Privacy Policy

Last updated: September 17, 2026

TokenBurn ("we", "us") is an LLM spend monitoring service operated by Beakman AI. This policy explains what data we access, what we store, and why. Questions? Email andre@beakman.ai.

What we access at OpenAI and Anthropic

To connect an organization you paste an Admin API key from OpenAI or Anthropic. We use it only to call the read-only usage, cost and naming endpoints of the provider's Admin API:

  • Costs — daily spend by project or workspace and line item.
  • Usage — daily token counts by project or workspace, model, user and API key.
  • Names — the projects or workspaces, users and API keys in the organization, so we can show names instead of IDs.

These endpoints return counts and totals only. We never read or send prompts or completions, and TokenBurn never calls endpoints that create, modify or delete anything in your OpenAI or Anthropic organization. Note that Admin keys themselves are not read-only — they are full organization credentials — so create a dedicated key with the least access your provider allows, and revoke it at the provider if it is ever exposed.

How we store your Admin API keys

A key is validated once and encrypted immediately with AES-256-GCM. The encryption key lives in Google Secret Manager and is only available to our backend while it syncs your data. The encrypted key is stored in Firestore in a collection your browser cannot read; after submission, only the last four characters are ever shown to you. Keys are never logged. Removing a connection in Settings deletes the encrypted key along with it.

What we store

We store the minimum needed to render your dashboard, in Google Firestore (Firebase):

  • Your account: email, display name, and (optionally) a profile photo from Google.
  • Your settings: monthly budget, per-project budgets, and whether you want the daily digest.
  • Your connections: provider, organization ID and name, the display name you chose, the last four characters of the key, and which projects or workspaces you chose to watch.
  • Aggregated snapshots: spend totals by project or workspace, model, line item and day, plus token counts by model, user and API key. We store aggregates — never prompts, completions or request contents.
  • Your daily digests — the same summary as the email, kept as a record.

Authentication

Sign-in is handled by Firebase Authentication (email/password or Google sign-in). We do not store your password.

Email

If the daily digest is on, we send one email per day to the address on your account. You can turn it off in Settings.

Analytics & cookies

We use Google Analytics 4 to understand traffic (page views, referral source). It loads only after you accept the cookie banner, and IP addresses are anonymized. If you decline, no analytics cookies are set and no analytics script loads. You can change your mind by clearing your browser's site data.

Who we share data with

We do not sell your data. We share it only with the infrastructure providers required to run the service: Google Firebase (hosting, authentication, database and the sync backend — servers in the United States), our email delivery provider (for the daily digest) and Google Analytics (traffic measurement). Your usage and cost data is read directly from your own OpenAI or Anthropic organization and is not shared with third parties.

Data retention & deletion

You can remove a connection at any time in Settings. This deletes the encrypted key and the stored snapshot for that organization and stops future syncs. To delete your account and all associated data, email andre@beakman.ai and we will erase it.

Your rights

Under the LGPD (Brazil) and GDPR (EU), you may request access to, correction of, or deletion of your personal data. Contact us at the address above.

Changes

We may update this policy as the product evolves; the "last updated" date above reflects the latest version.