Skip to content

Your work stays on your computer.

Optional performance contributions, no prompts, responses, code or account details. No advertising or behavioral analytics. Contributions use a persistent pseudonymous identity; they are not fully anonymous.

Updated 4 October 2026. Sharing notice version: 2026-10-04. Terms and legal notice.

Who is responsible

ILO APPLICATIONS SL
CIF / NIF: B93663862
Calle Artemisa 2, 29640 Fuengirola, Malaga, Spain
Registro Mercantil de Málaga: tomo 5805, libro 4712, folio 12, sección 8, hoja MA148941, inscripción 1 (28 January 2019).
Support: [email protected]
Legal and privacy: [email protected]

ILO APPLICATIONS SL is the controller for the Tokrate community service and website. Use the email or postal address above for privacy questions or rights requests.

Your choice comes first

From version 0.1.11, no contribution, community request or sharing-key access occurs until you select “Yes, let's contribute”. “Only for local use” keeps monitoring and local history available without sharing. A saved OFF choice stays OFF. Earlier ON settings without a consent record require a new choice after upgrading; they are not treated as consent. Older releases used default-on sharing: please upgrade or turn sharing off.

You can withdraw consent at any time using the sharing toggle, as easily as enabling it. Turning sharing off stops contribution and in-app community requests, clears the queue, and hides community comparisons and alerts. The OFF setting is saved across launches. Withdrawal does not affect the lawfulness of earlier consent-based processing and does not itself erase data already received. Contact us about erasure. The public website remains free to view.

Local monitoring

Monitoring starts automatically at launch. Tokrate reads supported Codex, Claude Code and Grok Build logs locally and retains seven days of derived performance history. It does not copy prompts, responses, shell commands or repository paths into its measurement history. The local parser necessarily reads log files that may contain this material. Those files are not uploaded. A local notice-version, choice and time record remembers your sharing decision; it is not an advertising identifier.

What contributions contain

Only turns completed after launch or after you enable sharing are eligible; earlier history is never backfilled. Records include a random sample ID, a five-minute UTC timestamp bucket, coding tool, model, inference provider, explicitly recorded reasoning effort or Unknown, client/app/parser/metric versions, source classification, output and reasoning counts, whole-turn duration and Codex-reported first-token time when available. No region, prompt, response, code, path, original session ID, name or account details are included.

Your operating system credential store holds a signing key (Mac Keychain, Windows Credential Manager or Linux Secret Service). The server receives a public key/signature and stores a hash of that key with measurements. A reporting registry stores that hash and first/last reporting times for contributor coverage. It does not count installations that never report. Signatures prove key control, not truthful measurements or unique people.

Purposes and legal bases

Optional contribution and community comparison processing relies on your consent (GDPR Article 6(1)(a)) in consent-enabled clients. You do not need to consent to use local monitoring. Essential website delivery, transient abuse limits, software-update delivery and proportionate service-security operations rely on our legitimate interests in operating and protecting a free service (Article 6(1)(f)). You may object to interest-based processing; we assess the request under the applicable conditions. Administration of authorized operator access relies on those same security interests. Handling rights requests and applicable legal duties relies on Article 6(1)(c), where required by law.

Tokrate does not measure answer quality, build advertising profiles, sell contribution data, or make automated decisions about people with legal or similarly significant effects. Its statistical status indicators concern model observations.

Publication and retention

Server samples expire after 30 days through asynchronous database deletion. Local derived history lasts seven days; the in-memory retry queue lasts at most 24 hours and clears when sharing stops or the app exits. Normal publication requires at least 10 reporting keys and 50 eligible turns per metric. Clearly labelled Early data can show one installation and one turn, so a published value may reflect one person's workload. Contributor identifiers are never published. Public results and API responses can be copied by others.

The current reporting registry retains first/last reporting dates for lifetime counts after samples expire. Backups can retain older records beyond the active database period. We are reviewing finite retention for the registry, logs and backups; we do not claim these proposed schedules are already enforced. Contact us for a data request. There is no self-service server-erasure tool in this release.

Website, recipients and connections

The public site needs no account and has no advertising or behavioral analytics trackers. The browser saves a theme preference; administrator login uses essential authentication and security cookies. Authorized company operators can access operational data. Cloudflare and the hosting infrastructure process connection information, including IP addresses, to deliver and protect the service. IP-based rate limits are transient. Application HTTP logs omit request headers, raw URLs and IP addresses; infrastructure error logs may still contain connection metadata.

Cloudflare provides edge delivery and security. GitHub distributes public source and release downloads under its own privacy arrangements. Hosting, backup and support providers may process data on our behalf. International processing may occur when using these services. Applicable processor terms, locations and transfer safeguards must be assessed for the actual company accounts; we do not claim EU-only processing or a particular safeguard without that verification. See Cloudflare's privacy policy and GitHub's privacy statement.

Software updates are separate

Updater-enabled companions (from version 0.1.10) have automatic update checks on by default with a separate switch. Turning community sharing off does not turn update checks off. You can disable automatic checks and check manually. Checks contact tokrate.dev and downloads contact GitHub; those services receive ordinary connection information such as IP address and user agent. Update traffic contains no contribution identity, measurements or agent content. Mac system-profile reporting is disabled. Compatible update packages are signature-verified; installation requires your action.

Your rights and requests

Subject to the GDPR's conditions, you can request access, rectification, erasure, restriction or portability and object to relevant processing. You may withdraw consent without detriment to local use. Contact the controller above; we normally respond within one month, with any lawful extension explained. You can complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.

We have no contributor accounts and may need evidence that you control the relevant signing identity. Do not send a private key, password or agent transcript. A public fingerprint alone does not authorize deletion. We will seek proportionate verification and will not ask for identity documents by default. Some records may need restriction or retention for legal obligations or claims. Backups must be handled so a restore does not silently reintroduce erased contributions.

Inspect the implementation

The MIT-licensed companions are open source. Review the upload allowlist yourself—or ask your AI agent to check it. The backend is proprietary and publishes its accepted fields in the public API schema. Open source is an inspection aid, not a legal-compliance certification.