Privacy Policy
Last updated: September 2026
Data controller: Flotic LC.
Notice address: 3F 301-Na025, Sangik Plaza, 57 Munin-ro, Suji-gu, Yongin-si, Gyeonggi-do, Republic of Korea
Privacy requests: support@minitok.dev.
1. What We Collect
minitok collects minimal data: email address, subscription status, and installation IDs. Open may submit allowlisted per-run telemetry only with an active subscription and entitlement capability. Select stores aggregate counters only; Private never uploads or stores telemetry. Open permits consented per-run telemetry with 30-day client policy retention; Select permits consented aggregate-only telemetry with 14-day client policy retention; Private never uploads or stores telemetry.
2. Account Security Emails
We send email-verification and password-reset messages through the authentication mail channel. Each message contains a one-time challenge that expires after 15 minutes. Challenges are retained only as a hashed value with purpose, expiry, consumption state, and limited audit metadata; raw challenges are not stored or logged. Password reset revokes existing customer sessions.
Authentication mail is separate from support mail. Support requests are handled through support@minitok.dev and are not used to deliver account challenges.
3. Accounts, Sessions, and Billing
The account page uses an authenticated customer session to show email verification, subscription access, limited session metadata, and passkey metadata. You can revoke individual sessions, revoke all sessions, change your password, sign out, and open the Dodo billing portal. The web client uses an HttpOnly, Secure, SameSite=Lax customer cookie for authenticated browser API requests and does not expose that token to JavaScript. CLI clients continue to use explicit Bearer JWTs. The account page never renders or logs tokens, raw challenge values, payment secrets, or provider identifiers.
4. What We Never Collect
- Your source code
- File paths or repository names
- Programming prompts or AI outputs
- API keys or credentials
5. How We Use Data and Processing Grounds
Data is used to provide accounts, authentication, billing, activation and entitlement checks, security, support, legal compliance, and optional telemetry. Depending on the processing activity, the applicable ground may be contract performance, compliance with a legal obligation, a legitimate interest in service security, or consent for optional telemetry.
6. Browser Storage and Third Parties
The web client uses an HttpOnly customer cookie for authenticated API requests and does not use browser storage for authentication or advertising. We do not use a third-party advertising or analytics SDK. The website may send a small allowlisted event containing only an event name and public page or guide key; the optional first_success signal requires an explicit confirmation on the case study page and does not report a model run. Date-based aggregate counters are stored without IP address, user-agent, cookie, session, referrer, query string, prompt, source code, token, UTM value, or other user identifier. Event delivery is optional and a failure does not affect the page. Discovery aggregate counters are retained for up to 90 days and may be viewed only by authorized administrators as date/event/surface/count summaries; they are not exposed through the public API. Session tokens are never rendered or logged by account pages. We use Dodo Payments for billing, Hetzner for hosting, and Let's Encrypt for TLS certificates. Dodo handles payment processing, Hetzner provides hosting infrastructure, and Let's Encrypt issues TLS certificates; these providers may process data in locations outside your country. See their current privacy terms and contact support@minitok.dev for processor and transfer details applicable to your account.
7. Data Retention and Deletion
Open telemetry policy: 30 days. Select aggregate telemetry policy: 14 days. Private telemetry: none. Account, billing, security, and support records are retained only as needed to provide the service, prevent abuse, resolve disputes, and meet legal obligations. Data is deleted or anonymized when the applicable retention purpose ends, subject to legal retention exceptions.
| Data category | Purpose | Policy retention |
|---|---|---|
| Account and authentication | Account access, verification, security | While needed for the account and legal/security obligations |
| Open telemetry | Optional workflow measurement | 30 days |
| Select aggregate telemetry | Optional aggregate measurement | 14 days |
| Private telemetry | Not collected | None |
8. Your Rights
Signed-in customers can submit an authenticated deletion request from Account; other privacy requests may be sent to support@minitok.dev. You may request access, correction, deletion, or anonymization of personal data. We may need to verify the request and retain limited billing, security, support, or legal records where required.