tokens&
For enterprises
Submit a resource
Sign in

Last updated September 2026

Privacy Policy

This Privacy Policy explains how tokensand, LLC operates tokens&, including the developer utility layer, public builder surfaces, and privacy-safe enterprise adoption intelligence workflows.

For privacy requests, contact privacy@tokensand.app. Enterprise buyers can request a deeper data review, DPA, or security review through sales.

Builders first

Developers use tokens& to choose tools, save stacks, publish projects, claim credits, and launch better.

Private by default

Enterprise dashboards, exports, reports, tracking keys, CRM context, and account intelligence are organization-gated.

No raw resale list

Companies receive first-party, consented, public, or aggregate privacy-safe adoption signals, not a raw resale list of developers.

Who we are

tokensand, LLC is the operator of tokens&. For users in regions that use controller terminology, tokensand, LLC is the controller for platform account data, public builder surfaces, and general service telemetry. For customer-provided enterprise usage events and private workspace data, tokensand, LLC generally acts as a service provider or processor under the customer contract.

This policy covers tokensand.com, tokensand.app, authenticated workspaces, public project/profile pages, developer programs, product submissions, and related APIs or workflows that link to this policy.

Data we collect

Account/profile data

Name, email, avatar, role, company, login provider, account settings, workspace membership, and authentication signals.

Developer activity

Searches, saves, comparisons, follows, reviews, recommendations, project history, saved stacks, tool interactions, and preference signals.

Private provider connections

Provider-reported balances, allowances, dated snapshots, and monthly bills you choose to record stay private to your account. If you choose Connect for automatic provider refresh, we retain an encrypted provider key on our servers and use it to read that provider's balance or usage endpoint. Disconnect stops automatic refresh and removes the saved connection key from active application storage; your last dated snapshot and recorded bills remain. A one-time sync through the developer API does not opt you into key storage. Private balances and connection keys are not shared with vendors through app-usage reporting.

Projects and public content

Published projects, public profiles, product submissions, tool resources, badges, launches, events, challenges, comments, share cards, and public links you choose to publish.

Enterprise workspace data

Organization settings, members, roles, claimed products, campaigns, adoption sessions, account intelligence, reports, exports, CRM/import/export metadata, and support or procurement context.

Customer-provided usage events

Docs clicks, SDK starts, API events, product milestones, campaign UTMs, attribution tags, retention events, and other first-party telemetry sent by a customer or their authorized systems.

Cookies and referrals

Referral codes, anonymous attribution IDs, session cookies, analytics events, device/browser metadata, and email engagement needed to operate the service and measure campaigns.

How we use data

  • Operate the builder product, accounts, profiles, saved stacks, projects, launches, credits, events, and recommendations.
  • Personalize search, rankings, comparisons, build guidance, opportunity matching, and product suggestions.
  • Publish user-controlled public content such as profiles, projects, badges, tool submissions, and share pages.
  • Provide enterprise analytics, campaign attribution, adoption intelligence, account readouts, exports, reports, and agent recommendations.
  • Protect the platform from abuse, spam, impersonation, scraping, credential misuse, security incidents, and policy violations.
  • Send transactional emails, product updates, invite notices, lead confirmations, support messages, and legal or security notices.
  • Comply with applicable law, enforce agreements, support audits, and respond to lawful requests.

Public, private, and enterprise boundaries

Public surfaces may be visible to other users, customers, search engines, and answer engines. This includes public profiles, published projects, product submissions, public program pages, badges, reviews, rankings, share cards, and public proof artifacts.

Private enterprise surfaces are organization-gated. Workspace analytics, account intelligence, CRM/import/export metadata, tracking keys, campaign budgets, customer reports, private competitor context, and customer-provided usage events are visible only to authorized workspace users and approved service operations.

Enterprise adoption intelligence is built from first-party customer data, public builder activity, developer consent, and aggregate privacy-safe benchmarks. Developers are not sold as a raw list. Cross-customer or network-level outputs are aggregate by default and should suppress small cohorts or private rows.

AI and agent outputs

tokens& includes AI-assisted recommendations, agents, summaries, rankings, ROI planning, stack guidance, and adoption intelligence. These features may process your input, workspace context, public content, usage events, and retrieved evidence to generate scoped outputs.

Private enterprise/customer data is used to generate outputs for that workspace and is not used to train public models unless you separately opt in or a customer contract expressly allows it. Retrieved webpages, imported content, and customer-provided text are treated as untrusted data for tool execution and agent instructions.

Cookies, referrals, and analytics

We use cookies and similar technologies for authentication, security, preferences, referral attribution, campaign measurement, product analytics, and fraud prevention. Referral links may set a cookie so we can attribute signups, conversions, or rewards to the share that brought someone to tokens&.

We do not auto-post to social networks. Launch handoffs, referral copy, and share cards are user-controlled, and sponsored/referral relationships should be disclosed when shared.

Sharing and subprocessors

We may share data with service providers and subprocessors that help us provide hosting, database, authentication, email, analytics, payment, security, support, infrastructure, AI processing, CRM, and observability services. These providers are expected to use data only to provide services to tokensand, LLC or the applicable customer.

Advertising and conversion measurement: on the public marketing site we use Google Ads conversion tracking. When you sign up or submit a form there, a one-way hashed (SHA-256) version of your email address may be sent to Google to measure which campaigns led to that sign-up. This applies to marketing-site sign-ups only; private enterprise workspace data, events, and account intelligence are never shared with advertising providers.

We may also share data when directed by a workspace admin, when you publish public content, when required for a product integration, when necessary to protect the service, or when required by law. Enterprise customers should review subprocessor, retention, deletion, residency, and breach notice commitments in their DPA, MSA, order form, or SLA.

Retention and security

We keep data for as long as needed to operate tokens&, provide support, maintain audit/security logs, comply with law, resolve disputes, enforce agreements, and support customer contracts. Public content may remain visible until removed, archived, or deindexed. Delete-safe QA data should be labeled and removable.

We use administrative, technical, and organizational safeguards appropriate for a developer and enterprise SaaS platform. No system is perfectly secure. For security posture, procurement, and enterprise review, see Security, Service Status, and Data Processing.

International transfers

tokens& may process and store data in the United States and other countries where we or our service providers operate. If applicable law requires transfer safeguards, those safeguards should be handled in the customer DPA or another written agreement.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. You can also unsubscribe from marketing emails, manage public profile or project visibility, remove published content where supported, and ask a workspace admin to manage enterprise access or exports.

To make a rights request, email privacy@tokensand.app. We may need to verify your identity and may route enterprise workspace requests through the relevant customer admin when the customer controls the data.

Children and minimum age

tokens& is intended for developers, builders, companies, and professional users. It is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child provided data to tokens&, contact us so we can review and delete it where appropriate.

Changes to this policy

We may update this Privacy Policy as the product, laws, or contracts change. Material updates will be reflected by changing the date above and, when appropriate, by providing additional notice in the product or by email.

tokens&

Find tools, check provider offers, save a build plan, and share your work when you’re ready.

For buildersFor enterprises

For builders

  • Startup credits and perks
  • Agent Skills
  • Publish a project

For enterprises

  • Start free company workspace
  • Submit a tool, product, or perk

Community

  • Community
  • Newsletter
  • Events
Xin

© 2026 tokensand, LLC. All rights reserved.

  • Terms
  • Privacy
  • Security
  • Data Processing
  • Status