1. Who is responsible for your data
Strateal Oy is the controller for personal data used to run Tokenforest, manage accounts, bill customers and communicate about the service. Contact us at hello@tokenforest.ai.
When an organisation sends its members' usage data to Tokenforest, that organisation may be the controller and we may be its processor. Our Data Processing Addendum applies to that processing.
2. Data we collect
Account and sign-in data
We process your name, email address, email-verification state, password hash, authentication account identifiers, and session records such as IP address and browser or device information.
Organisation and collaboration data
We process organisation names and slugs, membership roles, invitations, and your public forest and World listing choices.
AI usage and impact data
The Tokenforest client sends model name, tool source, event name, timestamp, input and output token counts, cached and reasoning token counts, and whether a count was estimated. We calculate weighted tokens and estimated emissions from those figures. We do not collect prompts, model output, source code, file paths, repository names or raw tool telemetry.
Connector and billing data
We keep connector names, scopes, token prefixes and one-way token hashes. If you enable tree billing, we keep your billing limit, billing periods, and Stripe customer, subscription, price and invoice references. Stripe handles payment-card details; Tokenforest does not receive full card numbers.
Tree and communication data
We keep tree quantities, contribution status and references returned by our planting partner. We also process messages you send us and delivery records for account emails.
3. Where the data comes from
We receive data from you, your organisation administrator, the Tokenforest CLI or supported integrations, and service providers used for payments, email and tree funding. We also create calculated usage and impact figures from the token counts sent to us.
4. Why we use data and our legal bases
- Contract: to create and secure accounts, accept usage events, calculate forests, provide team features, process subscriptions and answer support requests.
- Legitimate interests: to prevent misuse, diagnose faults, protect the service, keep business records and understand service reliability. We balance these interests against your rights.
- Legal obligations: to keep accounting records, answer lawful requests and meet tax, consumer-protection and regulatory duties.
- Consent: where you choose optional public forest or World visibility, or where consent is otherwise required. You can withdraw consent at any time without changing the lawfulness of earlier processing.
6. Public forests
Public visibility is optional. If an organisation enables its public forest, its name, slug, tree count and model-level usage breakdown can be visible on the web. If it separately joins the World listing, its name, rank and tree count can appear there. An organisation owner can turn these settings off. Search engines and third parties may retain older copies for a time.
7. How long we keep data
We keep account, organisation and usage records while the account is active. Authentication sessions normally expire after 30 days. We keep connector records until they are revoked or deleted. Billing, tax and transaction records remain for the periods required by Finnish law. Security logs, support messages and failed-delivery records are kept only as long as they serve the purpose for which they were recorded.
After an account is closed, we delete or anonymise personal data unless we must retain it for legal claims, security, accounting or tax. Data may remain briefly in rotating backups before those backups are overwritten.
8. Your rights
Depending on the circumstances, you may ask us to give you a copy of your data, correct it, delete it, restrict its use, or provide it in a portable format. You may object to processing based on legitimate interests and withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. Tokenforest does not make such decisions.
Send a request to hello@tokenforest.ai. We may ask for information needed to verify your identity. If your organisation controls the data, we may direct your request to its administrator.
You may lodge a complaint with the Finnish Data Protection Ombudsman at tietosuoja.fi, or with the data-protection authority where you live or work.
9. Security and children
We use access controls, encrypted connections, hashed connector credentials, limited staff access and operational monitoring to protect data. No online service can promise absolute security, so keep your password and connector tokens private and tell us promptly about a suspected compromise.
Tokenforest is made for developers and organisations, not children. We do not knowingly collect personal data from anyone under 16. A parent or guardian who believes a child has provided data should contact us.
11. Changes and contact
We may update this policy when the service, providers or law changes. We will post the new version here and change the effective date. If a change materially affects your rights, we will give notice in the service or by email when practical.
Questions about this policy can be sent to hello@tokenforest.ai.