Small data footprint.
Effective 16 August 2026
What TokenGauge processes
When you continue with ChatGPT, the login integration provides an account identifier and may provide your name, email address, and plan name. That identity can be your TokenGauge sign-in and can also power lab requests you explicitly run. Authentication credentials are encrypted at rest and kept on the TokenGauge server for up to seven days after the last activity that renews the connection. Raw tokens are never sent to the browser or exposed by TokenGauge routes or components.
Your TokenGauge account
We store your identity reference, plan entitlement, launch-offer eligibility, and optional method-tracking statuses. If you choose the separate email login, we also store your name, verified email address, password hash, sessions, and security settings. Session security records can include an IP address and browser user-agent. Passwords are hashed rather than stored. Authenticator secrets and recovery codes are encrypted by the account system. Verification and password-reset links are sent through our configured mail provider.
Provider connections
If you save an API key, TokenGauge encrypts it separately for your account using authenticated AES-256-GCM encryption. The browser receives only a four-character hint, never the stored plaintext. Keys are decrypted only for a lab request you initiate and can be removed from Settings.
Experiments
Your prompts and generated answers pass through this server to the model source you select so the A/B lab can work. They are returned to your browser and are not stored in the TokenGauge database. We retain only the provider, model, strategy label, timestamp, and aggregate input, output, and total token counts. Cache and reasoning counts can be returned for the current result but are not retained in the experiment table.
Payments
Stripe processes payments. TokenGauge sends Stripe an opaque billing identifier and, if your connected profile provides one, your email address. We retain Stripe customer, checkout, and payment identifiers needed to grant access, handle refunds, and prevent duplicate fulfilment. We do not receive full card details.
Anonymous product counters
TokenGauge keeps daily aggregate counts for selected page visits, account or pricing actions, and checkout creation or failure. These counters do not store IP addresses, browser identifiers, cookies, form contents, prompts, outputs, or account identifiers. A browser tab suppresses repeat page counts during its current session using session storage; that marker is not sent to the server.
Service enquiries
The fixed-scope service pages have no contact form and require no TokenGauge account. Their email links open your own mail application with a public-scope template. If you send it, your mail provider and the TokenGauge Proton mailbox process the message. Enquiries are kept only as needed to assess fit, scope the work, reply, and meet legal obligations. Do not include credentials, private source, prompts, outputs, customer data, or payment details in the initial enquiry.
Control and retention
Settings provides a self-service JSON export of the account data TokenGauge can associate with you. It deliberately excludes provider-key plaintext and ciphertext, authentication secrets, internal billing identifiers, prompts, outputs, and anonymous counters. The same page removes every optional provider credential, experiment record, and method status from the active workbench database in one operation. Mode-600 operational database backups can retain an earlier copy; they are kept on a 14-day retention schedule and deleted by the daily rotation job. Login security records, ChatGPT links, entitlements, payment references, and Launch 100 membership are kept by the workbench-data operation so access and refunds remain correct. You may request complete account deletion by emailing [email protected]; records required for accounting, fraud prevention, disputes, or legal obligations may still be retained. Disconnecting ChatGPT removes the local ChatGPT session, while signing in again with the same identity restores access still attached to it.
Third parties and infrastructure
The service relies on Cloudflare for the public network edge, Stripe for payment processing, Proton for account-email delivery, an open-source Login with ChatGPT integration, and whichever model provider you explicitly connect for lab requests. Cloudflare can process connection metadata such as IP address, request time, route, and browser details under its own privacy practices. The respective third-party terms and privacy practices apply.