Privacy Policy
Last updated: 4 August 2026
This policy explains what information Token Optimiser collects, how it is used, and who it is shared with. It describes the service as it actually works today — where something is not yet built, or not yet finalised, we say so directly rather than describing planned functionality as if it already existed.
1. Who operates Token Optimiser
Token Optimiser is a product operated by Karo Data Consultancy London Ltd, a company registered in England and Wales under company number 12855884.
Registered office:
Office 403, Screenworks22 Highbury GroveLondonUnited KingdomN5 2ERFor any privacy question, or to make a request about your personal information, contact us at karodataconsultancy@gmail.com.
2. Information we collect
We collect two distinct kinds of information: account data, and prompt/product data.
Account data
- Your account email address — sourced from Supabase Auth (the magic-link email you sign in with, or the email provided by Google/Facebook if you sign in that way). This remains the single authoritative source for your email everywhere in the product.
- Your Supabase authentication identifier (an internal account ID).
- Profile details completed during onboarding, and editable afterwards on the Account page: first name, last name, and a preferred AI model — all three are required to complete onboarding. Date of birth is always optional.
- A server-maintained copy of your account email stored alongside your profile. This copy is used for account administration and, only where you have given marketing consent, for managing marketing recipients — you cannot edit it directly, and it is kept automatically in sync with your Supabase Auth email.
- A record of your Terms & Conditions acceptance and Privacy Policy acknowledgement: the date/time of each, which version of this policy and the Terms you accepted, and the source it was captured from (e.g. onboarding).
- Your marketing-email consent choice: whether you are currently opted in, the date/time you last opted in or out, and which version of the consent wording applied when you opted in.
- Your cookie/analytics consent choice and which version of our consent settings it was made under.
Prompt/product data
- The original prompt text you submit to be optimised.
- The optimised prompt our system produces from it.
- Your prompt history (a record of past optimisations, tied to your account).
- Token counts (original, optimised, and saved) and the optimisation style/model target you selected for that run.
- Estimated API cost savings and the pricing methodology used to calculate them (see “Estimated savings” in our Terms).
- Usage and quota counters (e.g. how many optimisations you have run this month), used to enforce plan limits and basic rate limiting.
- Timestamps for when these records were created.
Preferences (stored on your device only)
- Your default optimisation style and model target, if set on the Preferences page — stored in your browser's local storage, not on our servers.
We do not collect payment information — Token Optimiser does not currently process payments (see our Terms & Conditions).
3. How we use this information
- To provide authentication and keep you signed in.
- To run the prompt-optimisation feature and return a result to you.
- To save and display your prompt history.
- To calculate and display your token and estimated cost savings.
- To enforce plan usage limits and basic request rate limiting.
- To remember your preferences.
- To operate, maintain, and improve the service, and to help prevent abuse of it.
- To keep a durable record of your Terms acceptance and Privacy acknowledgement, including when and under which version.
- Where you have opted in, to send you product update and marketing emails — see “Marketing emails” below.
- Where you have given analytics consent, to understand aggregate product usage (see “Analytics” below).
We do not use your information for advertising, ad targeting, or building an advertising profile of you.
4. Marketing emails
Choosing to receive marketing emails (product updates and similar communications) is entirely optional. It is separate from, and never a condition of, creating an account, completing onboarding, or accepting these Terms — declining does not affect your access to the service in any way.
We do not currently operate a marketing email sending system. Opting in records your consent for when such communications begin — it does not mean you will receive marketing emails immediately, or that any have been sent to date.
You can change this choice at any time from Account settings. Once marketing emails are actually being sent, each one will also include its own unsubscribe control, independent of the Account settings toggle.
5. How your prompts are processed
Token Optimiser's optimisation feature currently runs entirely through our own deterministic, rule-based optimisation logic, executed on our own servers. As of the date of this policy, we do not send your original prompt to OpenAI, Anthropic, Google Gemini, xAI (Grok), or any other external AI model provider — Token Optimiser does not currently integrate with any third-party AI model API at all.
When you choose a “model target” (for example, Claude, ChatGPT, Gemini, or Grok), that selection currently changes only: (a) the formatting conventions our own optimiser applies when producing your optimised prompt, and (b) which published reference rate we use to estimate your cost savings for that model family. It does not mean your prompt is submitted to that provider, and choosing a model target does not create any relationship between you and that provider through our service.
This section describes how the service works today. We may introduce integrations with third-party AI providers in the future to add new functionality. If we do, we will update this policy, and this section specifically, before that processing begins.
6. Storage
Your account data, original prompts, optimised prompts, and related optimisation metadata are stored in our database, provided by Supabase. Connections to our service use standard HTTPS encryption in transit; beyond that, we are not making specific technical claims about additional encryption or security measures in this policy.
You can delete a single saved optimisation, or all of your optimisation history, at any time from the History page — this removes the original and optimised prompt text and related metadata for the item(s) you choose, immediately and permanently. You can also delete your entire account from the Account page (see “Your rights” below for exactly what that removes).
Outside of a deletion you request yourself, we do not currently operate a formal data-retention schedule or automatic-deletion process for prompt or history data — there is no scheduled cleanup that removes it after a fixed period on its own. In practice, this means data you have not deleted is retained indefinitely. We are flagging the absence of an automatic retention schedule as an open item, not something already resolved — see the launch-compliance notes accompanying this policy's introduction for more detail if you are reviewing this as part of a compliance process.
7. Processors and other services we use
- Supabase — provides our authentication system and database. Account data and all prompt/product data described above is stored with Supabase.
- Vercel— hosts and runs the application itself. Request data passes through Vercel's infrastructure as part of serving the service to you.
- Vercel Web Analytics— collects anonymous page-view information about how the site is used (see “Analytics” below). This currently runs at all times, independent of your cookie/analytics consent choice.
- Google Analytics (GA4)— collects product usage analytics, but only after you give analytics consent (see “Analytics” below and our Cookie Policy).
We do not share your prompt content with any AI model provider — see “How your prompts are processed” above.
8. Analytics
Google Analytics (GA4)is optional. It is not loaded, and does not run, until you affirmatively accept analytics in our cookie consent banner or Cookie preferences. You can withdraw this consent at any time from “Cookie preferences” (see our Cookie Policy for exactly how this works, including what we do to stop analytics collection after you withdraw consent).
Vercel Web Analytics currently runs unconditionally, for every visitor, independent of the cookie/analytics consent described above. Based on our review of how it is configured, it is cookieless and does not receive any Token Optimiser-specific custom event data — but we are not treating that as a final legal conclusion about whether consent should apply to it. Whether Vercel Web Analytics requires the same consent treatment as GA4 is flagged as an open item for professional legal review, not something this policy resolves on its own.
9. Your rights
Depending on where you live, you may have rights over your personal information — for example, to ask what we hold about you, request a copy of it, ask us to correct inaccuracies, or ask us to delete it.
You can already do some of this yourself: edit your personal profile details on the Account page, withdraw marketing-email consent at any time from Account settings, delete a single optimisation or all of your optimisation history from the History page, and delete your account entirely from the Account page. Deleting your account removes your profile, your optimisation history, and your usage/quota data, and then removes your Token Optimiser sign-in itself — see “How your prompts are processed” and our Terms for what this does and does not affect.
Token Optimiser does not yet have a self-service way to export a copy of your data. For that, or for any other privacy request, please contact us at karodataconsultancy@gmail.com and we will respond appropriately. We are not stating a specific response timeframe in this policy — this is flagged for professional legal review rather than asserted here without basis.
10. International processing
Our service providers (including Supabase, Vercel, and Google) may process or store information outside the United Kingdom. We have not independently documented the exact locations involved or the specific legal transfer mechanism that applies for every provider. This is flagged as an item for professional legal review, rather than described in detail here without that verification.
11. Retention
As described in “Storage” above, we do not currently operate a formal retention schedule. We are flagging the absence of a documented retention schedule as an item that requires attention alongside professional legal review, rather than inventing specific retention periods that are not yet true of how the product actually works.
12. Changes to this policy
We may update this policy from time to time to reflect changes to the product or to legal requirements. When we do, we will update the “Last updated” date at the top of this page. We do not currently have an automated notification system (for example, an email) for policy changes — if you have an account, we'd encourage you to check this page periodically.
© 2026 Token Optimiser • Operated by Karo Data Consultancy London Ltd