Tokaware

updated October 3, 2026

Privacy policy

This policy says what Playpals Studio, established in Tunisia, which runs Tokaware ("we"), collects when you use the website, the desktop app and the team console, why, and what you can do about it; we are the controller of that data. For what an organization collects about its people through the service, the organization decides, and we process it for the organization under the data processing addendum.

What we collect

WhatWhenWhy
Your account: email, password (hashed), your name if you give it, whether the email is confirmedWhen you create an accountTo sign you in and write to you about your account
Claude and ChatGPT accounts you link: their sign-in tokens (encrypted), plan, account email and usageWhen you link one while signed inTo show their limits, to you and your teams
What a computer you connect sends: its host name, system and app version, the email each CLI there is signed in with, token counts by project, model and day, prompts, edits, lines and commands, sessions with their times, and their titles when the computer shares session contentWhen you connect it with the desktop appTo show your work, and your teams' dashboards
Claude Code's and Codex's telemetry, when your organization collects it: your email and your use per day (tokens and their cost, sessions, lines, commits, pull requests, active time, how many prompts; never a prompt's text)When Claude Code or Codex on your computer sends it with your organization's tokenTo count your organization's use on the days no computer of yours reports it through the desktop app
Conversations, prompts, images and remote sessions' outputOnly when someone allowed to read them asks and the computer allows it, or while a remote session runsTo show them to that person
Teams: name, members and roles, groups and who is in or manages each, invites with the email invited, settings, and API and ingest tokens (each one's name, who made it and when it was last used; the token itself only as a hash)When you create or join a teamTo run the team
Billing: the subscription and its status, seats, the billing name and email, the card's brand and last four digits, as Lemon Squeezy sends themWhen an organization subscribesTo apply the plan and answer billing questions
Messages to sales: email, name, company, seats and the messageWhen you use the contact formTo answer you
Sign-ins: when each began and was last used, its browser, and the address it was last used from (encrypted)When you sign in and use the serviceTo keep you signed in, and to show you where you are so you can end a sign-in you do not know
A Google or Microsoft account you sign in with: its id there and the email it gives (encrypted)When you sign in with it or connect itTo sign you in with it
Your organization's single sign-on: your id at its identity provider and the email it gives (encrypted), and which organization it isWhen you sign in with your organization's SSOTo sign you in with it, and to let the organization's policy count it
Your organization's directory: which of its people you are there, your email, and the groups you are inWhen your organization connects its directoryTo add you to the organization and its groups, and to take you out when its IT does
An organization's audit log: who did what (your email then) and when, what to, and the address it came from (encrypted), including reads of what its computers' sessions sayWhile you are in an organization on Business or Enterprise; an entry stays, as long as the organization keeps it, after you leave or delete your accountSo its owners, admins and viewers can see who did what, as their security requires
Technical data: IP addresses in our host's request logs, hashed counts of attempts, page views without cookiesWhen you use the websiteTo keep the service working and secure, and to count visits

Without an account

The dashboard works without an account: the accounts you add stay in your browser, and the website passes each request on to Claude or OpenAI without keeping anything. As a guest, the desktop app keeps everything on your computer.

What we do not do

  • We do not sell personal data, or use it for advertising.
  • We do not use your data, conversations or code to train AI models.
  • We do not read conversations or prompts ourselves, unless you show us one to help with a problem, or the law requires it.

Who processes it

The companies that host and run parts of the service for us are on the subprocessors page, with what each one handles. Lemon Squeezy processes payments as merchant of record, under its own privacy policy. When you link a Claude or ChatGPT account, the service reaches Anthropic or OpenAI with it, under their policies.

An organization's alerts and weekly digest go where its owners and admins send them: email to its people, or its own Slack, Microsoft Teams or webhook address. They name its people by email and its computers, projects and numbers.

An organization on Business or Enterprise can read its numbers from its own tools (a data warehouse, a dashboard, a SIEM) with the API tokens its owners and admins make, each reading only what it was given: its people with their roles and groups, their use per day by email, its spend and AI accounts, and its audit log.

An organization's connectors reach its own organization at Anthropic (its Claude Console or Claude Enterprise organization), at OpenAI (its API platform organization or ChatGPT Enterprise workspace), at Cursor (its Enterprise team) or at GitHub (its organization's Copilot) with the key it gives, every hour, and bring back what it was billed, its API usage by model, key, workspace, project or product, its seat counts, and its people's Claude Code, Codex, Cursor and Copilot use and costs, by email (for GitHub, the email of their SAML identity or their public one). They only read: a connector asks for reports and changes nothing there. The key is kept encrypted; what comes back is kept as long as the organization's plan keeps history.

Transfers

We are established in Tunisia, and our subprocessors are in the United States. Transfers from the European Economic Area, the United Kingdom and Switzerland rely on the Standard Contractual Clauses, with the UK addendum, or on the EU-U.S. Data Privacy Framework where the recipient is certified.

How long we keep it

DataKept
Your account, linked accounts and teamsUntil you delete them
What a connected computer last reportedWhile it stays connected
Daily numbers of usage and work, limit readings, and what connectors bring in (billed costs, API usage, seat counts)As long as the plan keeps history: 30 days on Free, 90 days on Team, 13 months on Business and Enterprise; 30 days outside an organization
An organization's alertsWhile they fire, then as long as its plan keeps history
An organization's audit logAs long as its plan keeps history: 13 months on Business and Enterprise
A month an organization closed (its chargeback as it stood)Until an owner reopens it, or the organization is deleted
Conversations, prompts and commands read from computers7 days
Images from conversations3 days
Remote sessions and their output30 days
Sign-ins, with the browser and the address each was last used from30 days, or less where an organization says so, or until you sign out
Links sent by emailUntil used, and at most an hour (a new password) or a day (confirming an email)
Invites7 days
What Lemon Squeezy sends about subscriptions, and messages to sales2 years
Our host's request logsUp to 30 days
Deleted data in our database provider's backupsUntil those backups expire

Cookies and storage

One cookie, aic_session, keeps you signed in: set when you sign in, removed when you sign out. The browser's local storage keeps your settings, and without an account the accounts you added. There are no advertising or tracking cookies; visits are counted by Vercel Web Analytics without cookies, from the page's address alone.

Your rights

You can see and change your data in the service, download a copy of everything kept of your account, and delete linked accounts, computers and your whole account yourself (Account, on the dashboard). You can also ask us for a copy of your data, to correct, restrict or erase it, or object to how we use it: write to support@tokaware.com, and we answer within a month. In the European Economic Area and the United Kingdom you can also complain to your data protection authority.

If an organization collects your data through the service, it decides about that data: ask it first, and we help it answer. Deleting your account deletes what is yours alone; the daily numbers of the work you did on an organization's computers stay with that organization, no longer linked to your email.

Security

How we protect data is on the security page.

Children

The service is not meant for anyone under 16, and we do not knowingly collect their data.

Changes

We post changes here, and tell account holders by email before a change that matters applies.

Contact

Playpals Studio, established in Tunisia, which runs Tokaware: support@tokaware.com.