Privacy Policy
Last updated: 28 August 2026
Token Curb helps organizations understand and control what they spend on AI services. This policy explains what information we collect, why we collect it, and what we do not collect.
1. Who we are
Token Curb ("Token Curb", "we", "us") operates the Token Curb AI spend management platform. For questions about this policy or your data, contact hello@tokencurb.com.
Where you use Token Curb as a customer organization, you are the controller of the data in your workspace and Token Curb acts as your processor, handling that data on your instructions and under our agreement with you.
2. Information we collect
Account and workspace information
- The email address you authenticate with, supplied by our identity provider at sign-in
- Your organization name, role, and membership status within a workspace
- Workspace configuration such as monthly budget, alert thresholds, data region, and retention settings
Provider credentials
To import your usage data, Token Curb stores the reporting-scope administrative API key you supply for each AI provider. These keys are encrypted with AES-256-GCM before storage, using an encryption key held in a managed cloud secret vault. A stored credential is cryptographically bound to the single organization and single provider it was created for, and is never displayed, exported, or returned by any interface after you enter it.
Usage and cost data imported from your AI providers
- Token counts (input, cached, and output), request counts, and model names
- Project or workspace identifiers as reported by the provider
- Billed cost amounts and line items, and the time periods they apply to
Operational records
- Audit events recording administrative actions, with actor email, action, target, and timestamp
- A one-way hash of the originating IP address on certain audit records
- Synchronization history: when an import ran, whether it succeeded, and how many records it wrote
- Rate-limiting counters used to protect the service from abuse
Information you send us directly
If you submit a pilot request or contact us, we collect the name, email address, and phone number you provide, together with any message content, so we can respond.
3. What we do not collect
- Prompt and response content. The text you send to AI models, and the text they return, is never requested or stored by Token Curb. The provider reporting interfaces we use do not expose it.
- Passwords. Authentication is handled by our identity provider; Token Curb never receives a password.
- Payment card details. Any future payment processing will be handled by a payment processor; card numbers will not be stored by Token Curb.
4. Why we use your information
| Purpose | Information used |
|---|---|
| Show your AI spend, usage, forecasts, and savings recommendations | Imported usage and cost data |
| Import data from your AI providers on a schedule | Encrypted provider credentials |
| Send budget alerts you have configured | Administrator email addresses, spend totals |
| Authenticate you and enforce roles and tenant isolation | Account email, organization membership |
| Maintain security, investigate incidents, and prevent abuse | Audit events, hashed IP addresses, rate-limit counters |
| Respond to your enquiries | Contact details you submit |
5. Service providers
Token Curb relies on a small number of providers to operate the service. Each processes data only as needed to provide their service to us.
| Provider | Role |
|---|---|
| Cloudflare, Inc. | Application hosting, database storage, authentication gateway, and secret storage |
| HighLevel Inc. (GoHighLevel) | Delivery of alert and notification emails, and management of enquiries you submit to us |
Your AI providers — such as OpenAI and Anthropic — are the sources of the usage data you ask Token Curb to import. They act as your own providers under your agreement with them, not as our subprocessors.
We do not sell personal information, and we do not share it with third parties for their own advertising purposes.
6. Where data is held
Token Curb runs on Cloudflare's global infrastructure. Data is stored in the region associated with your workspace configuration. If a specific data residency requirement applies to your organization, raise it with us before onboarding so we can confirm whether we can meet it.
7. How long we keep data
Imported usage and cost data is retained according to your organization's retention setting, which defaults to 365 days. Audit records are retained to support security investigations and compliance obligations. If your organization stops using Token Curb, we will delete or return your workspace data on request, subject to any legal retention requirements.
You can request export or deletion of your workspace data at any time by contacting us.
8. Security
Controls in place include: authentication in front of every page and interface; role-based access control; per-organization data isolation enforced on every database query; encryption of provider credentials at rest; encryption of data in transit; enterprise security headers; request validation and rate limiting; and audit logging of administrative actions.
No system is perfectly secure. Token Curb has not yet completed an independent penetration test or a SOC 2 examination; both are planned. We will tell prospective customers the current status honestly rather than imply certifications we do not hold.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact hello@tokencurb.com. If you are an individual whose data appears in a customer's Token Curb workspace, please contact that organization first; we will support them in responding to you.
You may also have the right to complain to your local data protection authority.
10. Children
Token Curb is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.
11. Changes to this policy
If we make a material change, we will update the date at the top of this page and, where the change significantly affects customers, notify workspace administrators directly.
12. Contact
Token Curb
PO Box 93621, Phoenix, AZ 85070, United States
hello@tokencurb.com