Privacy Policy

Last updated: September 9, 2026

1. Overview

TokenShrink is a GHB Ventures product. TokenShrink (“we”, “us”, “our”) respects your privacy. This policy explains what data we collect, how we use it, and your rights regarding that data.

2. What We Collect

Account Information

  • Email address — from your OAuth provider (GitHub or Google), used for account identification and billing communications
  • Display name — from your OAuth provider, shown in your dashboard
  • Profile image URL — from your OAuth provider, displayed in the navbar

V3 testing waitlist

If you opt in, we store your selected use case, tool and dated consent linked to your account. We use your account email for V3 testing invitations and may use usage counts to balance cohorts alongside random selection. We do not need raw prompts or documents to join. You can view your entry through the V3 page and leave at any time; leaving removes the waitlist entry. Waitlist participation is optional and does not change your subscription. The waitlist is retained until you leave, your account is deleted, or the V3 recruitment program closes; program closure is handled by the team.

Usage Statistics

  • Word counts (original and compressed)
  • Compression ratios and strategy used
  • Token savings and estimated dollar savings
  • Number of compressions per billing period

Feedback and service protection

We store feedback you submit, its category, and review status. Do not include secrets or private prompts. We use request network information for rate limiting and service protection. API keys are stored as hashes with labels and usage timestamps, not as recoverable keys.

Payment Information

Payment processing is handled entirely by Stripe. We store Stripe customer and subscription identifiers, subscription status and billing periods, webhook event identifiers, and checkout reservation details used to prevent duplicate purchases. Card details are entered with Stripe; our application does not store your full card number or CVC.

3. What We Do NOT Collect

  • Prompt text — the compression service processes your input in memory and does not save prompt text in its compression records. Hosted requests pass through our hosting infrastructure. Text you deliberately include in feedback is stored as feedback
  • Compressed output — the compressed result is never stored on our servers
  • Third-party API keys — we do not accept or store API keys from OpenAI, Anthropic, Google, or any other AI provider
  • Browsing history — we do not track pages you visit outside of TokenShrink

4. How We Use Your Data

  • To provide and operate the compression service
  • To track your usage against your plan’s word quota
  • To display your savings history in the dashboard
  • To process payments and manage subscriptions via Stripe
  • To send transactional emails (billing confirmations, quota warnings)

We do not sell your data. We do not use your data for advertising. We do not share your data with AI model providers.

5. Cookies

We use session cookies for authentication. We also use Vercel Web Analytics to understand site usage and collect aggregate compression measurements. Authentication and payment providers handle their own pages under their privacy policies.

6. Third-Party Services

Stripe — payment processing. See Stripe’s Privacy Policy.

Neon — database hosting (PostgreSQL). Stores account, subscription, API-key metadata, usage, checkout, and submitted feedback records.

Vercel — application hosting. See Vercel’s Privacy Policy.

Sentry — application error diagnostics. Our configured filter removes request contents, user fields and error messages; session replay and performance tracing are disabled.

GitHub / Google — OAuth authentication only. We receive your public profile information during sign-in.

7. Data Retention

  • Usage statistics — retained for the duration of your account
  • Account data — retained while your account is open; verified deletion requests are handled through support, subject to billing, security and legal retention requirements
  • API key hashes — retained until revoked; revoked keys are soft-deleted
  • Prompt text — never stored (processed in-memory only)

8. Your Rights (GDPR / CCPA)

You have the right to:

  • Access — request a copy of all data we hold about you
  • Correction — request correction of inaccurate data
  • Deletion — request deletion of account-linked application data; limited billing, security, backup or legal records may remain for their required retention period
  • Export — signed-in users can open the account-data JSON export. Follow its next-page links for additional records. Contact us for data outside this export’s stated scope.
  • Objection — object to processing of your data

To exercise any of these rights, contact us at ghbventures@gmail.com. We will respond within 30 days.

9. Security

We protect your data using industry-standard measures: encrypted connections (TLS), hashed API keys (SHA-256), OAuth authentication (no passwords stored), and access controls on our database. No system is 100% secure, and we cannot guarantee absolute security.

10. Children

TokenShrink is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have collected such data, contact us immediately.

11. Changes

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Material changes will be communicated via email.

12. Contact

Questions about privacy? Contact us at ghbventures@gmail.com.