Token WiseToken WiseHome

Privacy Notice

Last updated: 2026

Who we are (data controller)

The Token Wise extension and website are operated by Mazhar Mahmood, trading as Token Wise ("we", "us"). Mazhar Mahmood is the data controller responsible for any personal data processed in connection with the Service. You can contact us at support@tokenwise.me.

What we built

The extension auto-detects the AI platform you are on (ChatGPT, Claude, Perplexity, Gemini, Grok), estimates the token cost of your prompt locally, and offers a one-click rewrite. All platform cost rules are built in — you never enter pricing manually.

What stays on your device

What leaves your device

Nothing — until you click the Optimize button. When you do, your prompt is sent over HTTPS to our optimization endpoint, which proxies it to an AI model and returns a rewritten version. We do not log, store, or share prompt content. If the cloud rewriter is unavailable, the extension falls back to a local rule-based rewriter that never makes a network call.

No third-party trackers

The extension has no advertising identifiers and no third-party analytics SDKs. The cost estimates and pricing rules are bundled with the extension.

Service telemetry & abuse detection

To keep the optimization service reliable, our backend records per-request metadata when you click Optimize: timestamp, AI platform identifier, your tier, estimated input/output tokens, the model we routed the call to, and the cost in credits. We also store a SHA-256 hash of your prompt (used only to deduplicate identical calls for caching) and a short-lived, daily-salted SHA-256 hash of your IP address. We do not store raw IPs and we do not store your prompt text on the server.

These records are used to enforce daily/monthly quotas, detect abuse (rate, burst, or runaway-spend patterns), and compute aggregate billing metrics. They are not sold and not shared with advertisers.

Billing data (paid plans only)

If you purchase Pro or Power, we store your licence key, the email you used at checkout, your subscription status, billing period, and a counter of any overage blocks. Our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders and handles payment processing, billing, tax, and refund-related customer support — we never see your card details. Overage billing is strictly opt-in: nothing extra is charged unless you explicitly enable it in the extension popup, and you can disable it at any time.

Remote configuration

About every 12 hours the extension fetches a small JSON file from our hosted endpoint with the latest list of supported platforms and approximate pricing rules. Only that config file is requested — your prompts are never included.

Optional: API request monitoring

The extension includes an opt-in network monitor (off by default) that observes outgoing calls made by the page to known AI vendor API hosts only: api.openai.com, api.anthropic.com, generativelanguage.googleapis.com, api.x.ai, and api.perplexity.ai. When enabled, we capture metadata only: request size, response status, response size, model id, and timestamp. We never read prompt content, response bodies, auth headers, cookies, or any data from non-AI-vendor hosts. The monitor passes requests through unchanged — it never blocks, modifies, or delays them. You can disable it at any time in Settings, and a first-run disclosure is shown on install before any opt-in.

Limits of Browser-Based Monitoring

Token Wise observes direct browser-to-vendor API calls only. If an application sends AI requests from its own server (server-side), those requests are not visible to your browser and cannot be measured by any browser extension. Examples include tools that proxy AI calls through their backend infrastructure. This limitation is architectural and preserves user privacy boundaries.

Optional: Calibration mode

Also opt-in and off by default. When enabled, the extension computes a higher-fidelity token count for your prompt locally in your browser and sends only two numbers (our estimate vs the local count) to our calibration endpoint to improve accuracy. Prompt text never leaves your browser.

Anonymous device identifier

On first run the extension generates a random UUID (client_id) stored in chrome.storage.local. It is sent with optimization requests, the optional usage-event stream, and calibration samples for rate-limiting and abuse prevention. It is not linked to your name, email, or any other identifier, and is cleared if you uninstall or reset the extension.

Vendor billing reconciliation (admins only)

If an admin connects a vendor billing key on the dashboard, we pull aggregate usage and cost data from that vendor's billing API to compare against our estimates. Credentials are AES-256-GCM encrypted at the application layer before storage, scoped to admin RLS only, and never exposed to extension users. This pathway is opt-in at the workspace level and not active for end users by default.

Legal basis for processing

We rely on the following legal bases under UK/EU GDPR:

Who we share data with

We do not sell personal data and we do not share it with advertisers.

International transfers

Some of our processors are located outside the UK/EEA. Where personal data is transferred outside the UK/EEA we rely on appropriate safeguards such as the UK International Data Transfer Addendum and EU Standard Contractual Clauses, or on an adequacy decision where one applies.

How long we keep data

Your rights

Where UK or EU data-protection law applies, you have the right to: access the personal data we hold about you; have it rectified if it is inaccurate; have it erased; restrict or object to its processing; receive it in a portable format; and withdraw any consent you have given. To exercise any of these rights, email support@tokenwise.me. We aim to respond within one month.

You also have the right to lodge a complaint with a supervisory authority — in the UK that is the Information Commissioner's Office (ico.org.uk). For billing data held by Paddle, you can also contact Paddle directly via paddle.net.

Security

We use appropriate technical and organisational measures to protect personal data, including HTTPS/TLS in transit, encryption at rest for managed databases, AES-256-GCM application-layer encryption for any vendor billing credentials, scoped access controls and row-level security on the backend, hashed (not raw) IPs, and the principle of least privilege for any human access. No system is perfectly secure, so please use a strong unique password if you create an account and notify us immediately at support@tokenwise.me if you suspect a security issue.

Cookies

The marketing website uses only strictly-necessary first-party storage required to render pages. We do not set advertising or third-party analytics cookies. The extension does not use cookies; it uses chrome.storage.local on your device only.

Your controls