DRAFT — FOR ATTORNEY REVIEW — NOT YET IN EFFECT This document is an unreviewed working draft. It does not bind limitlesstokens or its users and should not be relied on. Bracketed PLACEHOLDER items are open questions flagged for counsel.
limitlesstokens /privacy

Privacy Policy

Working draft · limitlesstokens.com · last edited by product, pending legal

This policy describes what limitlesstokens collects, why, and what we deliberately do not collect. The guiding principle: we run on anonymized survey/task data and sponsor content, not on surveilling your code or your conversations with Claude.

1. What We Collect

2. What We Explicitly Do NOT Collect

We do not collect the prompt or completion content of your Claude turns. This is a hard line in how the product is built.

3. How We Use Data

4. Data Retention & Redaction

The financial ledger is append-only and retained for accounting, audit, and fraud-prevention integrity; we do not delete ledger entries. Personally identifying information (such as your email) is redactable on request — a redaction path exists that scrubs PII while preserving the integrity of the append-only financial record. Survey and task content is retained in anonymized form for research.

5. Sharing & Processors

6. Your Rights

7. Security

Passcodes are stored only as one-way scrypt hashes. Wallet ids are treated like API keys: they key your wallet, ledger, and account records (and are additionally captured in an internal, access-controlled administrative audit trail used for fraud investigation and abuse response), but they are never echoed to other users or shared externally. Traffic to the proxy is over TLS. Local credential files are written with restrictive permissions. For account-holding wallets, short-lived session tokens mean that possessing a bare wallet id alone is no longer full account control; note that a session token, if leaked, remains replayable until it expires. Database backups are configured for point-in-time recovery.

8. Contact

Questions or requests (including redaction): privacy@limitlesstokens.com PLACEHOLDER — attorney: confirm contact address, mailing address if required, and any jurisdiction-specific notice requirements.

limitlesstokens.com · Terms · Privacy · we never read your prompts