cost, and the verification status. It never processes the content of prompts or responses. That is an architectural constraint of the product, not a configuration option.

Whose data it is

The workspace is the controller of its members' usage data; we process it on the workspace's instructions. A workspace records the legal ground on which it processes its own people's data — we do not choose that ground for it.

Where it lives

The hosted service runs on infrastructure we operate in Seoul (ap-northeast-2). Each workspace's rows are isolated from every other workspace at the database level, enforced by the database rather than by application code. Optional on-device analysis runs on the device itself.

Devices

Collection from a person's device begins only after that device is enrolled and consent is recorded, and stops when consent is withdrawn. What a device sends is usage metadata on the same boundary as everything else.

Your rights

You can ask for access, erasure, portability or correction of your personal data, and the product implements all four. Erasure removes or pseudonymizes the data that identifies you while keeping the financial record the workspace needs — your identity is severed from it, and figures that would otherwise misstate what an organization spent are preserved. Ask your workspace administrator to raise the request.

Retention

Usage data lives as long as the workspace does. Closing a workspace erases the data we hold for it.

Contact

Write to us at the address on our site, or ask your workspace administrator, who can reach us on your behalf.