Last updated 20 July 2026
TokenLedger Ltd (“TokenLedger”, “we”) operates tokenledger.app. This policy says what we collect, why, where it lives, and how to take it away. It is written to be read.
TokenLedger has read-only access to usage metadata. No prompt or content data is ever collected — the keys you connect are not capable of exposing it.
Provider keys and webhook URLs are encrypted at rest with AES-256-GCM under a key held only in the server environment, decrypted server-side at sync time, displayed masked, and stripped from logs by a redaction layer. Deleting a connection destroys its key immediately.
Contract (running the service you signed up for), legitimate interest (security, abuse prevention, product analytics), and consent where required (marketing emails — each has a one-click unsubscribe).
Data lives as long as your workspace does. Deleting a workspace (Settings → Data, typed confirmation) hard-deletes every row and key within 24 hours, confirmed by email. The full CSV export is available on every plan, any time.
Access, rectification, erasure, portability, restriction, objection — the UK GDPR set. Most are self-serve (export, delete); for the rest, email privacy@tokenledger.app. You may also complain to the ICO.
This policy and any dispute under it are governed by the laws of England and Wales, and TokenLedger Ltd is the data controller.
Material changes are announced by email and in the changelog before they take effect. The date at the top is the date that counts.