← Back to SaveToken

Privacy Policy

Last updated: 2026-09-06.

1. What we collect from your API requests

When you call /v1/optimize, we process the text you send in memory to produce the reduced output. We do not store the content of your requests or responses. Verified in our own code: nothing from a request body is written to disk or logged anywhere in our processing pipeline.

2. What we do store

Per API call, we store: token counts (in/out), dollars saved, the transform used, and a pass/fail verdict — for your own usage dashboard and billing. Any free-text warning message is passed through a secret-redaction filter before storage. We never store your downstream LLM provider's API key.

3. Account and billing data

We store your API key (hashed, never in plain text), tenant ID, and plan tier. Payment details (card, billing address) are collected and processed entirely by Paddle, our payment processor — we never see or store your card details.

4. Free-tier identification

To enforce free-tier abuse limits (20 key mints per IP per day), we store your IP address with a timestamp each time you mint a free key. We do not otherwise track or store IP addresses.

5. Third parties

Paddle (payment processing, tax, invoicing) is the only third party we share billing-related data with. We use PostHog to understand site traffic (see Cookies below). We do not sell personal data, and we do not use your request content to train any model.

6. Cookies

When you sign in to the dashboard, we set one essential, first-party session cookie (__Host-session) so you stay logged in. It is a signed token that identifies your session, expires after three days, and is not shared with anyone.

We use PostHog to see how visitors find and use this site (pages viewed, traffic source, general location), configured not to set cookies or use browser storage. We do not use advertising cookies, and we do not use your request content for analytics.

7. Children's data

SaveToken is a developer/business API and is not directed at, or knowingly used to collect data from, children.

8. Changes to this policy

We may update this policy; continued use of the Service after an update constitutes acceptance.

9. Contact

SaveToken, c/o Invictus International Consulting Services, Gurugram, Haryana, India. Contact: contact@savetoken.org