TokenLoop

Privacy

Last updated: August 9, 2026

Who we are

TokenLoop is a free product of ARC Transformation Group. Contact: aking@arctransformationgroup.com.

What we collect

  • Account email and password hash (via Supabase Auth).
  • Organization name and optional Slack webhook URL.
  • Provider admin API keys you paste (Anthropic / Cursor) — encrypted at rest; never shown again in the UI.
  • Usage aggregates we pull from those providers (spend, tokens, user emails from the provider).
  • Audit events for connect, sync, and kill-switch actions.

How keys are protected

Admin keys are sent once over HTTPS to our API, encrypted with AES-256-GCM using a server-only encryption key, and stored as ciphertext in our database. We decrypt them only on the server to call provider admin APIs. We do not log plaintext keys or return them to the browser.

Processors

  • Supabase — auth and database hosting.
  • Vercel — application hosting.
  • Resend — transactional email (password reset / magic links).

Your choices

You may request deletion of your account and stored keys by emailing us. You can rotate provider keys anytime in Settings.

← Home · Terms