Privacy Policy
Last updated: September 27, 2026
TokenUity uses a tiered data architecture: end to end encrypted Sync Vault storage alongside server side, access controlled operational data. This Privacy Policy explains the data we use, how it is protected, the roles of controller and processor, and your rights under the GDPR (EEA/UK) and CCPA/CPRA (California).
1. Overview & Tiered Data Architecture
TokenUity uses a tiered data architecture. You should understand exactly what is and is not end to end encrypted.
- 1.1 End to End Encrypted (Sync Vault). Report snapshots you choose to save to the Sync Vault are encrypted in your browser using AES GCM under a key derived from a passphrase you choose (PBKDF2 SHA 256). The passphrase and derived key never leave your device. The Platform, its operator, and the underlying infrastructure store only the ciphertext, the initialization vector, the salt, and a one way content hash — they cannot decrypt your Sync Vault entries, view your decrypted content, or recover a lost passphrase on your behalf. Synced vault uploads carry a monotonic sequence counter, and the relay rejects any upload whose sequence is not strictly greater than the stored high watermark, so a captured older encrypted blob cannot overwrite your current state.
- 1.2 Server Side, Access Controlled, Non End to End Encrypted. Certain other data you create is stored on Platform servers and is not encrypted by you. This includes saved calculation records (including the input values and results you save), loaded labor and compensation profiles (base salary, benefits, payroll taxes, overhead, and derived loaded cost figures), aggregate organization metrics, alert records, organization membership and entitlement records, and reported issues. This server side data is access controlled (each user and administrator can read and modify only what they are entitled to under row level security) and is not keyed to your name or email, but TokenUity LLC and its infrastructure can store, read, and process it in order to operate the Platform. Do not save to these server side stores any content you require to be unreadable by the operator; use the Sync Vault for content requiring end to end encryption.
- 1.3 Client Side Computation. All modeling, calculation, and detection logic runs client side in your browser. The raw inputs you enter into a calculator are processed locally; only the records described in Section 1.2 are transmitted to Platform servers when you choose to save a result.
- 1.4 Idle Auto Lock and Memory Cleansing. For the security of an unlocked Sync Vault, an idle session is automatically locked after fifteen (15) minutes of inactivity, with a non blocking warning presented before the lock. The idle timer is measured against a monotonic clock so changing the device system clock cannot extend the session. When the vault locks, all decrypted report buffers held in your browser memory are overwritten and cleared so that no decrypted content persists in the device heap. If you have enabled “Trust this device,” a derived device key (not your passphrase) is stored on that device to auto unlock the vault on later logins; clearing this only drops access on that device.
- 1.5 End to End Encrypted (Org Shared Labor Vault). Loaded labor and compensation figures (base salary, benefits, payroll taxes, overhead, and derived loaded cost) are encrypted in an administrator's browser using AES GCM under a key derived from an organization wide shared passphrase (PBKDF2 SHA 256, with the salt stored on the Organization record). The shared passphrase and derived key never leave an admin's device. The Platform stores only the ciphertext, initialization vector, salt, one way content hash, and a monotonic sequence counter, and cannot decrypt labor vault entries or recover a lost shared passphrase. Synced labor uploads carry a monotonic sequence counter and the relay rejects any upload whose sequence is not strictly greater than the stored high watermark, preventing replay of captured older encrypted blobs. A lost shared passphrase is recovered only through dual control re keying requiring a second administrator's approval.
2. Controller & Processor Roles
TokenUity LLC is the data controller for the personal data it processes about you as an account holder, payer, and security/abuse subject (account email, authentication, payment, chargeback defense, and procurement attestation data). Where you are an organization administrator who invites members to use the Platform under your account, your organization is the controller of your members' personal data (their email addresses, system generated Member IDs, and organization placement), and TokenUity LLC acts as a processor on your organization's behalf, subject to the Data Processing Agreement available on the Platform. Where a member exercises data protection rights over data your organization controls, TokenUity will generally refer the request to your organization as controller; TokenUity will nonetheless honor verifiable direct requests to the extent required by applicable law and consistent with its processor role.
3. Personal Data We Collect
We collect and process the following categories of personal data:
- Account email and authentication credentials, processed by the underlying authentication infrastructure (we do not hold passwords in plaintext).
- A system generated, opaque Member ID assigned at registration or invitation; you cannot enter a personal display name.
- Organization metadata, package selection, seat limits, and per member entitlement toggles.
- Agentic plan session data: for organizations on the Agentic plan, the Platform stores a one-way hash of the one-time registration token issued at payment (cleared after activation), the UTC instant the access window began (activation), the UTC instant the current window expires, and (before activation) the length of the first purchased session. No raw registration token is retained.
- Saved calculation records (the input values and numeric results you choose to save), which are server side and access controlled and not end to end encrypted by you; and loaded labor and compensation profiles (base salary, benefits, payroll taxes, overhead, and derived loaded cost), which are end to end encrypted in the org shared labor vault under an admin shared passphrase (Section 1.5) and are not readable by the operator.
- Aggregated, nonidentifying numeric totals (organization report metrics, including those produced by the AI TCO Analysis module and the Shadow Metrics Hub pillars — Complexity Resolution Index, Integrity Assurance Tracker, and System Stewardship Tracker) you choose to persist; raw prompt text and raw CSV rows are not retained — raw prompt/step text is purged from every saved snapshot before persistence.
- Chargeback defense fingerprints collected at checkout and on disputes: a one way hash of the buyer email, the buyer email domain (not PII), a one way hash of the originating IP address, and (for card payments) a one way card fingerprint hash, together with the package and size tier and billing period recorded at purchase. We do collect and store a one way hash of your IP address for this purpose.
- Procurement access audit log entries: a one way hash of the verified requester email, the requester IP address, the action taken (view, download, or attestation), the document key, and the timestamp. For NDA acceptance attestations, the public key, signature, content hash, NDA version, and attestation statement are also retained as tamper evident evidence.
- Digital asset payment data: for USDC on Base payments facilitated by Coinbase CDP, the paying wallet address and the on chain transaction hash. On chain payment data is publicly visible on the Base blockchain and is outside TokenUity's control.
- Processed Stripe webhook event identifiers, retained on a 30 day auto purge schedule.
- Opt in, anonymized product usage telemetry: when enabled (see Section 7), the Platform emits only two coarse event families — that a module was opened (module key) and that a calculator was run (calculator type). No personal data, prompt text, report content, input values, or token counts are transmitted. Telemetry is off by default; it is enabled by an organization admin and any member may opt out individually at any time.
- Initiative Tracker assignments: when an organization admin launches an initiative, the Platform stores non personally identifying org structure labels (department and team slugs, cadence, and due dates) and sends cadence driven reminder emails to the account email addresses of assigned members. No individual headcount or role data is stored.
4. Metadata We Do and Do Not See
Loaded labor profile and group identifiers are one way hashed (SHA 256, salted) in your browser before they reach the Platform, so the operator is blind to the real names of your labor profiles and groups. User typed report labels on saved calculation records, however, are not hashed and are stored on Platform servers as you type them (server side and access controlled); the operator can read them. Member profile snapshots do not store names or emails for display — only opaque Member IDs are surfaced to other members and to organization administrators. If you require a label to be unreadable by the operator, do not save it as a server side record; save the report snapshot to the end to end encrypted Sync Vault instead.
5. Payment Data
Card payment information is handled exclusively by a third party payment processor (Stripe, PCI DSS compliant). The Platform does not receive or store your full card or bank details; it receives only a Stripe customer and subscription identifier and, for chargeback defense, the one way fingerprints described in Section 3. For digital asset payments, USDC on the Base network is facilitated through Coinbase CDP; the Platform records the paying wallet address and the on chain transaction hash, and the transaction itself is settled and recorded on the public Base blockchain. Coinbase receives the wallet address and transaction details necessary to facilitate and settle the payment under its own terms and privacy policy.
6. How We Use Information
- To authenticate access and enforce package and seat entitlements.
- To provision organization membership and per user module toggles, and to administer server side seat and administrator limits.
- To maintain service availability, integrity, and security, and to prevent, detect, and respond to abuse.
- To enforce that enrollment uses a valid business (organizational) email and to administer server side seat and administrator limits.
- To prevent and defend against friendly fraud and chargebacks, including pre purchase blocklist screening and post dispute blacklisting of fingerprints, as described in the Terms of Service.
- To verify and audit procurement access and NDA acceptance attestations.
- To process and reconcile digital asset payments and, where applicable, record settled on chain transactions for billing reconciliation.
- To measure coarse, anonymized product usage (which modules were opened and which calculators were run) for improving the Platform, only when telemetry has been enabled and not opted out as described in Section 7.
- To operate the Initiative Tracker, storing non personally identifying initiative assignments and sending cadence driven reminder emails to assigned members.
7. Legal Bases (GDPR)
For individuals in the European Economic Area, the United Kingdom, and Switzerland, TokenUity LLC processes personal data on the following legal bases: (a) performance of the contract between you (or your organization) and TokenUity, for account provisioning, authentication, entitlement enforcement, and service delivery; (b) TokenUity's legitimate interests in operating, securing, and protecting the Platform and its business, including fraud and abuse prevention, chargeback defense, and procurement audit, except where overridden by your rights and interests; (c) compliance with a legal obligation to which TokenUity is subject; and (d) your consent, where you affirmatively opt in to a specific processing activity (you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal). Product usage telemetry (Section 3) is processed on the basis of your consent: it is off by default, is enabled by an organization admin, and any member may opt out individually at any time, in which case no telemetry event is emitted for that member. Where TokenUity acts as a processor on behalf of your organization, processing is carried out under your organization's instructions and legal basis as controller, as set out in the Data Processing Agreement.
8. Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy and then delete or anonymize it. Server side calculation records, compensation profiles, aggregate metrics, alerts, and reported issues persist until you delete them or until your organization's subscription is canceled or, for Agentic plan organizations, until the active timed session window expires. Upon cancellation or termination of your organization's subscription, an automated process permanently deletes your organization and user identifiers, all end to end encrypted org shared labor vault entries (including their salts and ciphertext), and purges the cryptographic salts and one way email hashes used for authentication at the end of a thirty (30) day grace period (during which your organization retains access), as described in the Terms of Service, leaving no residual personal data on the Platform's servers or relays. This erasure is irreversible. The following categories are intentionally retained beyond the grace period: (a) the processed Stripe webhook event ledger, which auto purges on its own 30 day retention schedule; (b) procurement NDA acceptance attestation records, retained as tamper evident evidence of mutual confidentiality obligations; and (c) chargeback blocklist fingerprints (email hash, email domain, IP hash, card fingerprint) for accounts permanently blacklisted for friendly fraud, retained to prevent repeat abuse. Decrypted Sync Vault content exists only in your active browser session: when your session is idle locked after fifteen (15) minutes of inactivity, the Platform overwrites and clears in memory decrypted buffers so that no decrypted content remains in the device heap.
9. Your Rights: GDPR (European Economic Area & UK)
- Access: you may request a copy of the personal data we hold about you (limited to the categories in Section 3).
- Rectification: you may correct your account email or request correction of inaccurate data.
- Erasure: you may delete your account and saved data at any time; your organization's automated erasure is described in Section 8.
- Restriction and portability: you may restrict certain processing and may export your reports as PDF, CSV, or Excel.
- Objection: you may object to processing carried out on legitimate interest grounds.
- Withdrawal of consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority, or with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
- Automated decision making: the Platform does not engage in solely automated decision making producing legal or similarly significant effects. All modeling and detection is deterministic, client side, user parameterized computation, reviewed and acted on by you.
- Because the Sync Vault is end to end encrypted, TokenUity cannot recover or reset a lost vault passphrase for you; a forgotten passphrase may be reset only through the vault reset mechanism described in the Terms of Service, which permanently deletes your existing encrypted reports. Where your data is controlled by your organization, direct rights requests may be referred to your organization as controller.
10. Your Rights: CCPA / CPRA (California)
- Right to know: the categories and specific pieces of personal data collected (the categories in Section 3).
- Right to delete: you may request deletion of your personal data, subject to legal retention (including the retained categories in Section 8).
- Right to correct: you may request correction of inaccurate personal data.
- Right to opt out of sale or sharing: TokenUity does not sell or share personal data and does not engage in cross context behavioral advertising; no opt out is therefore required.
- Right to limit use of sensitive personal information: TokenUity does not use sensitive personal information for purposes beyond providing and securing the service.
- Right to nondiscrimination: exercising your rights will not result in different service quality.
- Authorized agents may submit requests on your behalf with verifiable authorization.
- Business to business context: to the extent California law provides a limited exemption for business contact and certain personnel data collected in an employment or B2B context, that exemption is relied upon where applicable. For independent contractors who are consumers, the rights above apply.
11. Your Rights: Other Markets
The Platform is offered across multiple markets. If you are located outside the EEA, UK, or California, you may have additional or different rights under your local data protection law (for example, PIPEDA in Canada, the LGPD in Brazil, or equivalent laws in your jurisdiction). We will honor verifiable requests made under applicable local law on the same basis as the rights above. To the extent a local law grants a right not listed here, you may exercise it by contacting TokenUity LLC through the support channel in your account settings or as provided in Section 19.
12. Data Residency & International Transfers
Personal data is hosted and processed on infrastructure operated by the platform provider (Base44/Wix), with primary processing and storage located in the United States. Authentication and transactional email are routed through the platform provider's infrastructure. Card payment data is processed by Stripe under its own regional infrastructure, and digital asset payments are facilitated by Coinbase CDP with settlement on the Base blockchain. Where personal data is transferred from your jurisdiction to the United States or another country, such transfers rely on an appropriate recognized transfer mechanism: for transfers from the EEA, UK, or Switzerland, the European Commission's Standard Contractual Clauses (or the UK's equivalent International Data Transfer Addendum), and for other jurisdictions, an equivalent transfer safeguard recognized under the law of that jurisdiction.
13. Subprocessors
The Platform uses a limited set of named subprocessors. Each is engaged under a written contract imposing protections no less stringent than this Policy. The current subprocessor schedule is: We will provide notice of material changes to this subprocessor schedule (including new subprocessors) through the Platform or by direct notice where required by law, and will, where applicable, give you the opportunity to object in accordance with applicable law and the Data Processing Agreement.
- Base44 (operated by Wix.com): application infrastructure, hosting, user authentication, and transactional email delivery.
- Stripe, Inc.: card payment processing and subscription billing (the Platform receives only a customer/subscription identifier and chargeback defense fingerprints, never full card details).
- Coinbase, Inc. (Coinbase Developer Platform / CDP): facilitation and settlement of digital asset (USDC on Base) payments; receives the paying wallet address and transaction details necessary to facilitate settlement.
- Cloudflare, Inc.: bot and automated abuse protection (Turnstile); processes only ephemeral challenge tokens.
- UptimeRobot: passive external uptime monitoring; performs HTTP reachability checks against the Platform's public endpoints at a five minute interval, with no alert emails configured and no personal data processed for the Platform's purposes.
- The Base network is a public permissionless blockchain, not a subprocessor; on chain payment data is publicly visible and outside TokenUity's control.
14. EU Artificial Intelligence Act: Nonapplicability
The Platform is a client side modeling and decision support tool. It does not place an “AI system” on the Union market within the meaning of Regulation (EU) 2024/1689 (the EU Artificial Intelligence Act): all outputs are produced by deterministic, user parameterized computations running in your browser (regex based detectors, deterministic formulas, and byte pair encoding token counting), and the Platform does not invoke any large language model, machine learning model, or other trained model. Accordingly, the transparency, risk classification, logging, and conformity assessment obligations of the AI Act do not apply to the Platform. This is a statement of nonapplicability based on the Platform's actual functionality, not an exemption claim.
15. Cookies & Analytics
The TokenUity application itself sets no cookies. The hosting platform may set strictly necessary operational cookies to keep the service available and secure; authentication is token based and does not rely on a browser cookie. Cloudflare Turnstile may set strictly necessary challenge cookies on pages where bot protection is rendered. Product usage telemetry is opt in and anonymized: when enabled, the Platform records only that a module was opened and that a calculator was run, with no personal data, prompt text, report content, or token counts, and it performs no session replay, advertising, or cross site tracking and no cross context behavioral advertising. It is off by default, enabled by an organization admin, and any member may opt out individually at any time. Further detail is available in the Cookie Policy.
16. Children's Privacy
The Platform is not directed to, and is not offered to, anyone under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, contact us as provided in Section 19 and we will delete it.
17. Security Measures
In addition to the end to end encryption of the Sync Vault and the org shared labor vault described in Section 1, TokenUity applies: row level access control so each user and administrator can read and modify only what they are entitled to; one way hashing and salting of email addresses, IP addresses, card fingerprints, and labor identifiers; client side derivation and device local storage of vault keys; dual control re keying of the org shared labor vault, which requires a second organization administrator's approval before the shared passphrase and salt are rotated; and automated memory cleansing on idle lock. Card data never touches our infrastructure. Notwithstanding these measures, no system is perfectly secure, and you should use the Sync Vault for any content you require to be unreadable by the operator.
18. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date and, where required, communicated to registered users. Continued use after a change constitutes acceptance of the revised Policy.
19. Contact
To exercise any right above, request information, or contact us about privacy, contact TokenUity LLC, 1101 Silentglade Rd, Owings Mills, MD 21117, United States, or through the support channel provided in your account settings. For GDPR matters, you may also lodge a complaint with your local data protection supervisory authority.
