Privacy policy

This policy explains how TOKRACE processes information when you browse, run model comparisons, sign in, sync data, or publish a share.

Updated: September 9, 2026

1. Local data and model requests

Model configurations, API keys, prompts, run history, and preferences are saved in your browser's localStorage by default. Local storage is not the same as an encrypted vault: someone with access to your browser may access this data. Clearing site data removes local copies.

When you run a comparison, your prompt, supplied images, parameters, and required credentials are processed by TOKRACE's request proxy and sent to the model endpoint you select. The proxy does not intentionally persist request bodies or API keys. The selected provider processes requests under its own policies. Optional public sharing and encrypted cloud backups are described below.

2. Accounts and optional cloud sync

Account features use Supabase. Signing in processes your account identifier, email and profile information supplied by the login provider, and stores a login session in your browser. Free quotas and referral rewards use account or device identifiers, usage records, and network information to operate the service and prevent abuse.

Cloud sync happens when you choose to upload. The backup can include API keys, prompts, history, and settings. It is encrypted in your browser with your sync passphrase before being stored in Supabase. The sync passphrase is not uploaded. Keep it safe: we cannot recover an encrypted backup without it.

3. Public shares and contributions

Publishing a share stores the selected prompt, model outputs, title, notes, and measurement data as a public snapshot. API credentials and custom endpoint URLs are excluded from the snapshot fields. Anyone with the link may view or copy the published content. Check it before publishing, especially text that may itself contain private information. You can disable or delete your shares in My Center; copies already made by others may remain.

If you opt in to anonymous measurement sharing, we store model and provider identifiers, timing and token metrics, input/output character counts, a random device identifier, and consent records. This contribution excludes prompt text, outputs, images, and API keys. Votes and comments you submit may be shown publicly.

4. Site analytics and security

We use Vercel Web Analytics and Speed Insights to understand page traffic and performance. They process page URLs, referrers, browser/device information, approximate location, and performance measurements. These site statistics are separate from voluntary model measurement contributions. Hosting and abuse prevention may also process IP addresses, request metadata, and operational logs.

Vercel Web Analytics · Vercel Speed Insights

5. Cookies and Google advertising

Cookies or local storage support language preferences, login sessions, device identification, and your saved settings. When Google AdSense ads are enabled on a page, third-party vendors including Google may use cookies, web beacons, IP addresses, or other identifiers to deliver, measure, and personalize advertising.

Google and its partners may use advertising cookies to serve ads based on previous visits to this site or other websites. Where required, a consent message will let you manage advertising choices before applicable storage or personalization is enabled. Rejecting personalized advertising does not necessarily remove all ads.

Manage Google ad personalization · How Google uses information · Other vendors' advertising choices

6. Service providers and retention

Vercel provides hosting and analytics, Supabase provides account and database services, and model providers process the requests you send to them. Some requests may pass through Cloudflare when the configured transport uses it. These providers may process information outside your country. Advertising partners, when enabled, process information as described above.

Local data remains until you remove it. Account records, shares, encrypted backups, and service records are retained as needed to provide the corresponding feature, handle requests, prevent abuse, and meet applicable obligations. Removing browser data does not remove cloud records or public shares. Provider backups may expire on a different schedule.

7. Your choices and contact

You can clear local site data, sign out, stop cloud uploads, change measurement-sharing consent, and manage your public shares. For access, correction, deletion, or other privacy requests, contact the maintainers through the contact page. We may need to verify ownership before changing account or shared data. Do not send API keys or passwords.

The site is intended for developers and AI reviewers and is not directed at children. We update this policy when the service changes and display the revised date above.

Contact TOKRACE