MINTOK
1658 CODING SCORE
LOG IN BUY PRO ($9.99)
DATA PRIVACY & SECURITY GUARANTEE

Privacy Policy

Effective Date: October 1, 2026. How MinTok handles code context, telemetry, account data, and cryptographic key boundaries.

1. Our Privacy Philosophy

Developers demand absolute confidentiality when running autonomous agents over proprietary codebases. MinTok was designed from day one with a zero-knowledge, zero-retention architecture.

2. Ephemeral Processing Guarantee & No Model Training on Customer Data

  • Upstream Model Passthrough: MinTok operates as an in-flight optimization proxy to original base model APIs (OpenAI, Anthropic, Google Cloud, Mistral, DeepSeek). We strictly adopt and uphold the standard enterprise data protection terms of these upstream providers.
  • Zero Training on Customer Data: Neither MinTok nor upstream model providers train, fine-tune, or calibrate any AI model on your API inputs, code snippets, or prompt completions.
  • In-Flight Memory Compaction: MinTok reduces tokens strictly in-memory inside isolated V8 execution environments. MinTok never writes your raw code, diffs, or repository contents to persistent disk or databases.
  • Upstream Abuse Monitoring: Consistent with standard upstream provider enterprise policies (OpenAI, Anthropic, Google), requests may be held temporarily by upstream model providers solely for automated safety and abuse detection (typically 0 to 30 days maximum) before automatic cryptographic deletion.
  • Bring Your Own Key (BYOK): When utilizing MinTok Engine with your own API keys, your direct enterprise agreement, zero-retention addendum, and business associate agreements with the upstream provider govern all sessions.

3. Information We Collect

We collect only the bare operational metadata required to deliver billing and rate-limiting:

  • Account Credentials: Email address, optional developer name, and hashed authentication tokens for workspace ownership.
  • Usage Telemetry: Token quantities (prompt tokens, completion tokens, avoided tokens) and latency statistics for credit deduction and dashboard analytics.
  • Payment Records: Billing identifiers processed securely by Stripe with zero local storage of credit card numbers.

4. Edge Security & Tenant Isolation

All API requests terminate at the nearest Cloudflare edge PoP over TLS 1.3 with mandatory HTTP Strict Transport Security (HSTS). Sessions utilize host-only cookies (__Host-) to prevent cross-domain credential leakage.

5. GDPR, CCPA, and Data Deletion

You may request complete deletion of your MinTok account and associated credit ledgers at any time by contacting privacy@adstim.net. Account records will be purged within 48 hours.

6. Google API Services User Data Policy Compliance (Google OAuth)

MinTok's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Scopes Requested: When you choose to authenticate via Google OAuth, MinTok requests access only to standard, non-sensitive identity scopes: openid, email, and profile.
  • Purpose of Access: We access this information solely to verify your identity, provision your MinTok developer workspace, and issue your secure session cookie.
  • No Data Resale or Advertising: MinTok never sells your Google user data, never transfers it to data brokers, and never uses it for advertising or behavioral profiling.
  • Zero Model Training: Google user profile data is never used to train, retrain, or improve generalized machine learning or artificial intelligence models.
  • Access Revocation: You can revoke MinTok's access to your Google account at any time via your Google Security Settings.