Legal

Privacy Policy.

We only collect what we need. We never sell your data. Your prompts stay yours.

What This Policy Covers
Information We Collect
How We Use Your Information
User IDs & Your End Users
Data Sharing
Self-Hosted Deployments
Data Retention
Security
Cookies
Your Rights
Children
Changes to This Policy
Contact
Last updated: April 2026
Questions? hello@llmcosttracker.com

Also see: Terms of Service
The short version
We never see your prompts or responses
We never sell your data
Self-hosted means zero data leaves your infra
Delete your account, data gone in 30 days
01
What This Policy Covers

This Privacy Policy describes how LLM Cost Tracker ("we," "us," "our") collects, uses, and protects information when you use our website and Service.

It does not cover how your end users' data is handled by your own application — that is your responsibility as the developer integrating the SDK.

02
Information We Collect
Account information

When you sign up, we collect your name, email address, and company name.

Billing information

Payment details are processed by Stripe. We store only the last four digits of your card and billing address for your records.

LLM event metadata

When you use the SDK, we receive and store per-call metadata:

FieldDescription
modelModel name and version (e.g. claude-sonnet-4-6)
input_tokensNumber of input tokens sent
output_tokensNumber of output tokens returned
cost_usdCalculated cost in USD
latency_msRequest latency in milliseconds
featureFeature tag you define (e.g. "summarization")
user_idYour app's user identifier, supplied by you
prompt_versionVersion label you pass in to track prompt changes
created_atTimestamp of the call
We do not receive the text of your prompts or your AI model's responses. Only metadata about the call is transmitted.
Usage analytics

We collect standard dashboard analytics (page views, feature usage) to improve the product. We use privacy-respecting analytics and do not sell this data.

Support communications

If you contact us, we retain that correspondence.

03
How We Use Your Information

We use the information we collect to:

  • Provide and operate the Service
  • Display your usage data in the dashboard
  • Send transactional emails (receipts, plan limit alerts, account notifications)
  • Respond to support requests
  • Improve the product based on aggregate usage patterns
  • Comply with legal obligations
We do not sell your data. We do not use your LLM event data to train AI models.
04
User IDs & Your End Users

The SDK allows you to pass a userId parameter so you can attribute LLM costs to specific users of your application. You control what value you pass.

We recommend using an internal identifier (e.g., a UUID) rather than an email address or real name. You are responsible for ensuring your use of user attribution complies with your own privacy policy and applicable law.

05
Data Sharing

We share data only with:

  • Service providers who help us operate the platform — Supabase/PostgreSQL for storage, Vercel for hosting, Stripe for billing. These providers are bound by data processing agreements.
  • Law enforcement or legal process, when required by applicable law and only to the extent required.

We do not share your data with advertisers, data brokers, or AI providers.

06
Self-Hosted Deployments

If you use the self-hosted option, your event data is stored entirely in your own infrastructure. We have no access to it. Only your account registration data (email, plan) is held by us.

This is the recommended option for teams with compliance requirements in fintech, healthcare, or enterprise environments.

07
Data Retention

LLM event data is retained for as long as your account is active, plus 30 days after termination. You can request deletion of your data at any time by contacting us.

Account information (email, billing records) is retained as required by law for tax and compliance purposes.

08
Security

We use Supabase Row Level Security (RLS) to ensure your project data is only accessible to your account. Data is encrypted in transit (TLS) and at rest. API keys used for SDK authentication are hashed before storage.

If you discover a security vulnerability, please contact us at security@llmcosttracker.com before disclosing publicly.

09
Cookies

We use essential cookies for authentication (session management). We do not use third-party advertising cookies.

If we add analytics cookies, we'll update this policy and request consent where required by applicable law.

10
Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt out of marketing emails (every email includes an unsubscribe link)

To exercise any of these rights, contact us at privacy@llmcosttracker.com. We'll respond within 30 days.

11
Children

The Service is intended for businesses and developers. We do not knowingly collect data from individuals under 16. If you believe we have inadvertently collected such data, contact us for immediate deletion.

12
Changes to This Policy

If we make material changes, we'll notify you by email or in-app notice before the changes take effect. The "last updated" date at the top of this page always reflects the current version.

13
Contact

For privacy questions or data requests: hello@llmcosttracker.com