This policy explains how TokenSmith ("TokenSmith," "we," "us") handles information when you use the TokenSmith desktop and mobile apps, website, API, and related services.
Information we collect
- Account information: your email address, account identifier, authentication records, security information, and a profile name when supplied through an optional Apple or Google sign-in.
- User content: prompts, conversations, model responses, and feedback you choose to submit.
- Desktop workspace information: files, attachments, terminal output, tool results, and connector content that you select or authorize the app to use. Relevant content can be included in requests to your selected model or connector. Local workspace files and device settings can remain on your device after account deletion.
- Commerce information: store and product details, buyer contact and delivery information, order records, and payment, refund, and dispute status when you use commerce features. Store operators and payment providers receive information needed to fulfill and process orders.
- Search information: search queries generated from a request when web search is used to answer it.
- Service and purchase records: model selections, token usage, timestamps, credit balance, purchase history, and subscription status. Payment-card details are handled by the payment provider and are not collected by the mobile app.
- Technical information: network and request information needed to operate, secure, and troubleshoot the service.
How we use information
We use this information to authenticate accounts, provide and synchronize conversations, route requests to the selected AI model, perform requested web searches, account for usage, prevent fraud and abuse, provide support, maintain security, and comply with law. We do not sell personal information or use it for cross-company advertising tracking.
Service providers and AI providers
TokenSmith uses service providers to operate the product, including Supabase for authentication and database services, Apple and Google when you choose their sign-in options, Cloudflare for network and API infrastructure, Stripe for web billing, and Brave Search for requested web results.
Before the mobile app sends your first message to an AI provider, it asks for your explicit permission. If you allow it, the message and relevant conversation context are sent to the provider of the model you select so that provider can generate a response. This content may include personal information you choose to enter. Depending on the selected model, the provider may be OpenAI, Anthropic, Google, xAI, Together AI, or another provider identified in the model picker. These parties process information under their own terms and privacy commitments as applicable.
In the mobile app, you can withdraw this permission at any time from Settings → AI data sharing. After withdrawal, the mobile app will not send another message to an AI provider unless you explicitly allow it again.
Retention and deletion
Account information and synchronized conversations are retained while your account is active. You can permanently delete your account from Settings → Delete account in the mobile app. Deletion removes the account and associated conversations, API keys, generated media, remaining TokenSmith credits, and the linked web billing customer where applicable, except records we must retain for legal, tax, fraud-prevention, dispute, or security purposes.
Apple subscriptions must be canceled separately in your App Store subscription settings. Deleting an account or uninstalling the app does not cancel Apple renewal charges. For deletion without the mobile app, email support@tokensmith.us. Third-party providers may retain records under their own applicable obligations.
Device storage
The website uses browser storage to keep your sign-in session, preferences, and return destination. Desktop and mobile apps also keep session and preference data on your device. Signing out and clearing site or app data can remove local settings; clearing local data does not delete your cloud account. Browser Do Not Track signals do not change the service’s processing described in this policy.
Security and international processing
We use administrative, technical, and organizational safeguards designed to protect information. Information may be processed in countries other than your own, subject to applicable safeguards. No system is completely secure, so we cannot guarantee absolute security.
Children
TokenSmith accounts are intended for adults aged 18 or older who can enter a binding contract where they live. Do not create or use an account if you are below that age. If you believe a child has provided personal information, contact support@tokensmith.us so we can investigate and address the account and data. Do not email a child’s identity documents or sensitive content.
Your choices and rights
Depending on your location, you may have rights to access, correct, export, object to processing of, restrict, or delete your personal information. To make a request, delete your account in the app or contact us. We may verify your identity before completing a request. Use support@tokensmith.us to request access, correction, a portable copy, or deletion, or to appeal a privacy-request decision. You may also complain to the data-protection authority where you live. These rights depend on applicable law; exercising them does not waive your consumer rights.
Changes
We may update this policy as TokenSmith changes. We will post the updated policy here and change the date above. Material changes may also be communicated in the service.
Email support@tokensmith.us with privacy questions or requests.