Privacy Policy

Effective date: April 24, 2026

AiTokens (“we,” “our,” or “us”) operates aitokens.app. This policy explains what personal data we collect when you use the platform, why we collect it, and what rights you have over it. We keep this plain-English — no legalese.

1. What data we collect

We collect only what is necessary to operate the service:

  • Account email address. Collected at sign-up via Firebase Authentication (Google OAuth or email/password). Used to identify your account and send billing notifications.
  • Firebase Auth metadata. Sign-in timestamp, user ID, and authentication provider. Used for account security and to enforce session expiry.
  • Stripe customer ID and subscription state. When you subscribe to a paid tier, Stripe generates a customer ID that we store to link your account to your subscription. We never store your card number, CVV, or any payment instrument details — that data lives on Stripe’s servers only.
  • Watchlist contents. The tokens you add to your watchlist are stored against your user ID so they persist across sessions.
  • Page analytics (future). If we add Vercel Analytics or a similar provider, aggregated, anonymized page-view data may be collected to understand which parts of the platform are most used. We will update this policy before activating any analytics tool.

2. How we use it

  • Account management. Authenticating you, enforcing subscription tier access, and allowing you to manage your account settings.
  • Billing. Processing subscription payments, handling upgrades and cancellations, and sending billing receipts via Stripe.
  • Product analytics. Understanding aggregate platform usage to prioritize features. We do not build individual behavioral profiles for advertising.
  • Service communications. Sending transactional emails (subscription confirmation, renewal reminders, material policy updates). We do not send marketing email without explicit opt-in.

We do not sell your personal data to third parties. Ever.

3. Subprocessors (who else touches your data)

We use these third-party services to operate the platform. Each is under contract to handle your data only for the purposes we specify:

  • Google Firebase (Authentication, Firestore, Cloud Functions, Hosting) — account identity, data storage, and server-side logic. Data is stored in the us-east4 (Virginia) region.
  • Stripe — payment processing, subscription management, and the customer self-service billing portal. Stripe is PCI-DSS Level 1 certified. We operate as a SAQ-A merchant: card data never touches our servers.
  • Email newsletter provider (future) — if and when we launch a newsletter, we will name the provider here and update this policy before any email list is created.

4. Cookies and local storage

We use a minimal set of browser storage mechanisms:

  • Firebase Auth session cookie. Set automatically when you sign in. Required for authentication to function. This is a strictly necessary cookie — no consent banner is required.
  • Theme preference (aitokens-theme) — stored in localStorage. Remembers your light/dark mode choice. Contains no personal data.
  • Privacy mode preference (aitokens-privacy) — stored in sessionStorage. Remembers whether you have activated the financial data blur feature. Cleared when you close the browser tab. Contains no personal data.

We do not use advertising cookies, cross-site tracking pixels, or fingerprinting. No consent banner is required for the above — these are functional and strictly necessary under GDPR Article 5(3).

5. Data retention

  • Account data is retained while your subscription is active and for 90 days after cancellation, to allow for reactivation and to fulfill any outstanding support requests.
  • Billing records (Stripe transaction IDs, subscription history) are retained for seven years as required by U.S. IRS recordkeeping rules.
  • Cloud Functions logs (including IP addresses) are retained for 90 days by Google Cloud’s default logging policy.

If you delete your account, we delete your Firestore document and Firebase Auth record within 30 days. Billing records are retained for the statutory period only.

6. Your rights

Depending on where you are, you may have the following rights over your data:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Ask us to correct inaccurate data.
  • Deletion. Request that we delete your account and associated personal data (subject to legal retention requirements above).
  • Portability. Receive your data in a machine-readable format.
  • Objection / opt-out. CCPA consumers can request that we not sell their personal information — we do not sell data, so this right is already satisfied by default.

To exercise any of these rights, email privacy@aitokens.app. We will respond within 30 days. We may ask you to verify your identity before processing the request.

7. Children

AiTokens is not intended for users under 13 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us at privacy@aitokens.app and we will delete it immediately.

8. Policy updates

When we make material changes to this policy, we will notify active subscribers via email at least 14 days before the changes take effect. The effective date at the top of this page is updated on every revision. Continued use of AiTokens after the effective date constitutes acceptance of the updated policy.

9. Contact

For privacy questions, data subject requests, or security reports, contact us at privacy@aitokens.app.