Builders first
Developers use tokens& to choose tools, save stacks, publish projects, claim credits, and launch better.

Preparing tokens&
Loading the next builder or enterprise surface.
Loading
Preparing page
Loading product graph, proof, and adoption context.
LoadingLast updated May 2026
This Privacy Policy explains how tokensand, LLC operates tokens&, including the developer utility layer, public builder surfaces, and privacy-safe enterprise adoption intelligence workflows.
For privacy requests, contact privacy@tokensand.app. Enterprise buyers can request a deeper data review, DPA, or security review through sales.
Developers use tokens& to choose tools, save stacks, publish projects, claim credits, and launch better.
Enterprise dashboards, exports, reports, tracking keys, CRM context, and account intelligence are organization-gated.
Companies receive first-party, consented, public, or aggregate privacy-safe adoption signals, not a raw resale list of developers.
tokensand, LLC is the operator of tokens&. For users in regions that use controller terminology, tokensand, LLC is the controller for platform account data, public builder surfaces, and general service telemetry. For customer-provided enterprise usage events and private workspace data, tokensand, LLC generally acts as a service provider or processor under the customer contract.
This policy covers tokensand.com, tokensand.app, authenticated workspaces, public project/profile pages, developer programs, product submissions, and related APIs or workflows that link to this policy.
Name, email, avatar, role, company, login provider, account settings, workspace membership, and authentication signals.
Searches, saves, comparisons, follows, reviews, recommendations, project history, saved stacks, tool interactions, and preference signals.
Published projects, public profiles, product submissions, tool resources, badges, launches, events, challenges, comments, share cards, and public links you choose to publish.
Organization settings, members, roles, claimed products, campaigns, adoption sessions, account intelligence, reports, exports, CRM/import/export metadata, and support or procurement context.
Docs clicks, SDK starts, API events, product milestones, campaign UTMs, attribution tags, retention events, and other first-party telemetry sent by a customer or their authorized systems.
Referral codes, anonymous attribution IDs, session cookies, analytics events, device/browser metadata, and email engagement needed to operate the service and measure campaigns.
Public surfaces may be visible to other users, customers, search engines, and answer engines. This includes public profiles, published projects, product submissions, public program pages, badges, reviews, rankings, share cards, and public proof artifacts.
Private enterprise surfaces are organization-gated. Workspace analytics, account intelligence, CRM/import/export metadata, tracking keys, campaign budgets, customer reports, private competitor context, and customer-provided usage events are visible only to authorized workspace users and approved service operations.
Enterprise adoption intelligence is built from first-party customer data, public builder activity, developer consent, and aggregate privacy-safe benchmarks. Developers are not sold as a raw list. Cross-customer or network-level outputs are aggregate by default and should suppress small cohorts or private rows.
tokens& includes AI-assisted recommendations, agents, summaries, rankings, ROI planning, stack guidance, and adoption intelligence. These features may process your input, workspace context, public content, usage events, and retrieved evidence to generate scoped outputs.
Private enterprise/customer data is used to generate outputs for that workspace and is not used to train public models unless you separately opt in or a customer contract expressly allows it. Retrieved webpages, imported content, and customer-provided text are treated as untrusted data for tool execution and agent instructions.
We may share data with service providers and subprocessors that help us provide hosting, database, authentication, email, analytics, payment, security, support, infrastructure, AI processing, CRM, and observability services. These providers are expected to use data only to provide services to tokensand, LLC or the applicable customer.
We may also share data when directed by a workspace admin, when you publish public content, when required for a product integration, when necessary to protect the service, or when required by law. Enterprise customers should review subprocessor, retention, deletion, residency, and breach notice commitments in their DPA, MSA, order form, or SLA.
We keep data for as long as needed to operate tokens&, provide support, maintain audit/security logs, comply with law, resolve disputes, enforce agreements, and support customer contracts. Public content may remain visible until removed, archived, or deindexed. Delete-safe QA data should be labeled and removable.
We use administrative, technical, and organizational safeguards appropriate for a developer and enterprise SaaS platform. No system is perfectly secure. For security posture, procurement, and enterprise review, see Security, Trust, and Data Processing.
tokens& may process and store data in the United States and other countries where we or our service providers operate. If applicable law requires transfer safeguards, those safeguards should be handled in the customer DPA or another written agreement.
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. You can also unsubscribe from marketing emails, manage public profile or project visibility, remove published content where supported, and ask a workspace admin to manage enterprise access or exports.
To make a rights request, email privacy@tokensand.app. We may need to verify your identity and may route enterprise workspace requests through the relevant customer admin when the customer controls the data.
tokens& is intended for developers, builders, companies, and professional users. It is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child provided data to tokens&, contact us so we can review and delete it where appropriate.
We may update this Privacy Policy as the product, laws, or contracts change. Material updates will be reflected by changing the date above and, when appropriate, by providing additional notice in the product or by email.