1. Introduction
This Privacy Policy explains how Prolific Automation AI LLC ("Company," "we," "us," "our") collects, uses, and protects your personal information when you use toknless. We are committed to protecting your privacy and operating transparently about our data practices.
2. Information We Collect
toknless collects minimal personal information:
2.1 Account Information
- Name and email address — collected when you sign up for a free trial or purchase a subscription
- License key and entitlement data — your unique license identifier and subscription expiry date, stored securely
2.2 Payment Information
- Stripe payment data — when you enter payment details during checkout, Stripe processes and stores that information. Prolific Automation AI LLC never receives, stores, or has access to your credit card numbers or full payment details. Stripe's privacy practices govern payment data.
2.3 Account Memory (On by Default, End-to-End Encrypted)
- User-authored notes and preferences — toknless includes an "Account Memory" feature that syncs your personal notes, settings, and preferences to our cloud servers so they persist across your devices. For licensed users it is on by default, and you can turn it off at any time in the app (Settings → Account Memory → Turn Off Sync). Your source code and project files are never included in Account Memory.
- It is encrypted on your machine before it is uploaded, and we cannot read it. As of version 0.4.1, Account Memory is encrypted end-to-end. The key is derived on your device from your password and a recovery code we show you once and never store. What reaches our database is ciphertext — including the file paths and note titles, not only the note contents. We cannot read your notes, cannot produce them for a support request, and cannot hand a readable copy to anyone who compels us to. This is why the feature can be on by default: leaving it on does not give us access to anything.
- The cost of that, stated plainly. If you lose both your password and your recovery code, your synced Account Memory is gone. There is no reset, no admin override, and no copy on our side we can decrypt for you. Your local notes on your own machine are unaffected — this applies only to the synced copy. That is the direct and unavoidable price of us not holding the key.
- What we can still see — encryption hides contents, not the fact of storage. We can see which account the records belong to, how many there are, how large they are, and when each last changed. We cannot see what is in them or what they are called.
- Before version 0.4.1, Account Memory was stored in our database in readable form. If you used it before that release, your existing records are converted to encrypted ones automatically the first time you sign in to 0.4.1 or later, and the readable copies are deleted at that point.
2.4 License Verification Pings
- License key — toknless periodically sends your license key to our servers to verify your subscription is active. That is the whole contents of the ping: no app version, no device or system details, no usage data. Pings are made over HTTPS, and individual pings are not logged (see §5).
2.5 Crash Reports (Optional, Off by Default)
- You turn these on — we do not. toknless sends no crash reports unless you enable them. The app asks you once, plainly, the first time you use it, and declining is remembered — we will not ask again. You can also change the setting yourself at any time (Settings → Crash Reports). They are off in a fresh install, off if you decline or never answer, and off after an update.
- What a report contains — when crash reports are on and the app hits an error it cannot recover from, we receive the error message, the JavaScript stack trace, the app version, your operating system and architecture, which screen you were on (for example "session" or "landing"), and the time it happened.
- What a report does not contain — your source code, file contents, prompts, session transcripts, API keys, credentials, license key, name, or email address. Reports carry no account identifier, so we cannot link one back to you.
- One honest caveat — an error message is written by our code, but it can quote a value it was working with, such as a project name or a file path. We cannot rule that out in advance. Reports are used only to fix the defect and are deleted after 90 days (see §5).
2.6 What We Do NOT Collect
- Your API keys or credentials — toknless runs your own Claude Code with your own credentials; we never store or transmit those, and no optional feature changes that
- Usage analytics — we do not track how you use the app, what you build, or how often you open it. There is no telemetry, no session recording, and no product analytics of any kind.
- Your source code, project files, session history, or conversation logs — toknless runs locally and does not upload them. The only thing that could ever change this is Encrypted Sync (§2.7), which does not exist yet, would be off unless you turned it on, and would send us ciphertext we cannot read rather than your work.
The only diagnostic data we ever receive is a crash report, and only if you switch it on yourself (see §2.5).
2.7 Encrypted Sync (Optional, Off by Default — Not Yet Available)
- This feature does not exist yet. No released version of toknless syncs your project files or session history, and none ever has. We are publishing this section before writing the code, so the commitments below are on the record ahead of the feature rather than written afterwards to describe whatever got built. The encryption they describe is not hypothetical — it is the same machinery Account Memory already uses (§2.3). What has not shipped is extending it to your project files and session history.
- You would turn it on — we would not. If and when Encrypted Sync ships, it will be off in a fresh install, off after an update, and off unless you switch it on yourself. Declining is not a downgrade: everything toknless does today, it keeps doing with sync off.
- End-to-end encrypted, in the strong sense. Encryption and decryption would happen on your machine, under a key derived from your password and a recovery code you save. That key never reaches us. What we would receive and store is ciphertext — including file paths and project names, not only file contents. We could not read your code or your transcripts, could not produce them for a support request, and could not hand a readable copy to anyone who compelled us to.
- The cost of that, stated plainly. If you lose both your password and your recovery code, your synced data is gone. There is no reset, no admin override, and no copy on our side we can decrypt for you. That is the direct and unavoidable price of us not holding the key.
- What sync would never include — your API keys and provider credentials. Those stay on your machine and are not part of sync at all (§2.6).
- What we would still be able to see — encryption hides contents, not the fact of storage. We would see which account the records belong to, how many there are, how large they are, and when each last changed. We would not see what is in them or what they are called.
3. How We Use Your Information
We use the information collected for the following purposes:
- Delivering and supporting toknless (account creation, license verification, bug fixes)
- Processing payments and managing your subscription (via Stripe)
- Communicating with you about your account, updates, or policy changes
- Syncing and storing your Account Memory records, which are encrypted before they reach us (§2.3). We store and return ciphertext and nothing else — we cannot process, analyze, or train on contents we are unable to decrypt.
- Storing and serving your encrypted records if you ever turn on Encrypted Sync (§2.7). We would store and return ciphertext and nothing else — we cannot process, analyze, or train on contents we are unable to decrypt.
- Diagnosing and fixing crashes, if you have turned on crash reports (§2.5). We do not use crash reports for any other purpose.
- Complying with legal obligations
- Improving toknless (analyzing aggregate, anonymized usage trends)
We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes.
4. Sub-Processors and Third-Party Services
To operate toknless, we work with the following service providers ("Sub-Processors"):
4.1 Stripe
Purpose: Payment processing. Stripe is PCI DSS Level 1 certified and compliant with international payment security standards. Stripe stores and processes your payment method details according to Stripe's privacy policy (stripe.com/privacy).
4.2 GoHighLevel
Purpose: Transactional email delivery and account communications. We send you license keys, subscription confirmations, and account notifications via GoHighLevel. GoHighLevel has access to your email address and the content of transactional emails.
4.3 Fly.io
Purpose: Backend hosting for toknless cloud services (license verification, Account Memory sync). Fly.io is a cloud infrastructure provider certified under SOC 2. Your data is hosted in Fly.io's data centers (US region by default).
4.4 Turso
Purpose: Database hosting for license keys, Account Memory, and user entitlements. Turso is built on SQLite and hosted on Fly.io infrastructure. Account Memory records stored here are ciphertext (§2.3), so neither Turso nor we can read them. The same is true of the records Encrypted Sync would store if it ships (§2.7).
4.5 Vercel
Purpose: Hosting the toknless website (toknless.io). Vercel may collect IP addresses and basic usage data as part of standard web hosting. Vercel's privacy practices are available at vercel.com/privacy.
4.6 Cloudflare
Purpose: DNS, CDN, and download hosting for toknless binaries (via Cloudflare R2). Cloudflare may process your IP address and basic request metadata. Cloudflare's privacy practices are available at cloudflare.com/privacy.
5. Data Retention
- Account information: Retained for the duration of your subscription and for 12 months after cancellation (for legal and billing records).
- Account Memory: Retained as long as your account is active. If you request deletion (see §6), Account Memory is deleted within 30 days. Because we hold only ciphertext, deletion is the only operation we can perform on it — we cannot inspect or export the contents on your behalf.
- License verification logs: Aggregate license verification data is retained for 90 days; individual pings are not logged.
- Encrypted Sync data (§2.7): Retained while your account is active. Turning sync off stops new records and lets you delete what is stored; a deletion request under §6.2 removes it within 30 days. Because we hold only ciphertext, deletion is the only operation we can perform on it — we cannot inspect or export the contents on your behalf.
- Crash reports: Retained for 90 days, then deleted. Because reports carry no account identifier, we cannot single yours out to delete on request — turning crash reports off stops any further reports, and the ones already sent age out on the same 90-day schedule.
- Payment data: Retained by Stripe according to Stripe's retention policy (typically 7+ years for PCI compliance).
6. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
6.1 Right of Access
You have the right to request a copy of all personal information we hold about you, including your license records and the account details in §2.1. To submit a data access request, email support@prolificautomation.ai with the subject line "Data Access Request."
One honest limit: we cannot export your Account Memory contents, because we cannot read them (§2.3). What we can provide is what we actually hold — the number of records, their sizes, and when each last changed. Your readable notes live in the app on your own machine, which is where you can always reach them.
6.2 Right to Deletion
You have the right to request that we delete your personal information, including Account Memory. We will delete your data within 30 days of a verified deletion request, except where we are legally required to retain it (e.g., for tax records). To request deletion, email support@prolificautomation.ai with the subject line "Delete My Data."
6.3 Right to Correct
You may request correction of inaccurate personal data. To update your name, email, or other account details, email support@prolificautomation.ai or update your information in your account settings (if available).
6.4 Right to Opt Out
Account Memory sync is on by default for licensed users, and you may disable it at any time in the app: Settings → Account Memory → Turn Off Sync. This stops future records from being stored in our cloud and keeps your notes on your machine only; records already stored are retained until you delete them, which you can do from the same screen or by requesting deletion (see §6.2).
Crash reports require no opt-out because they are off unless you turn them on. If you have turned them on, switch them back off at any time in the app: Settings → Crash Reports → Turn Off.
Encrypted Sync (§2.7) requires no opt-out today because it does not exist. When it ships it will be off unless you turn it on, and switching it off will stop further syncing and offer to delete what is already stored.
7. Data Location and Cross-Border Transfers
Your personal data is primarily stored in the United States (Fly.io US region, Vercel US infrastructure, Cloudflare US/global). If you are located in the EU or another jurisdiction with data residency requirements, your data may be transferred to the United States. By using toknless, you consent to such transfers. If data transfers require additional safeguards under GDPR or similar laws, we will work with you to put standard contractual clauses or other approved mechanisms in place.
8. Security
We implement industry-standard security measures to protect your personal information:
- HTTPS encryption for all data in transit
- Encrypted storage for sensitive data (license keys, Account Memory)
- Access controls limiting employee access to personal data
- Regular security audits and vulnerability testing
- End-to-end encryption for Encrypted Sync when it ships (§2.7) — keys are derived on your machine from your password and your recovery code, and are never sent to us. The practical consequence runs both ways: a breach of our database would expose ciphertext rather than your work, and losing both your password and your recovery code means nobody, including us, can recover the data.
However, no security system is 100% secure. We cannot guarantee absolute protection against unauthorized access, and you use toknless at your own risk.
9. Cookies and Tracking
The toknless website (toknless.io) may use essential cookies for session management and security. We do not use tracking cookies or third-party analytics by default. If we introduce analytics in the future, we will update this policy and obtain your consent.
10. Children's Privacy
toknless is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided personal data, we will delete it promptly. Parents or guardians who believe their child's information has been collected should email support@prolificautomation.ai.
11. California Privacy Rights (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected and how it is used
- Right to delete personal information (subject to legal exceptions)
- Right to opt out of the sale or sharing of personal information (we do not sell your data)
To exercise these rights, email support@prolificautomation.ai with "California Privacy Rights" in the subject line.
12. European Privacy Rights (GDPR)
If you are located in the European Union or European Economic Area, your personal data is processed under GDPR. Your rights include:
- Right of access, rectification, and erasure (as detailed in §6)
- Right to restrict processing
- Right to data portability (we will provide your data in a structured format upon request)
- Right to object to processing
- Right to lodge a complaint with your national data protection authority
Our legal basis for processing your data is your consent (account creation and use of toknless) and the necessity to perform our contract (providing the service and processing payments). To exercise GDPR rights, email support@prolificautomation.ai.
13. Changes to This Privacy Policy
We may update this policy to reflect changes in our data practices. Material changes will be communicated to you via email. Continued use of toknless after updates constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy, or to exercise your privacy rights, please contact us at:
- Email: support@prolificautomation.ai
- Company: Prolific Automation AI LLC, Michigan, USA