Privacy & Portability Compliance

Last updated: September 21, 2026

A consolidated statement of how TokenUity protects your personal data and honors your rights to access and port it. This page cross-references the binding policy documents rather than duplicating them.

1. Purpose of This Statement

This statement consolidates, in one place, how TokenUity protects personal data and honors your rights to access and port it. It is a navigation layer over the binding documents below — where this statement and a referenced policy differ, the referenced policy controls.

2. Privacy Posture at a Glance

  • Tiered data architecture: end-to-end encrypted Sync Vault for sensitive report snapshots; server-side, access-controlled operational data for saved calculations, labor profiles, and aggregate metrics.
  • Zero trust: the operator never holds your vault passphrase or derived key and cannot decrypt your Sync Vault entries.
  • Client-side computation: all modeling, detection, and token counting runs in your browser; raw prompts and raw CSV rows are not retained.
  • One-way hashing of email addresses, IP addresses, card fingerprints, and labor identifiers before they reach the platform.
  • No product analytics, no session replay, no cross-context behavioral advertising, and no sale or sharing of personal data.

3. Portability Commitment

You can export a full-fidelity copy of the records you own at any time, generated and downloaded in your browser. Saved reports can also be exported as PDF, CSV, or Excel. Exports are self-service and available without contacting us.

  • Personal records: complete JSON export of the records you own (in-app Data Rights tools).
  • Saved reports: PDF, CSV, and Excel export from any report view.
  • Aggregate organization metrics: exportable by organization administrators.
  • Machine-readable formats: JSON and CSV/Excel are provided so exports can be ingested by another system without transformation.

4. Your Rights (GDPR & CCPA/CPRA)

You have rights to access, rectify, erase, restrict, port, and object to the processing of your personal data, and to withdraw consent where processing is based on consent. The full enumeration of rights, legal bases, and market-specific detail is in the Privacy Policy.

5. Exercising Your Rights

Rights can be exercised directly from within the application — no support ticket required. The Data Rights page provides self-service tools for access (view and export), portability (full-fidelity export), and erasure (permanently delete the records you own). Organization administrators additionally have dual-control tools for organization-wide data wipe and subscription erasure. For requests a self-service tool cannot satisfy, contact us as provided in the Privacy Policy.

6. Related Binding Documents

7. Changes to This Statement

We may update this statement from time to time. Material changes are reflected by the “Last updated” date and, where required, communicated to registered users. The underlying binding documents remain the controlling source for any term this statement summarizes.

8. Contact

To exercise a right, request information, or raise a privacy or portability concern, contact TokenUity LLC, 1101 Silentglade Rd, Owings Mills, MD 21117, United States, or through the support channel provided in your account settings. For GDPR matters, you may also lodge a complaint with your local data protection supervisory authority.

© 2026 TokenUity™ · Zero trust · End to end encrypted