At a glance
- Controller: Henry Tushman, sole operator of AdToken / limitlesstokens.com. Contact: support@limitlesstokens.com.
- What we collect: wallet ID, optional email, ad-completion events, LLM-call metadata (NOT prompt content by default), IP for security.
- What we do NOT do: we do not sell or share Personal Information; we do not run cross-site tracking; we do not store prompts unless you opt in.
- Your rights: access, correction, deletion, portability, withdrawal of consent, opt-out of any future selling/sharing, complaint to a supervisory authority. See ยง 9.
- Verifiability: our proxy code is open source at github.com/henrytushman-ctrl/adtoken. You can compare any claim below against the actual implementation.
This Policy applies to the AdToken service operated at limitlesstokens.com, the AdToken CLI, the AdToken browser extension, and any AdToken-branded subdomain ("the Service"). Effective 2026-05-12.
1. Categories of Personal Information collected (CCPA framework)
The California Consumer Privacy Act, as amended by the CPRA, defines eleven categories of Personal Information. The table below maps each to what AdToken actually collects.
- (A) Identifiers โ wallet ID (
adt_<hex>, opaque), optional linked email, magic-link session cookie, IP address (transient).
- (B) Customer records (ยง 1798.80(e)) โ none beyond (A).
- (C) Characteristics of protected classifications โ none.
- (D) Commercial information โ Token balance, ad-completion ledger, LLM-call metering ledger (model, token counts, cost in cents, timestamp).
- (E) Biometric information โ none.
- (F) Internet or other electronic network activity โ IP address (transient), user-agent string (in webhook logs), HTTP request paths to our service.
- (G) Geolocation data โ country-level only, inferred from IP for rate-limiting and abuse detection. We do not collect precise geolocation.
- (H) Sensory information โ none.
- (I) Professional or employment-related information โ none.
- (J) Non-public education information (FERPA) โ only your
.edu domain (if you sign up with one) โ used solely to confirm student-eligibility for the default signup tier.
- (K) Inferences โ none. We do not build profiles, predict preferences, or model individual users.
Sensitive Personal Information (CPRA ยง 1798.140(ae)): we do not knowingly collect SPI. Magic-link emails are used only for authentication; we do not treat them as SPI.
2. Sources of Personal Information
- Directly from you โ when you create a wallet, log in with email, click an affiliate link, or post an LLM request.
- From your device / browser โ IP and user-agent on every HTTP request, automatically.
- From third-party ad networks โ webhook callbacks from AppLixir, CPX Research, and similar partners report which ad-completion event maps to your wallet ID.
3. Purposes of processing and legal bases (GDPR Article 6)
For users in the EEA, UK, or Switzerland, the GDPR / UK GDPR requires us to state the lawful basis for each processing purpose.
- Operate the proxy + bill your wallet โ relay prompts to upstream model providers, count tokens, debit cents. Basis: performance of a contract (Art 6(1)(b)) โ necessary to provide the Service you are using.
- Credit ad views + affiliate clicks โ record ad-completion events from network partners, increment your Token balance. Basis: performance of a contract (Art 6(1)(b)).
- Send magic-link login emails โ deliver one-time codes to authenticate you. Basis: performance of a contract (Art 6(1)(b)).
- Detect and prevent abuse โ rate-limit IPs, block replay attacks, refuse forged ad-completion postbacks. Basis: legitimate interest (Art 6(1)(f)) โ securing the Service against fraud, weighed against minimal user-data use.
- Improve the Service via prompt observation โ only for users who have affirmatively opted in. Basis: explicit consent (Art 6(1)(a)) โ withdrawable at any time without affecting prior lawful processing.
- Comply with legal obligations โ respond to valid legal process, retain records as required. Basis: legal obligation (Art 6(1)(c)).
4. Disclosures to third parties (CCPA + GDPR)
We disclose Personal Information to the categories of recipients below, strictly for the purposes stated. Each is bound by a data-processing or services agreement that limits use to providing services to AdToken.
- Fly.io (hosting + persistent SQLite volume) โ receives all data stored by the Service in the ordinary course of hosting. Categories: (A), (D), (F), (J). Policy.
- Vercel AI Gateway (LLM router) โ receives the contents of LLM requests and returns responses, plus per-request metering metadata. Vercel forwards prompts to the underlying model provider. Categories: (A), (D), (F), and the contents of any prompts you send. Policy.
- Upstream model providers (Anthropic, OpenAI, DeepSeek, Meta, Qwen, Google via Gateway, etc.) โ receive the contents of LLM requests via Vercel AI Gateway. Each provider's policy governs prompt-content processing in their hands. We surface the active model on every response via the
x-adtoken-fallback-model header.
- Ad and survey networks (AppLixir, CPX Research, and similar partners we may add) โ receive the wallet ID and IP at completion time so they can attribute the reward to the correct wallet. Categories: (A), (F), (G).
- Resend (transactional email) โ receives your email address solely to deliver magic-link codes. Category: (A). Policy.
- Stripe (payment processor) โ used only for sponsor-side payments (advertisers paying AdToken). End-user wallets do not pass data to Stripe. Policy.
- Law enforcement and regulators โ where required by valid legal process, we may disclose information necessary to respond. We narrowly construe such requests and notify users where lawful.
Disclosures for business purposes (CCPA ยง 1798.140(d)): in the 12 months preceding the effective date of this Policy, we disclosed categories (A), (D), (F), (G), and (J) for the business purposes identified in ยง 3 above to the recipients listed in this ยง 4. No other categories were disclosed for business purposes.
5. We do not sell or share Personal Information
We do not "sell" Personal Information for monetary or other valuable consideration as defined by the CCPA / CPRA, the Virginia VCDPA, the Colorado CPA, the Connecticut CTDPA, the Utah UCPA, the Texas TDPSA, or any other state-level privacy law. We do not "share" Personal Information for cross-context behavioral advertising. We have not sold or shared Personal Information in the 12 months preceding this Policy. We do not knowingly sell or share the Personal Information of minors under 16.
If this ever changes, we will update this Policy, give clear advance notice, and provide a "Do Not Sell or Share My Personal Information" mechanism. The link at the bottom of every page reflects this current state.
6. Financial incentive notice (CCPA ยง 1798.125)
AdToken offers a "financial incentive": you receive Tokens (each redeemable for 1ยข of LLM API credit) in exchange for watching ads, completing surveys, or clicking affiliate links. This is a fair-value exchange โ the Tokens reflect a reasonable share of the advertising revenue your engagement generates, less infrastructure costs. We do not condition basic access to the Service on participation, you may withdraw from the program at any time by simply not earning further Tokens, and we do not charge a different price or deny service if you opt out.
7. Cookies and tracking technologies
We use the minimum number of cookies necessary to operate the Service. We do not load Google Analytics, Meta Pixel, fingerprinting libraries, or any other third-party tracker.
adtoken_user โ anonymous wallet identifier (the adt_<hex>). Set on first visit. Strictly necessary. ~1 year.
adtoken_session โ magic-link session token after you log in. Strictly necessary while logged in. 24-hour sliding window.
adtoken_admin โ set only on the admin subdomain for the operator's own use; not set on the consumer site.
- Third-party cookies inside ad iframes โ when you watch a rewarded video served by AppLixir or take a survey served by CPX Research, the third-party provider may set their own cookies inside their iframe. Those are governed by the third party's own privacy policy (linked in ยง 4).
All cookies above are first-party except as noted. Strictly-necessary cookies do not require consent under the GDPR / ePrivacy Directive. We do not use non-essential cookies.
8. Retention
- Wallet record (ID, balance, ledger) โ retained for the active life of the wallet. Anonymous wallets with no activity for 90 days may be pruned.
- Linked email + session token โ retained until you delete your account or 24 months of inactivity, whichever is sooner.
- Ad-completion events โ retained for the active life of the wallet. We may retain de-identified aggregate counts indefinitely.
- LLM metering records (model, tokens, cost, timestamp) โ retained for the active life of the wallet, then ~36 months for accounting reasons, then deleted.
- Prompt content โ NOT retained by default. If you opt in to prompt observation, retained until you opt out and request deletion.
- HTTP access logs โ at most 30 days, rotated, IPs partially truncated.
- Backups โ encrypted snapshots may retain deleted data for up to 30 additional days before being overwritten.
When the purpose for which Personal Information was collected ends, we delete or de-identify it within a reasonable period.
9. Your rights
9.1 Rights available to all users
- Access โ request a copy of the Personal Information we hold about you.
- Correction / rectification โ request that we correct inaccurate or incomplete Personal Information.
- Deletion / erasure โ request that we delete your wallet and associated data. Note: ad-network completion logs at our partners are subject to their own retention policies.
- Portability โ request a machine-readable copy of your wallet balance, ledger, and other data we have stored about you.
- Withdraw consent โ withdraw your opt-in to prompt observation at any time, without affecting prior lawful processing.
- Non-discrimination โ you will not be charged a different price or denied service for exercising any of these rights.
9.2 EEA / UK / Switzerland (GDPR + UK GDPR)
- Right to object to processing based on legitimate interest, including profiling. AdToken does not profile, but you may object to our legitimate-interest-based abuse-detection processing.
- Right to restrict processing in the circumstances of GDPR Art 18.
- Right to lodge a complaint with a supervisory authority โ in the EEA, your local Data Protection Authority (full list: edpb.europa.eu); in the UK, the Information Commissioner's Office (ico.org.uk); in Switzerland, the FDPIC (edoeb.admin.ch).
- No Data Protection Officer is appointed. AdToken's core activities do not require one under GDPR Art 37 (no large-scale systematic monitoring, no large-scale processing of special categories). Privacy questions go to support@limitlesstokens.com.
9.3 California (CCPA / CPRA)
- Right to know โ the specific pieces of Personal Information we hold about you, the sources, the purposes, and the categories of third parties we have disclosed it to (in the prior 12 months).
- Right to correct inaccurate Personal Information.
- Right to delete Personal Information.
- Right to opt out of sale or sharing โ we do not sell or share, but you may exercise this right preemptively and we will record it.
- Right to limit use and disclosure of Sensitive Personal Information โ we do not knowingly collect SPI.
- Right to non-discrimination.
9.4 Virginia / Colorado / Connecticut / Utah / Texas / Oregon / Montana / Tennessee / others
Residents of these states have substantially equivalent rights (access, correct, delete, portability, opt-out). Submit a request via the same email below and identify which state's law applies.
9.5 How to exercise your rights
Send a request to support@limitlesstokens.com from the email linked to your wallet, or via signed authorized agent. We will:
- Confirm receipt within 10 business days.
- Substantively respond within 30 days (GDPR) / 45 days (CCPA, extendable once by 45 days with notice).
- Verify your identity using your wallet ID and linked email; we will not require disproportionate verification information.
- Accept requests from authorized agents with proof of authorization (a written, signed permission) and a verification step from the consumer.
- Refuse only where a request is manifestly unfounded, excessive, or would conflict with a legal obligation; we will explain in writing if so.
10. Automated decision-making
AdToken does not make decisions about you that produce legal or similarly significant effects through solely automated processing. Abuse-detection rate-limits are rule-based (e.g. "more than N completions per minute from one IP") and do not produce legally or substantially significant effects on you โ at worst, a temporary rate-limit on the offending IP, reversible by support contact. Per GDPR Art 22, you may request human review of any rate-limit or wallet-suspension decision.
11. International transfers
Our servers and data stores are located in the United States (Fly.io regions in IAD / SJC). When you use the Service from outside the US, your Personal Information is transferred to and processed in the US.
For transfers from the EEA, UK, or Switzerland, we rely on:
- Standard Contractual Clauses (2021 EU SCCs + UK Addendum) with our US-based processors that process EEA / UK personal data.
- Supplementary technical measures as appropriate: encryption in transit (TLS 1.2+), encrypted backups, access logging.
You may request a copy of the SCC mechanism we rely on for any specific processor by emailing the contact in ยง 14.
12. Children
The Service is not directed to children under 13 (under 16 in the EEA/UK). We do not knowingly collect Personal Information from children below that age. If we learn we have collected such information, we will delete it promptly and, where required, notify a parent or guardian. Parents or guardians who believe their child has provided us with Personal Information may contact support@limitlesstokens.com for review and deletion.
13. Security and data-breach commitment
We employ industry-standard technical and organizational measures including TLS 1.2+ in transit, encrypted volume storage at rest, hashed sessions, CSPRNG-generated tokens, rate-limited authentication, and restricted operator-side access. The proxy code is open source for independent review.
No system is perfectly secure. If we become aware of a Personal Information breach that creates a risk to your rights or freedoms, we will:
- Notify the competent supervisory authority within 72 hours where required (GDPR Art 33).
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights (GDPR Art 34), and as required by applicable US state breach-notification laws.
- Publish a post-mortem at github.com/henrytushman-ctrl/adtoken/security for incidents affecting the proxy code.
14. Contact, complaints, and successor in interest
Privacy questions, rights requests, complaints: support@limitlesstokens.com. We aim to respond within 10 business days.
Supervisory-authority complaints (EEA / UK / Switzerland users): see ยง 9.2 for direct links.
Successor in interest: if AdToken is acquired, merged, restructured, or sold, your Personal Information may transfer to the successor entity as a business asset, subject to commitments at least equivalent to this Policy. We will notify users in-product before any such transfer where reasonably practical.
15. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of the page reflects the most recent revision; the version history is in our public repository (commit log of src/server.ts). For material changes that affect your rights, we will give notice in-product before the change takes effect and, where required by law, obtain renewed consent.
16. Limits of this document
This Policy is drafted by the operator and is intended to be accurate, complete, and compliant with the laws cited. It is not legal advice. For specific legal questions about how this Policy applies to your particular situation, please consult an attorney licensed in your jurisdiction.