legal ยท privacy policy

Privacy Policy

Last updated 2026-05-12. Questions: support@limitlesstokens.com.

At a glance

This Policy applies to the AdToken service operated at limitlesstokens.com, the AdToken CLI, the AdToken browser extension, and any AdToken-branded subdomain ("the Service"). Effective 2026-05-12.

1. Categories of Personal Information collected (CCPA framework)

The California Consumer Privacy Act, as amended by the CPRA, defines eleven categories of Personal Information. The table below maps each to what AdToken actually collects.

Sensitive Personal Information (CPRA ยง 1798.140(ae)): we do not knowingly collect SPI. Magic-link emails are used only for authentication; we do not treat them as SPI.

2. Sources of Personal Information

3. Purposes of processing and legal bases (GDPR Article 6)

For users in the EEA, UK, or Switzerland, the GDPR / UK GDPR requires us to state the lawful basis for each processing purpose.

4. Disclosures to third parties (CCPA + GDPR)

We disclose Personal Information to the categories of recipients below, strictly for the purposes stated. Each is bound by a data-processing or services agreement that limits use to providing services to AdToken.

Disclosures for business purposes (CCPA ยง 1798.140(d)): in the 12 months preceding the effective date of this Policy, we disclosed categories (A), (D), (F), (G), and (J) for the business purposes identified in ยง 3 above to the recipients listed in this ยง 4. No other categories were disclosed for business purposes.

5. We do not sell or share Personal Information

We do not "sell" Personal Information for monetary or other valuable consideration as defined by the CCPA / CPRA, the Virginia VCDPA, the Colorado CPA, the Connecticut CTDPA, the Utah UCPA, the Texas TDPSA, or any other state-level privacy law. We do not "share" Personal Information for cross-context behavioral advertising. We have not sold or shared Personal Information in the 12 months preceding this Policy. We do not knowingly sell or share the Personal Information of minors under 16.

If this ever changes, we will update this Policy, give clear advance notice, and provide a "Do Not Sell or Share My Personal Information" mechanism. The link at the bottom of every page reflects this current state.

6. Financial incentive notice (CCPA ยง 1798.125)

AdToken offers a "financial incentive": you receive Tokens (each redeemable for 1ยข of LLM API credit) in exchange for watching ads, completing surveys, or clicking affiliate links. This is a fair-value exchange โ€” the Tokens reflect a reasonable share of the advertising revenue your engagement generates, less infrastructure costs. We do not condition basic access to the Service on participation, you may withdraw from the program at any time by simply not earning further Tokens, and we do not charge a different price or deny service if you opt out.

7. Cookies and tracking technologies

We use the minimum number of cookies necessary to operate the Service. We do not load Google Analytics, Meta Pixel, fingerprinting libraries, or any other third-party tracker.

All cookies above are first-party except as noted. Strictly-necessary cookies do not require consent under the GDPR / ePrivacy Directive. We do not use non-essential cookies.

8. Retention

When the purpose for which Personal Information was collected ends, we delete or de-identify it within a reasonable period.

9. Your rights

9.1 Rights available to all users

9.2 EEA / UK / Switzerland (GDPR + UK GDPR)

9.3 California (CCPA / CPRA)

9.4 Virginia / Colorado / Connecticut / Utah / Texas / Oregon / Montana / Tennessee / others

Residents of these states have substantially equivalent rights (access, correct, delete, portability, opt-out). Submit a request via the same email below and identify which state's law applies.

9.5 How to exercise your rights

Send a request to support@limitlesstokens.com from the email linked to your wallet, or via signed authorized agent. We will:

10. Automated decision-making

AdToken does not make decisions about you that produce legal or similarly significant effects through solely automated processing. Abuse-detection rate-limits are rule-based (e.g. "more than N completions per minute from one IP") and do not produce legally or substantially significant effects on you โ€” at worst, a temporary rate-limit on the offending IP, reversible by support contact. Per GDPR Art 22, you may request human review of any rate-limit or wallet-suspension decision.

11. International transfers

Our servers and data stores are located in the United States (Fly.io regions in IAD / SJC). When you use the Service from outside the US, your Personal Information is transferred to and processed in the US.

For transfers from the EEA, UK, or Switzerland, we rely on:

You may request a copy of the SCC mechanism we rely on for any specific processor by emailing the contact in ยง 14.

12. Children

The Service is not directed to children under 13 (under 16 in the EEA/UK). We do not knowingly collect Personal Information from children below that age. If we learn we have collected such information, we will delete it promptly and, where required, notify a parent or guardian. Parents or guardians who believe their child has provided us with Personal Information may contact support@limitlesstokens.com for review and deletion.

13. Security and data-breach commitment

We employ industry-standard technical and organizational measures including TLS 1.2+ in transit, encrypted volume storage at rest, hashed sessions, CSPRNG-generated tokens, rate-limited authentication, and restricted operator-side access. The proxy code is open source for independent review.

No system is perfectly secure. If we become aware of a Personal Information breach that creates a risk to your rights or freedoms, we will:

14. Contact, complaints, and successor in interest

Privacy questions, rights requests, complaints: support@limitlesstokens.com. We aim to respond within 10 business days.

Supervisory-authority complaints (EEA / UK / Switzerland users): see ยง 9.2 for direct links.

Successor in interest: if AdToken is acquired, merged, restructured, or sold, your Personal Information may transfer to the successor entity as a business asset, subject to commitments at least equivalent to this Policy. We will notify users in-product before any such transfer where reasonably practical.

15. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top of the page reflects the most recent revision; the version history is in our public repository (commit log of src/server.ts). For material changes that affect your rights, we will give notice in-product before the change takes effect and, where required by law, obtain renewed consent.

16. Limits of this document

This Policy is drafted by the operator and is intended to be accurate, complete, and compliant with the laws cited. It is not legal advice. For specific legal questions about how this Policy applies to your particular situation, please consult an attorney licensed in your jurisdiction.

Do Not Sell or Share My Personal Information ยท Terms of Use