Privacy Policy
Last updated: June 2026
Plain English Summary
- We collect your email address and usage spend data from your AI providers.
- Your API keys are encrypted with AES-256-GCM before storage. They are decrypted only in server memory at sync time — never stored in plaintext, never logged.
- We never sell your data. We never show you ads.
- You can delete your account and all data at any time.
- We use Supabase (database), Vercel (hosting), Stripe/Razorpay/Dodo Payments (payments), Resend (email).
- We do not sell personal data or use it for cross-site advertising networks.
- We do not share your data with third parties except as described below (including hosting, payments, email, and error/analytics subprocessors).
1. Who We Are
TryTokka is an AI spend monitoring tool operated as an independent product. We help software builders track and manage their AI API costs across multiple providers. For privacy inquiries, contact us at privacy@trytokka.com.
2. Data We Collect
2.1 Account Data
When you sign up: your email address and a hashed password (managed by Supabase Auth).
We also record a coarse, country-level location at signup — a 2-letter country code derived from our hosting provider's network routing, not your IP address, city, or precise location. This helps us understand where our users are for compliance and fraud-prevention purposes (legitimate interest).
2.2 Provider API Keys
When you connect an AI provider, we receive your API key. We immediately encrypt it using AES-256-GCM before storing it in our database. The encryption key is stored separately in our server environment and is never written to the database. Keys are never stored in plaintext and never logged.
Your keys are decrypted only in server memory during scheduled sync operations (once daily, or on demand when you trigger a manual sync), used to make one HTTPS API call to your AI provider, then discarded. They are never logged, never returned in API responses, and never stored anywhere except the database in encrypted form.
2.3 Usage Data
We fetch your AI API spend data from your connected providers and store it as daily cost totals per model. This includes: provider name, model name, date, token counts, and cost in USD. We keep this data for as long as your account is active, so you can see long-term spend trends — not just the last few months. CSV export and some in-app views are limited to the most recent 90 days at a time, but nothing is deleted behind that window.
2.4 Payment Data
We use Stripe (international), Dodo Payments (international, Merchant of Record), and Razorpay (India) for billing. We never see or store your card number. Payment processors handle all card data under PCI-DSS compliance. We store only a customer ID and subscription status. For how these providers handle your payment data, see Dodo Payments’ privacy policy and Razorpay’s privacy policy.
2.5 Newsletter & Marketing Emails
Visitors to our blog or website may subscribe to Scout's weekly AI cost newsletter by providing an email address. This email address is stored in our database and used only to send the newsletter. It is never shared with third parties. You can unsubscribe from any newsletter email with one click.
2.6 Technical Data
Standard server logs including IP addresses and request timestamps. Used for security monitoring and debugging. Retained for 30 days.
2.7 Key Access Audit Log
We log every time your API keys are accessed (sync events): timestamp, provider, success/failure. This log is visible to you in your account settings and is used for security monitoring.
3. How We Use Your Data
- To display your AI spend dashboard
- To send you spend-threshold alert emails (only if you configure an alert)
- To send weekly spend digest emails and month-end budget summaries (you can opt out at any time in Settings → Notifications, or via the unsubscribe link in each email)
- To send you account and billing emails
- To sync your usage data from AI providers on a schedule
- To manage your subscription (trial expiry, Pro status)
- To send the Scout newsletter to visitors who subscribe (opt-in only; one-click unsubscribe in every email)
We do not use provider usage data or credentials to train AI models or sell them to third parties. The public website uses cookieless aggregate Vercel Analytics when deployed on Vercel; it is not used for advertising profiles.
4. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & Auth | Email, encrypted keys, usage data |
| Vercel | Hosting & Cron | Server logs, environment variables |
| Stripe | Payments (international) | Email, payment info |
| Razorpay | Payments (India) | Email, payment info |
| Dodo Payments | Payments (international, Merchant of Record) | Email, payment info, billing address |
| Resend | Transactional email | Email address, alert content |
| Sentry | Error monitoring | Anonymous user id, stack traces, request path (no API keys; PII scrubbed) |
5. Your Rights
You have the right to:
- Access — request a copy of all data we hold about you
- Deletion — delete your account data from settings, subject to records we must retain for legal, fraud, refund, or dispute obligations
- Correction — update your email in account settings
- Portability — export your usage data as CSV from the dashboard
- Objection — contact us at privacy@trytokka.com to object to any processing
Indian users have rights under the Digital Personal Data Protection Act 2023 (DPDP Act). EU/UK users have rights under GDPR/UK GDPR. To exercise any right, email privacy@trytokka.com.
6. Data Retention
- Account data: until you delete your account
- API keys (encrypted): until you disconnect a provider or delete your account
- Usage snapshots: kept while your account is active. After access ends (trial expiry, cancellation), preserved in read-only mode for 30 days, then may be deleted if no paid plan is active.
- Server and application logs: retained under the current hosting and monitoring configuration; retention can differ by service and plan.
- Payment and transaction records: retained as required for applicable accounting, tax, fraud, refund, and dispute obligations.
7. Security
See our Security page for a detailed description of how we protect your API keys. In summary: AES-256-GCM encryption before credential storage, server-memory decryption for authorized provider operations, recorded verification/sync/deletion actions, and HTTPS transport.
8. Cookies
We use essential session cookies (Supabase) and optional error-reporting beacons via Sentry when enabled. We do not set advertising or cross-site tracking cookies. Cookieless aggregate Vercel Analytics may run on the public site when deployed on Vercel — see §3 and the Cookie Policy.
9. Related products (Try family)
TryTokka is the AI API spend product in the Try family under Acsaven (parent brand hub). The canonical product site is trytokka.com. Sister sites — TryQuickImg (tryquickimg.com), TryDevSnip (trydevsnip.com), and TryCalculatingNow (trycalculatingnow.com) — are separate free browser utilities on their official .com domains. They are not affiliated with lookalike brands such as quickimg.org, DevSnips (devsnips.biz), or calculatesnow.com, and those official domains do not redirect to those sites. They do not share your TryTokka account data, API keys, or billing information. See the Try family hub for an overview of all four products.
10. Changes to This Policy
We will notify active users by email if we make material changes to this policy. The “Last Updated” date at the top reflects the most recent revision.
11. Contact
Email: privacy@trytokka.com