Privacy Policy
Effective 2026. Last updated alongside TokenShrinker 1.0.
This page covers two things: the TokenShrinker desktop app, and the account system at osparlabs.com. The desktop app's End User Licence Agreement is the source of truth for how it handles your data; this page does not contradict it, and repeats the relevant parts here so you don't have to read a licence agreement to find them.
What never leaves your machine
Prompt text, documents, images, source code, logs, and every other input you give the desktop app are processed in memory on your own device. We never receive them and have no facility to receive them. This applies to prompt compression, secret scanning, loop detection, cache alignment, and file ingestion, without exception. Your AI provider API keys are encrypted on your device with your operating system's credential store and are sent only to the provider you've configured them for.
The one thing that does leave your machine by design is the request you deliberately send to an AI provider, that's the point of the tool. That request goes from your machine to your chosen provider using your own credentials, under that provider's own privacy policy, exactly as if you'd called them directly. We are not a party to that exchange and cannot see it.
What we do collect
- Account email. Used to sign in (by emailed code) and to identify your subscription. We don't require a password or any other personal detail to create an account.
- Subscription and billing status. Your plan tier and renewal date, so the app knows what you're entitled to. Card details are handled entirely by Stripe; we receive a customer and subscription identifier, never your card number.
- Device records, if you're on a plan with a device limit. A device name (defaults to the hostname, editable), platform, app version, and a fingerprint derived from your hostname, platform, processor architecture, and a random id, so we can enforce "up to N machines" without asking you to log in constantly. You can see and remove your own devices from the account page.
- Aggregate usage figures, only if you turn this on. It's off by default. If enabled, the app periodically sends request counts, token totals, savings figures, app version, and operating system. Before anything is sent, API keys, email addresses, and file paths are stripped out. Prompt content is never included under any setting.
Cookies
Signing in on osparlabs.com sets two cookies, sb-access
and sb-refresh. Both are httpOnly (no
script running on the page, ours or anyone else's, can read them), used only to keep you signed in, and expire
automatically. We do not run any third-party analytics, advertising, or tracking script on this site.
Who else sees any of this
We use a small number of service providers to run the account system and billing, and we share only what each one needs to do its job:
- Supabase: authentication, the account database, and delivery of sign-in codes.
- Stripe: payment processing and billing management.
We do not sell your data, and we do not share it with anyone else for their own marketing purposes.
How long we keep it
Account, device, and subscription records are kept for as long as your account is active. If you delete your account, we delete the associated records, other than what we're required to keep for tax, fraud-prevention, or other legal obligations.
Your choices
You can review and remove your own devices, and manage or cancel your subscription, from the account page. For anything else, correcting your details, exporting your data, or deleting your account entirely, email [email protected] and we'll handle it directly.
Children
TokenShrinker is a developer tool and isn't directed at children. We don't knowingly collect data from anyone under 13.
Changes to this policy
If this policy changes in a way that affects what we collect or how we use it, we'll update this page and the "last updated" date above. Material changes will be announced in the app or by email to registered users.
Contact
OsparLabs, [email protected]
For how the desktop app itself handles compression, secret scanning, and licence verification in detail, see the Terms of Service and the End User Licence Agreement shown during installation.