Privacy Policy

Last updated: May 2026

This policy covers both the free TokenID CLI (runs locally on your machine) and the Vaudit hosted platform at app.audit.id.

What we collect

When you use the free CLI, we collect anonymous usage and stability statistics — crash reports, performance metrics, and feature usage — associated with the email address you verified at first start. We do not collect, transmit, or store the content of your LLM calls. Prompts, completions, token counts, and cost estimates all remain in local SQLite on your machine.

When you use the hosted platform, we additionally collect the usage metadata you send us through our SDKs, proxy, or ingest endpoints — token counts, model names, request timestamps, estimated costs, latency, and provider names. We do not collect prompt content or tool outputs.

What we never collect

How we use it

We use the data we collect to:

We do not sell your data to third parties or use it for advertising.

Opting out of usage telemetry

You can disable usage and crash telemetry from the free CLI at any time with tokenid --no-telemetry. Email verification and license renewal still occur — they are required for your license to remain active.

Opting out also disables the in-app self-upgrade feature and entitlement offers, because both rely on the same usage signal.

Service providers

We rely on a small number of service providers to operate Vaudit. They process data on our behalf under contract:

Data storage

Hosted-platform data is stored on infrastructure within the EU. Credentials are encrypted at rest with Fernet (AES-128-CBC + HMAC-SHA256). Free CLI data stays on your machine.

Retention

Hosted-platform usage records are retained for the duration of your subscription plus 90 days after cancellation, then permanently deleted. Free-CLI usage telemetry is retained for 90 days. You may request immediate deletion by emailing privacy@audit.id.

Your rights

You may request access to, correction of, or deletion of your data at any time. Contact privacy@audit.id. We respond within 30 days.

Cookies

The hosted platform uses a single session cookie for authentication. No advertising or tracking cookies are used.

Contact

Questions about this policy: privacy@audit.id