This notice describes the data TokenBinge actually receives, what remains private, what you may choose to publish, and how to take your data back or delete it.
TokenBinge currently connects to personal OpenAI accounts. The optional Windows Relay can stay quietly in the notification area and regularly send private model and cache details from local Codex counters. Other sign-in methods, price integrations and Google Analytics remain paused.
Last updated: 31 August 2026.
01Controller and scope
TokenBinge is published by JoDevelop, which decides why and how personal data is processed for this service. It is intended for individual accounts. If you connect OpenAI, known business, team, education, and enterprise plans are rejected.
02Account sign-in and connected services
You can access one TokenBinge account with a verified email and password, a one-use email link, Google, or OpenAI. TokenBinge stores your login address encrypted and keeps a separate keyed blind index for lookup. It never stores a recoverable password: a unique salt and 600,000-round PBKDF2-HMAC-SHA-256 derivation are protected again with a server-side secret. Email verification and recovery links use a random token that expires after 15 minutes, works once, is bound to the requesting browser, and is stored only as an HMAC-SHA-256 keyed digest; the requester's network address is also reduced to a keyed blind index for rate limiting. Google sign-in uses short-lived server-side state and PKCE, receives a verified account identifier and email, and retains no Google access token. Expired or consumed authentication attempts are removed by hourly cleanup, normally within two hours of creation. If you connect OpenAI, TokenBinge receives your email address, name, OpenAI account identifier, sign-in provider, personal plan and subscription end date, token totals and daily usage, plus an encrypted credential used to refresh those counters. It does not request or store your Google or OpenAI password, API keys, prompts, conversations, or source code.
03Local collector
If you install the optional Windows Relay, TokenBinge receives your machine name and local Codex daily counters by model and token category, plus Relay version and billing-mode metadata when available. Relay stays quietly in the notification area, syncs immediately and checks for changes every six hours; the installation checkbox only chooses whether it starts again with Windows. Codex does not identify your TokenBinge account: a download created while signed in carries a one-use code valid for 10 minutes, which Relay exchanges for a separate random 256-bit device credential protected by Windows. You can revoke the device. Uploads are signed with their timestamp and monotonic sequence. TokenBinge never receives prompts, conversations, source code, files, OpenAI credentials or API keys from Relay.
04Purposes and legal bases
Email, password, Google and OpenAI authentication, account recovery, OpenAI or collector usage import, the dashboard, saved designs, export, and cards you ask to publish are processed because they are necessary to perform the service you request. Publishing an optional ranking profile relies on your explicit choice, which you can withdraw. Relational notification emails about your own usage, rank and profile activity, along with session security, abuse prevention, service reliability, and limited aggregate view and click counts, rely on JoDevelop's legitimate interests. Notifications stay reasonable, contain no advertising or offers, and you can object at any time; daily rotating visitor digests reduce the impact of audience measurement.
05What you make public
Nothing appears in a public profile or leaderboard until you opt in. A public profile can show your chosen display name and profile address, country, uploaded picture, links, projects, unique-view count and—only in full mode—up to 120 recent daily points. The ordinary leaderboard uses one canonical total: reported usage across all collector tools when available, otherwise the official OpenAI counter; the two are never added together. Its provenance is shown as Reported or Official. The model leaderboard remains based on reported collector totals. An OpenAI-linked profile can also show its personal plan. Published card images and their visible title, handle, period, dates, and total are public at an unguessable link; collector-based cards are labelled as reported. Cards do not expire automatically. Moving a card to Trash immediately unpublishes it at TokenBinge's origin, but keeps its database row and image so you can restore it until you empty Trash or the account is finally erased. Copies already created in browser or network caches may persist for their own cache periods and cannot be revoked by TokenBinge.
06Profile views and link clicks
On public profiles, TokenBinge counts at most one view per network address per day and one click per destination per day. The raw address is not written to the product database: it is turned into a keyed digest that changes each UTC day. Nightly cleanup removes daily rows once they are older than the previous UTC day, normally within two days. Bot-like user-agent strings are excluded but not stored in these counters. Aggregate view and click totals remain with the account until it is finally deleted.
07Email notifications
All relational notification categories start enabled when an account is created. TokenBinge uses the email address associated with your account for an activity-only weekly summary and for rank, profile-view or link-click milestones. You can turn each category off at any time. Encrypted preferences and notification state, plus the type and date of the latest send, prevent repeats and limit the cadence. Every message links to granular settings and offers unsubscribe; disabling everything stops notification email. These messages never contain third-party advertising, offers or a promotional newsletter.
08Cookies and browser storage
TokenBinge uses no advertising cookie or social-network tracker. Google Analytics 4 is optional and is neither downloaded nor contacted until you accept audience measurement. If accepted, it measures page views without query strings or TokenBinge account identifiers; advertising signals and personalization are disabled. You can change your choice through “Analytics choices” in the footer; refusal is stored locally and withdrawal stops future measurements. A secure, HttpOnly, SameSite=Lax account cookie lasts up to 365 days; temporary authentication cookies last no more than 24 hours. A requested email link expires after 15 minutes and is consumed once. Your browser also keeps interface choices, language, theme, draft card assets, legacy card-deletion keys, and your analytics choice until you clear site data or the application resets them.
09Retention, sign-out, and deletion
Active accounts are not deleted for inactivity; account data, collector history, preferences, email settings and aggregates remain until you request deletion. Signing out revokes only that browser session; sign-in methods and connected AI services stay attached to the account. Deletion revokes outstanding authentication attempts, removes provider credentials, and unpublishes the profile immediately, then schedules all remaining database rows and stored images for erasure after 30 days. Signing in again with a verified method during that grace period restores the account; after final erasure, TokenBinge cannot rebuild the history. Moving a card to Trash immediately unpublishes it at TokenBinge's origin, while its database row and image remain restorable until you empty Trash or the account is finally erased. Copies already held in browser or network caches may persist for their own cache periods and cannot be revoked.
10Security and encryption limits
OpenAI identity, daily OpenAI usage, credentials, preferences, profile fields, sign-in email, and private images are sealed by the Worker with AES-256-GCM before storage; searchable identifiers use keyed blind indexes. Collector and valuation rows remain readable in D1: source and machine labels; daily token-category and per-model counters; lifetime per-model counters; billing mode and collector version; and valuation events with the reported model, the assumed catalogue provider, token-category and observed public-rate details, priced coverage, the estimated public-API-list-price equivalent, method, and timestamps. That provider is inferred from the model or, only when the observed models do not conflict, from a Codex, Claude Code, or Gemini CLI source. Source-based attribution remains assumed: it is a pricing reference, never a record of the actual execution or billing route. Unmatched usage, including local Ollama usage, remains unpriced rather than receiving an invented cost. All are tied to an opaque account ID. Opaque row IDs, technical timestamps and flags, and token totals needed to order rankings also remain readable. Published card images are deliberately unencrypted so link-preview services can fetch them. Encryption limits the harm from a database export alone; it cannot protect data from an attacker controlling the Cloudflare account and its secret store.
A price API key secret is shown once and never stored. D1 keeps only a keyed blind index, your key label, creation and last-use timestamps, and bounded account-level quota counters. Invalid-key attempts are limited using a short-lived keyed digest of the network address. Revoking a key, deactivating the account, or final deletion immediately makes it unusable.
11Recipients and international transfers
Cloudflare provides the network, Worker, Container, D1 database, R2 object storage, email delivery, and operational logs. Google receives authorization requests only if you choose Google sign-in and, after your separate analytics consent, receives limited page-view and browser or device data through Google Analytics 4. TokenBinge strips query strings, sends no account identifier, and disables advertising signals and personalization. OpenAI receives authentication and refresh requests only if you connect OpenAI. Cloudflare also receives the recipient address and message when you request an email link or account notifications are active. TokenBinge verifies AI price pages without sending any TokenBinge account data to their providers. Cloudflare operational logs can include request metadata and technical errors and are retained for up to seven days. Providers may process data outside the EEA under their applicable transfer safeguards, including adequacy frameworks or standard contractual clauses where required.
12Your rights and younger users
You can download a JSON copy, correct your public profile, leave the ranking, manage email choices, delete cards, or request account deletion from the dashboard. Depending on the law that applies, you may also request access, rectification, erasure, restriction, portability, or object to processing, and withdraw consent at any time; a response is normally due within one month. You may complain to your data-protection authority, including the CNIL in France. TokenBinge is not directed at children: in France, anyone under 15 needs their own consent and that of a parent or guardian for consent-based public or email features, and OpenAI requires parental permission for users under 18.
Submit a complaint to the CNIL