← Back to site

Privacy Policy

Last updated: 28 August 2026

Token Curb helps organizations understand and control what they spend on AI services. This policy explains what information we collect, why we collect it, and what we do not collect.

The short version: Token Curb reads billing and usage metadata from your AI providers — how many tokens, which model, what it cost. We do not receive, store, or process the content of your AI prompts or the responses returned to you.

1. Who we are

Token Curb ("Token Curb", "we", "us") operates the Token Curb AI spend management platform. For questions about this policy or your data, contact hello@tokencurb.com.

Where you use Token Curb as a customer organization, you are the controller of the data in your workspace and Token Curb acts as your processor, handling that data on your instructions and under our agreement with you.

2. Information we collect

Account and workspace information

Provider credentials

To import your usage data, Token Curb stores the reporting-scope administrative API key you supply for each AI provider. These keys are encrypted with AES-256-GCM before storage, using an encryption key held in a managed cloud secret vault. A stored credential is cryptographically bound to the single organization and single provider it was created for, and is never displayed, exported, or returned by any interface after you enter it.

Usage and cost data imported from your AI providers

Operational records

Information you send us directly

If you submit a pilot request or contact us, we collect the name, email address, and phone number you provide, together with any message content, so we can respond.

3. What we do not collect

4. Why we use your information

PurposeInformation used
Show your AI spend, usage, forecasts, and savings recommendationsImported usage and cost data
Import data from your AI providers on a scheduleEncrypted provider credentials
Send budget alerts you have configuredAdministrator email addresses, spend totals
Authenticate you and enforce roles and tenant isolationAccount email, organization membership
Maintain security, investigate incidents, and prevent abuseAudit events, hashed IP addresses, rate-limit counters
Respond to your enquiriesContact details you submit

5. Service providers

Token Curb relies on a small number of providers to operate the service. Each processes data only as needed to provide their service to us.

ProviderRole
Cloudflare, Inc.Application hosting, database storage, authentication gateway, and secret storage
HighLevel Inc. (GoHighLevel)Delivery of alert and notification emails, and management of enquiries you submit to us

Your AI providers — such as OpenAI and Anthropic — are the sources of the usage data you ask Token Curb to import. They act as your own providers under your agreement with them, not as our subprocessors.

We do not sell personal information, and we do not share it with third parties for their own advertising purposes.

6. Where data is held

Token Curb runs on Cloudflare's global infrastructure. Data is stored in the region associated with your workspace configuration. If a specific data residency requirement applies to your organization, raise it with us before onboarding so we can confirm whether we can meet it.

7. How long we keep data

Imported usage and cost data is retained according to your organization's retention setting, which defaults to 365 days. Audit records are retained to support security investigations and compliance obligations. If your organization stops using Token Curb, we will delete or return your workspace data on request, subject to any legal retention requirements.

You can request export or deletion of your workspace data at any time by contacting us.

8. Security

Controls in place include: authentication in front of every page and interface; role-based access control; per-organization data isolation enforced on every database query; encryption of provider credentials at rest; encryption of data in transit; enterprise security headers; request validation and rate limiting; and audit logging of administrative actions.

No system is perfectly secure. Token Curb has not yet completed an independent penetration test or a SOC 2 examination; both are planned. We will tell prospective customers the current status honestly rather than imply certifications we do not hold.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, contact hello@tokencurb.com. If you are an individual whose data appears in a customer's Token Curb workspace, please contact that organization first; we will support them in responding to you.

You may also have the right to complain to your local data protection authority.

10. Children

Token Curb is a business tool and is not directed to children. We do not knowingly collect personal information from anyone under 16.

11. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where the change significantly affects customers, notify workspace administrators directly.

12. Contact

Token Curb
PO Box 93621, Phoenix, AZ 85070, United States
hello@tokencurb.com