Privacy Policy
Last updated: August 2026
Plain English Summary
- We collect your email address and usage spend data from your AI providers.
- Your API keys are encrypted with AES-256-GCM before storage. They are decrypted only in server memory at sync time — never stored in plaintext, never logged.
- We never sell your data. We never show you ads.
- You can delete your account and all data at any time.
- We use Supabase (database), Vercel (hosting), Stripe/Razorpay/Dodo Payments (payments), Resend (email).
- We do not sell personal data or use it for cross-site advertising networks.
- We do not share your data with third parties except as described below (including hosting, payments, email, and error/analytics subprocessors).
1. Who We Are
TryTokka is an AI spend monitoring tool operated as an independent product. We help software builders track and manage their AI API costs across multiple providers. For privacy inquiries, contact us at privacy@trytokka.com.
2. Data We Collect
2.1 Account Data
When you sign up: your email address and a hashed password (managed by Supabase Auth).
We also record a coarse, country-level location at signup — a 2-letter country code derived from our hosting provider's network routing, not your IP address, city, or precise location. This helps us understand where our users are for compliance and fraud-prevention purposes (legitimate interest).
2.2 Provider API Keys
When you connect an AI provider, we receive your API key. We immediately encrypt it using AES-256-GCM before storing it in our database. The encryption key is stored separately in our server environment and is never written to the database. Keys are never stored in plaintext and never logged.
Your keys are decrypted only in server memory during scheduled sync operations (once daily, or on demand when you trigger a manual sync), used to make one HTTPS API call to your AI provider, then discarded. They are never logged, never returned in API responses, and never stored anywhere except the database in encrypted form.
2.3 Usage Data
We fetch your AI API spend data from your connected providers and store it as daily cost totals per model. This includes: provider name, model name, date, token counts, and cost in USD. We keep this data for as long as your account is active, so you can see long-term spend trends — not just the last few months. CSV export and some in-app views are limited to the most recent 90 days at a time, but nothing is deleted behind that window.
2.4 Payment Data
We use Stripe (international), Dodo Payments (international, Merchant of Record), and Razorpay (India) for billing. We never see or store your card number. Payment processors handle all card data under PCI-DSS compliance. We store only a customer ID and subscription status. For how these providers handle your payment data, see Dodo Payments’ privacy policy and Razorpay’s privacy policy.
2.5 Newsletter & Marketing Emails
Visitors to our blog or website may subscribe to Scout's weekly AI cost newsletter by providing an email address. This email address is stored in our database and used only to send the newsletter. It is never shared with third parties. You can unsubscribe from any newsletter email with one click.
2.6 Technical Data
Standard server logs including IP addresses and request timestamps. Used for security monitoring and debugging. Retained for 30 days.
2.7 Key Access Audit Log
We log every time your API keys are accessed (sync events): timestamp, provider, success/failure. This log is visible to you in your account settings and is used for security monitoring.
3. How We Use Your Data
- To display your AI spend dashboard
- To send you spend-threshold alert emails (only if you configure an alert)
- To send weekly spend digest emails and month-end budget summaries (you can opt out at any time in Settings → Notifications, or via the unsubscribe link in each email)
- To send you account and billing emails
- To sync your usage data from AI providers on a schedule
- To manage your subscription (trial expiry, Pro status)
- To send the Scout newsletter to visitors who subscribe (opt-in only; one-click unsubscribe in every email)
We do not use provider usage data or credentials to train AI models or sell them to third parties. The public website uses cookieless aggregate Vercel Analytics when deployed on Vercel; it is not used for advertising profiles.
4. Third-Party Services
Canonical list (reviewed 2026-08-18): /subprocessors. It includes disaster-recovery backups, not only the live app vendors.
| Service | Purpose | Data shared | Where |
|---|---|---|---|
| Supabase | Database, Auth, and Row-Level Security | Email, hashed passwords, encrypted provider credentials, usage snapshots, audit rows | Supabase-hosted Postgres and Auth. Region is fixed at project creation; not selectable per customer. |
| Vercel | Application hosting, cron, environment secrets, cookieless Analytics on the public site | Server logs, request metadata, ENCRYPTION_KEY and other env secrets. Analytics is aggregate page views, not account rows. | Current production serverless functions run in iad1 (Washington, D.C. area, United States). Region is not customer-selectable. |
| Stripe | Payments (international card checkout) | Email, payment details handled by Stripe (TryTokka does not store card numbers) | Stripe’s infrastructure under Stripe’s DPA |
| Razorpay | Payments (India) | Email, payment details handled by Razorpay (TryTokka does not store card numbers) | Razorpay’s infrastructure |
| Dodo Payments | Payments (international, Merchant of Record) | Email, payment info, billing address | Dodo Payments as Merchant of Record |
| Resend | Transactional email (alerts, auth, billing mail) | Email address, alert and transactional content | Resend’s infrastructure |
| Sentry | Error monitoring (when enabled) | Anonymous user id, stack traces, request path (no API keys; PII scrubbed) | Sentry’s infrastructure |
| Cloudflare | Off-site disaster-recovery snapshots of the database (Workers KV) | Daily encrypted-database dump (includes emails and credential ciphertext). 90-day TTL per snapshot. | Cloudflare Workers KV |
| GitHub | Disaster-recovery database dumps as Actions artifacts (when that workflow runs) | Database dump artifacts, 90-day expiry | GitHub Actions artifact storage |
| Peerlist | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Peerlist’s image host |
| Product Hunt | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Product Hunt’s image host |
| Post Your Startup | Footer badge image | IP address and user-agent when the badge image loads (logged-out visitors included) | Post Your Startup’s image host |
The three badge images sit in the footer and are lazy-loaded, so the request is made when that part of the page is reached. They carry no account data and no cookies of ours; they are how those directories serve the badge artwork.
5. Your Rights
You have the right to:
- Access — request a copy of all data we hold about you
- Deletion — delete your account data from settings, subject to records we must retain for legal, fraud, refund, or dispute obligations
- Correction — update your email in account settings
- Portability — export your usage data as CSV from the dashboard
- Objection — contact us at privacy@trytokka.com to object to any processing
- Nomination — nominate another person to exercise these rights on your behalf if you die or become incapacitated, a right the DPDP Act grants specifically
- Withdraw consent — as easily as you gave it; disconnect a provider or delete your account from settings, with no need to email us first
Indian users have rights under the Digital Personal Data Protection Act 2023 (DPDP Act). EU/UK users have rights under GDPR/UK GDPR. To exercise any right, email privacy@trytokka.com.
Grievance redressal. Samson PG is the person responsible for answering questions about how TryTokka handles your personal data, reachable at privacy@trytokka.com. We answer grievances within 30 days. If we get it wrong, you can escalate: users in India may complain to the Data Protection Board of India, and EU/UK users to their local supervisory authority. We would rather you told us first so we can put it right.
6. Data Retention
- Account data: until you delete your account
- API keys (encrypted): until you disconnect a provider or delete your account
- Usage snapshots: kept while your account is active. After access ends (trial expiry, cancellation), preserved in read-only mode for 30 days, then may be deleted if no paid plan is active.
- Server and application logs: retained under the current hosting and monitoring configuration; retention can differ by service and plan.
- Payment and transaction records: retained as required for applicable accounting, tax, fraud, refund, and dispute obligations.
7. Security
See our Security page for a detailed description of how we protect your API keys. In summary: AES-256-GCM encryption before credential storage, server-memory decryption for authorized provider operations, recorded verification/sync/deletion actions, and HTTPS transport.
8. Cookies
We use essential session cookies (Supabase) and optional error-reporting beacons via Sentry when enabled. We do not set advertising or cross-site tracking cookies. Cookieless aggregate Vercel Analytics may run on the public site when deployed on Vercel — see §3 and the Cookie Policy.
9. Related products (Try family)
TryTokka is the AI API spend product in the Try family under Acsaven (parent brand hub). The canonical product site is trytokka.com. Sister sites — TryQuickImg (tryquickimg.com), TryDevSnip (trydevsnip.com), and TryCalculatingNow (trycalculatingnow.com) — are separate free browser utilities on their official .com domains. They are not affiliated with lookalike brands such as Quinn (tryquinn.com), quickimg.org, DevSnips / DevSnip Pro, CalcNest (calcnest.com), or calculatesnow.com, and those official domains do not redirect to those sites. They do not share your TryTokka account data, API keys, or billing information. See the Try family hub for an overview of all four products.
10. Children
TryTokka is a business tool for people who hold API keys with paid AI providers, and accounts are for adults. India’s Digital Personal Data Protection Act 2023 counts anyone under 18 as a child and requires a parent’s verifiable consent before a child’s personal data is processed; its rules were notified in November 2025 and that duty becomes enforceable on 13 May 2027. You confirm you are 18 or over when you create an account, and we do not knowingly hold data about anyone younger.
We run no advertising and no ad networks anywhere on this product, so the Act’s separate bans on tracking children and on advertising targeted at children have nothing to bite on here. If you are a parent or guardian and believe a child has created an account, tell us at the address in §12 and we will delete the account and everything attached to it, ahead of the 30 days we allow ourselves for a grievance.
11. Changes to This Policy
We will notify active users by email if we make material changes to this policy. The “Last Updated” date at the top reflects the most recent revision.
12. Contact
Email: privacy@trytokka.com