Skip to main content
Tokenforest

Privacy policy

What Tokenforest collects, why we use it and the choices you have.

Effective 4 September 2026

1. Who is responsible for your data

Strateal Oy is the controller for personal data used to run Tokenforest, manage accounts, bill customers and communicate about the service. Contact us at hello@tokenforest.ai.

When an organisation sends its members' usage data to Tokenforest, that organisation may be the controller and we may be its processor. Our Data Processing Addendum applies to that processing.

2. Data we collect

Account and sign-in data

We process your name, email address, email-verification state, password hash, authentication account identifiers, and session records such as IP address and browser or device information.

Organisation and collaboration data

We process organisation names and slugs, membership roles, invitations, and your public forest and World listing choices.

AI usage and impact data

The Tokenforest client sends model name, tool source, event name, timestamp, input and output token counts, cached and reasoning token counts, and whether a count was estimated. We calculate weighted tokens and estimated emissions from those figures. We do not collect prompts, model output, source code, file paths, repository names or raw tool telemetry.

Connector and billing data

We keep connector names, scopes, token prefixes and one-way token hashes. If you enable tree billing, we keep your billing limit, billing periods, and Stripe customer, subscription, price and invoice references. Stripe handles payment-card details; Tokenforest does not receive full card numbers.

Tree and communication data

We keep tree quantities, contribution status and references returned by our planting partner. We also process messages you send us and delivery records for account emails.

3. Where the data comes from

We receive data from you, your organisation administrator, the Tokenforest CLI or supported integrations, and service providers used for payments, email and tree funding. We also create calculated usage and impact figures from the token counts sent to us.

4. Why we use data and our legal bases

  • Contract: to create and secure accounts, accept usage events, calculate forests, provide team features, process subscriptions and answer support requests.
  • Legitimate interests: to prevent misuse, diagnose faults, protect the service, keep business records and understand service reliability. We balance these interests against your rights.
  • Legal obligations: to keep accounting records, answer lawful requests and meet tax, consumer-protection and regulatory duties.
  • Consent: where you choose optional public forest or World visibility, or where consent is otherwise required. You can withdraw consent at any time without changing the lawfulness of earlier processing.

5. Service providers and data transfers

We disclose only the data needed for these providers to perform their work:

  • Stripe for checkout, subscriptions, invoices, fraud checks and payments;
  • Resend for account and service emails;
  • Ecologi for tree-funding fulfilment and contribution references; and
  • cloud hosting, database, security and monitoring providers used to run Tokenforest.

Some providers may process data outside the European Economic Area. Where GDPR requires it, we rely on an adequacy decision, the European Commission's standard contractual clauses or another lawful transfer safeguard. Providers may also process data as independent controllers where the law or their regulated role requires it, as Stripe does for parts of payment processing.

We may disclose data if required by law, to protect legal rights, or as part of a corporate transaction subject to suitable confidentiality terms. We do not sell personal data or use it for third-party advertising.

6. Public forests

Public visibility is optional. If an organisation enables its public forest, its name, slug, tree count and model-level usage breakdown can be visible on the web. If it separately joins the World listing, its name, rank and tree count can appear there. An organisation owner can turn these settings off. Search engines and third parties may retain older copies for a time.

7. How long we keep data

We keep account, organisation and usage records while the account is active. Authentication sessions normally expire after 30 days. We keep connector records until they are revoked or deleted. Billing, tax and transaction records remain for the periods required by Finnish law. Security logs, support messages and failed-delivery records are kept only as long as they serve the purpose for which they were recorded.

After an account is closed, we delete or anonymise personal data unless we must retain it for legal claims, security, accounting or tax. Data may remain briefly in rotating backups before those backups are overwritten.

8. Your rights

Depending on the circumstances, you may ask us to give you a copy of your data, correct it, delete it, restrict its use, or provide it in a portable format. You may object to processing based on legitimate interests and withdraw consent at any time. You also have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect. Tokenforest does not make such decisions.

Send a request to hello@tokenforest.ai. We may ask for information needed to verify your identity. If your organisation controls the data, we may direct your request to its administrator.

You may lodge a complaint with the Finnish Data Protection Ombudsman at tietosuoja.fi, or with the data-protection authority where you live or work.

9. Security and children

We use access controls, encrypted connections, hashed connector credentials, limited staff access and operational monitoring to protect data. No online service can promise absolute security, so keep your password and connector tokens private and tell us promptly about a suspected compromise.

Tokenforest is made for developers and organisations, not children. We do not knowingly collect personal data from anyone under 16. A parent or guardian who believes a child has provided data should contact us.

10. Cookies

Tokenforest uses sign-in, security and interface-preference cookies. We do not currently use advertising or cross-site tracking cookies. Read the Cookie notice for names and lifetimes.

11. Changes and contact

We may update this policy when the service, providers or law changes. We will post the new version here and change the effective date. If a change materially affects your rights, we will give notice in the service or by email when practical.

Questions about this policy can be sent to hello@tokenforest.ai.