Privacy policy
Last updated: 2026-06-14
1. Controller
Controller for data processing on tokenmoth.com within the meaning of the GDPR:
Martin Dehlan, Am Breiten Luch 46, 13053 Berlin, Deutschland
Email: legal@tokenmoth.com
Full details in the legal notice.
2. What data we process
a) Account & authentication
When you sign in (OAuth login via Supabase) we process your email address and a user ID. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
b) Usage / telemetry data
TokenMoth records metrics about your Claude Code usage: token counts, estimated cost, model names, repository names, session metadata and plugin/hook overhead. The locally installed hook sends these via an API key to our API. Transcripts/source code are not transmitted. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
c) Server logs
When you access the website, technically necessary data (e.g. IP address, timestamp, user agent) is processed by our hosting provider. Legal basis: legitimate interest in operation and security (Art. 6(1)(f) GDPR).
d) Product analytics (consent only)
With your consent we use PostHog to analyse usage and improve TokenMoth. Without consent no analytics take place. Legal basis: consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw consent at any time via Cookie settings in the footer.
3. Cookies & local storage
Technically necessary cookies (e.g. to keep your Supabase login session) are set on the basis of § 25(2) TDDDG without consent. Your cookie/analytics choice is stored locally in your browser. Optional analytics cookies are only set after your consent.
4. Recipients / processors
To provide the service we use the following providers. Data processing agreements under Art. 28 GDPR are in place with each:
| Service | Purpose | Region | Transfer |
|---|---|---|---|
| Supabase | Authentifizierung & Datenbank (Account, Nutzungsdaten) | EU (Irland, eu-west-1) | EU-Region — kein Drittlandtransfer |
| Amazon Web Services (AWS) | Hosting der Web-App (Amplify) und API (App Runner/Lambda), Server-Logs, Software-Downloads (S3/CloudFront) | EU (Frankfurt, eu-central-1) | Verarbeitung in EU-Region; SCC (AWS DPA) |
| PostHog | Produkt-Analytics (nur nach Einwilligung) | EU (eu.i.posthog.com) | EU-Region — kein Drittlandtransfer |
| Anthropic | Claude Code erzeugt die Nutzungsdaten lokal; TokenMoth sendet keine Transcripts/PII an Anthropic | USA (nur clientseitig durch Nutzer:in selbst) | kein Transfer durch TokenMoth |
5. Retention
We store account and usage data for as long as your account exists. After account deletion the associated data is deleted; statutory retention obligations (e.g. tax law for invoices) remain unaffected. Specific retention periods: usage data is kept until you delete your account; server logs are deleted after 14 days; invoice data is retained for 10 years under statutory tax law (§ 147 AO, § 14b UStG).
6. Your rights
Under the GDPR you have in particular the following rights:
- access to the data stored about you (Art. 15)
- rectification of inaccurate data (Art. 16)
- erasure (Art. 17) — directly via “Delete account” in settings
- restriction of processing (Art. 18)
- data portability / export (Art. 20) — via the export function in the dashboard
- objection to processing based on legitimate interests (Art. 21)
- withdrawal of consent with effect for the future (Art. 7(3))
An email to legal@tokenmoth.com is sufficient to exercise these. You also have the right to lodge a complaint with a supervisory authority.
7. Changes
We adapt this privacy policy when processing changes. The version published on this page applies.