Legal

Privacy Policy

Last updated: April 2026

1. Summary

TokenSavr is a planning tool for AI coding workflows. We collect the minimum data needed to run your account, generate strategies, and improve estimate accuracy. We do not sell your data. We do not use your project ideas to train our own models.

2. What we collect

  • Account data: email address, optional display name, and authentication tokens managed by our backend provider.
  • Strategy content: the project ideas, budgets, and platform preferences you submit, plus the AI-generated steps and your progress notes.
  • Usage signals: step completions, actual credit costs you log, and aggregated accuracy metrics used to calibrate future estimates.
  • Preferences: theme, daily budget, preferred platforms, and the calibration toggle.

3. How we use it

  • To authenticate you and operate your account.
  • To send your prompt to a third-party AI model and stream the generated strategy back to you.
  • To calibrate future estimates against your historical over/under-spend pattern (you can disable this in Settings).
  • To debug errors, prevent abuse, and improve the quality of the Service.

4. AI providers

Strategies are generated using third-party AI models (e.g. via the Lovable AI Gateway). When you generate a strategy, your prompt and any calibration signals are sent to the model provider for processing. Providers may retain request data for abuse monitoring per their own policies. We do not authorize providers to use your prompts for training.

5. Data storage & security

Your account data, profiles, strategies, and step progress are stored in our managed backend (Lovable Cloud). Access is protected by row-level security so each user can only read and write their own records. Connections use TLS in transit. No system is perfectly secure — please use a strong, unique password.

6. Cookies & local storage

We use essential cookies and browser localStorage to keep you signed in, remember your theme, and store opt-in preferences such as the calibration toggle. We do not use third-party advertising cookies.

7. Sharing

We do not sell your personal data. We share data only:

  • With AI providers strictly to fulfill your strategy generation request.
  • With our infrastructure providers (hosting, database, authentication) under contractual confidentiality.
  • When required by law, valid legal process, or to protect our rights.

8. Your rights

You can:

  • Access and update your profile from the Settings page.
  • Delete every saved strategy and step record from Settings → Danger zone.
  • Request full account deletion (including the underlying auth record) by contacting support.
  • Opt out of historical calibration at any time in Settings.

Depending on where you live (EEA, UK, California, etc.), you may have additional rights such as portability or to lodge a complaint with a supervisory authority.

9. Data retention

We retain your data while your account is active. When you delete strategy data from Settings, it is removed promptly. Backups may persist for a short period before being overwritten.

10. Children

TokenSavr is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has created an account, contact us so we can remove it.

11. International transfers

Our infrastructure and AI providers may process data in countries outside your own. By using the Service you consent to such transfers, subject to applicable safeguards.

12. Changes

We may update this policy as the Service evolves. Material changes will be announced via the Service or email. The "Last updated" date above always reflects the current version.

13. Contact

Questions about your privacy? Reach out via the support contact listed on our homepage.

See also our Terms of Service.