Privacy Policy

Last updated: August 6, 2026

1. Controller

The data controller for myapptoken.com, dashboard.myapptoken.com and api.myapptoken.com is Aliaksandr Kolesen, ul. Polska 19D/19, 00-703 Warszawa, Poland (see company information). Contact: hello@myapptoken.com.

2. What we process, and why

a. Your dashboard account

When you sign in with Google we receive your email address, name and profile picture. We use these to operate your account, to show who has access to shared applications, and to send transactional email such as member invitations. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

b. Proxied API traffic

When your applications route requests through the proxy, we process request and response metadata (timestamps, sizes, status codes, latency, model names, your app's user identifiers) and the request/response content itself (which may include prompts your users write). This powers your usage statistics, rate limiting, abuse control and AI Insights — core features of the Service. Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interest in operating a secure, abuse-resistant service (Art. 6(1)(f)).

Your responsibility: for personal data contained in your applications' traffic (e.g. what your end users type), you are the controller and we act as your processor, handling that data only to provide the Service to you. Ensure your own privacy notice covers your use of MyAppToken.

c. Server logs

Our infrastructure records IP addresses and technical request data for security and troubleshooting. Legal basis: legitimate interest (Art. 6(1)(f)).

d. Stored provider keys

API keys you store in the token vault are used exclusively to forward your requests to the provider you configured and are never shown in full after entry.

3. AI-assisted insights

If you use the AI Insights feature, samples of prompts from your own applications' traffic are sent to OpenAI (OpenAI Ireland Ltd / OpenAI LLC) to generate usage summaries for you. OpenAI's API terms prohibit training on this data. Insights run per-application and are visible only to that application's members.

4. Where your data lives

The Service runs on Amazon Web Services in the us-east-1 (N. Virginia, USA) region. Transfers of personal data to the USA are safeguarded by AWS's certification under the EU-U.S. Data Privacy Framework and the EU Standard Contractual Clauses. Our processors: Amazon Web Services (hosting, storage, email delivery), OpenAI (AI Insights, as described above), Google (sign-in), Sentry (error monitoring, backend errors only).

5. Retention

6. Your rights

Under the GDPR you can request access to, rectification, erasure or portability of your personal data, restriction of or objection to its processing. Write to hello@myapptoken.com — we respond within 30 days. You may also lodge a complaint with your supervisory authority; in Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa.

7. No profiling, no selling

We do not sell personal data, do not use it for advertising, and do not make automated decisions with legal effects about you.

8. Changes

We will announce material changes to this policy by email or in the dashboard. The "last updated" date above always reflects the current version.