TokenLoop
Privacy
Last updated: August 9, 2026
Who we are
TokenLoop is a free product of ARC Transformation Group. Contact: aking@arctransformationgroup.com.
What we collect
- Account email and password hash (via Supabase Auth).
- Organization name and optional Slack webhook URL.
- Provider admin API keys you paste (Anthropic / Cursor) — encrypted at rest; never shown again in the UI.
- Usage aggregates we pull from those providers (spend, tokens, user emails from the provider).
- Audit events for connect, sync, and kill-switch actions.
How keys are protected
Admin keys are sent once over HTTPS to our API, encrypted with AES-256-GCM using a server-only encryption key, and stored as ciphertext in our database. We decrypt them only on the server to call provider admin APIs. We do not log plaintext keys or return them to the browser.
Processors
- Supabase — auth and database hosting.
- Vercel — application hosting.
- Resend — transactional email (password reset / magic links).
Your choices
You may request deletion of your account and stored keys by emailing us. You can rotate provider keys anytime in Settings.