Privacy Policy

What personal data TrayToken collects from website visitors, Customer accounts, and Monitored Users — how we use, share, and protect it, and the rights you have over it. Last updated: July 8, 2026.

1. Introduction

TrayToken (“TrayToken”, “we”, “us”, or “our”) is operated by TrayToken OÜ, a company registered at Sepapaja tn 6, 15551 Tallinn, Estonia. TrayToken provides an engineering-intelligence platform, available at https://traytoken.com/, that helps organizations understand how their engineering teams work with AI tools (the “Services”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use, share, store, and protect it, and what rights you have in relation to it. It applies to three groups of people: visitors to our website, individuals who administer or use a TrayToken account on behalf of an organization that has purchased the Services (our “Customers”), and engineers and other staff whose interactions with AI tools are recorded through the Services at a Customer's direction (“Monitored Users”).

Because the Services record how engineers work with AI tools, we collect information that many software products do not. This includes the identity of individual engineers, the text of prompts they submit to AI tools, and the names of the projects and files they work on. Sections 4 and 5 describe this in detail. Please read this policy carefully before using the Services. If you do not agree with this policy, do not access or use our Services and/or interact with any other aspect of our business.

2. Our Roles: When We Act as Controller and When as Processor

Data protection laws distinguish between a “controller”, which decides why and how personal data is processed, and a “processor”, which processes personal data on a controller's instructions. TrayToken acts in both roles, depending on the data involved.

We act as a controller for personal data relating to website visitors, sales prospects, and Customer account administrators: for example, contact details submitted through our website, billing information, account credentials, and analytics about how our website and the Services themselves are used.

We act as a processor (or “service provider” under California law) for monitoring data about Monitored Users, including engineer identity, prompt text, and project and file names. Our Customer, typically your employer or the organization you work for, is the controller of that data. The Customer decides which engineers are monitored, which AI tools are covered, and how long monitoring data is kept, and the Customer is responsible under applicable law for informing you that monitoring takes place and for establishing a lawful basis for it. If you are a Monitored User and you have questions about why you are being monitored, your employer's privacy notice is the primary document that governs that processing, and requests about it should normally be directed to your employer. We support our Customers in responding to such requests, as described in Sections 12 and 13.

3. Personal Data We Collect

We collect personal data in three ways: you provide it to us directly, we collect it automatically through the Services and our website, and we receive it from third parties.

Data you provide directly

This includes your name, work email address, job title, employer name, and phone number when you create an account, request a demo, contact support, or subscribe to communications; billing and payment details when your organization purchases the Services (payment card numbers are handled by our payment processor and are not stored on our systems); and the content of any messages you send us.

Data we collect automatically through the monitoring features of the Services

When a Customer deploys TrayToken to its engineering team, the Services collect the following about each Monitored User:

  • Engineer identity. Name, work email address or username, team or department, and internal identifiers assigned by the Customer's systems, so that AI-tool activity can be attributed to the correct person.
  • Prompt text. The text of prompts and related inputs that a Monitored User submits to AI tools covered by the Customer's deployment, together with metadata such as the tool used, timestamps, and response characteristics.
  • Project and file names. The names and paths of repositories, projects, branches, and files associated with a Monitored User's AI-tool activity, so that usage can be linked to specific work.
  • Usage and technical data. Frequency and duration of AI-tool sessions, feature-level usage events, device and browser type, operating system, and IP address.

Data we collect automatically through our website

Like the operators of most websites, we collect IP address, browser type, device information, pages visited, time spent on pages, referring pages, and approximate location derived from IP address. Section 7 explains the cookies and similar technologies involved.

Data we receive from third parties

We may receive personal data from the Customer's identity provider or directory service (for example, to provision Monitored User accounts), from the AI tools and development platforms that the Customer connects to TrayToken, and from publicly available professional sources used for sales outreach, such as a company website or a professional networking profile.

We do not intentionally collect special categories of personal data (such as health data, religious beliefs, or biometric data), and we ask that you do not submit such data to us. Section 5 explains what happens when such data appears inside prompt text despite this.

4. Explicit Disclosure: Engineer Identity, Prompt Text, and Project and File Names

We want the core of what TrayToken does to be unmistakable, so we state it plainly here. When your organization deploys TrayToken, we collect and process, on that organization's behalf:

  1. Who you are. Your identity as an individual engineer, linked to your activity.
  2. What you ask AI tools. The full text of the prompts you submit to covered AI tools.
  3. What you are working on. The names of the projects, repositories, and files connected to that activity.

This data is made available to your organization through dashboards, reports, and exports. Depending on how your organization configures the Services, managers, administrators, and other authorized personnel at your organization may be able to view your individual prompts and activity, not only aggregated statistics. Your organization controls those configuration choices, not TrayToken.

5. Prompt Text and File Names May Contain Personal or Confidential Information

Prompt text is free-form. A prompt written to an AI tool may incidentally contain personal data about the engineer who wrote it or about third parties (for example, names in a bug report, customer details in a support ticket being summarized, or personal remarks). Project and file names may reveal confidential product plans, client names, or the structure of proprietary source code. We treat this risk directly rather than assuming prompts are harmless telemetry:

  • We treat all prompt text and file-name data as potentially containing personal data and confidential information, and we apply the security measures described in Section 11 to it in full.
  • We do not use prompt text, file names, or any other Customer monitoring data to train our own or any third party's machine-learning models, and we contractually prohibit our subprocessors from doing so.
  • We do not read, mine, or analyze the substantive content of prompts for our own purposes. Our own use of monitoring data is limited to operating, securing, and supporting the Services and, where our agreement with the Customer permits, producing aggregated and de-identified statistics that do not identify any individual or reveal any Customer's confidential content.
  • Customers can configure exclusions and redaction rules (for example, excluding named repositories or masking detected patterns such as email addresses and access tokens) before data is stored.
  • If you are a Monitored User, avoid including personal data or credentials in prompts where you can. Your organization's policies on acceptable AI-tool use apply alongside this policy.

6. How We Use Personal Data and Our Legal Bases

Where the GDPR or UK GDPR applies and we act as controller, we rely on the legal bases listed below. Where we act as processor, we process monitoring data only on the documented instructions of the Customer, and the Customer is responsible for its own legal basis, which for workplace monitoring is typically its legitimate interests, assessed and documented by the Customer.

PurposePersonal data involvedLegal basis (as controller)
Providing, operating, and maintaining the Services and Customer accountsAccount data, usage and technical dataPerformance of a contract (Art. 6(1)(b))
Processing monitoring data (engineer identity, prompt text, project and file names) on a Customer's behalfMonitoring dataNot applicable — we act as processor on the Customer's instructions
Billing, invoicing, and account administrationAccount and billing dataPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records
Securing the Services, detecting fraud and abuse, and logging accessUsage and technical data, account dataLegitimate interests (Art. 6(1)(f)): keeping the Services and their data safe
Improving the Services and developing new features, using aggregated or de-identified data wherever possibleUsage and technical data; aggregated monitoring statisticsLegitimate interests (Art. 6(1)(f)): understanding how the Services perform
Responding to inquiries and providing supportContact data, message content, account dataPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for pre-contract inquiries
Sending marketing communications about our ServicesContact dataConsent (Art. 6(1)(a)) where required; otherwise legitimate interests (Art. 6(1)(f)), always with the ability to opt out
Complying with legal obligations and responding to lawful requestsAny of the above, as requiredLegal obligation (Art. 6(1)(c))
Establishing, exercising, or defending legal claimsAny of the above, as requiredLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms; you may object as described in Section 12. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing that took place before withdrawal.

7. Cookies and Tracking Technologies

Our website and the Services use cookies and similar technologies (such as pixels and local storage) in three categories:

  • Strictly necessary. Required for the website and Services to function, including sign-in and security. These cannot be switched off through our banner.
  • Analytics. Used to understand how visitors use our website and how Customers use the Services, so we can improve them. We use third-party analytics providers for this purpose; their identities are available on request at [email protected].
  • Preference and marketing. Used to remember your settings and, on our public website only, to measure the effectiveness of our marketing.

Where the law requires consent for non-essential cookies, we present a consent banner when you first visit, and you can change your choices at any time through the cookie settings link on our website. You can also refuse or delete cookies through your browser settings, although parts of the website may not function without strictly necessary cookies. We honor the Global Privacy Control (GPC) signal as an opt-out where applicable law, including California law, requires us to do so. We do not respond to other “Do Not Track” browser signals, for which no common standard has been adopted.

We do not use monitoring data (engineer identity, prompt text, or project and file names) for advertising, and we do not permit advertising networks to access it.

8. How We Share Personal Data

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only in the following circumstances:

  • To your organization. If you are a Monitored User or an account user, your activity data, including engineer identity, prompt text, and project and file names, is disclosed to the Customer that deployed TrayToken, in line with that Customer's configuration.
  • To subprocessors and service providers. We use third-party providers for cloud hosting and storage, payment processing, customer support tooling, email delivery, and analytics. Each provider is bound by a written contract that limits its use of personal data to the services it performs for us, imposes confidentiality and security obligations, and, for Customer monitoring data, prohibits any use for the provider's own purposes, including model training. A current list of subprocessors that handle Customer monitoring data is available on request at [email protected].
  • To comply with law. We may disclose personal data where required by law, regulation, legal process, or a binding governmental request, or where disclosure is necessary to protect the rights, property, or safety of TrayToken, our Customers, or others. Where legally permitted, we will notify the affected Customer before disclosing its monitoring data.
  • In corporate transactions. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality protections and to this policy or a successor policy that provides at least equivalent protection.
  • With your consent. We share personal data for any other purpose only after telling you and, where required, obtaining your consent.

We may create and share aggregated or de-identified information that cannot reasonably be used to identify you or to reveal any Customer's confidential content, for example industry benchmarks on AI-tool adoption.

9. International Data Transfers

We are based in Estonia, and our primary data hosting is located in the European Union (AWS data centers in Frankfurt, Germany). Your personal data may be transferred to, and processed in, countries other than the one in which you live, including countries that have not been found by the European Commission or the UK Government to provide an adequate level of data protection.

Where we transfer personal data originating in the European Economic Area, the United Kingdom, or Switzerland to such countries, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses, supplemented where needed by the UK International Data Transfer Addendum and the Swiss recognized version, together with additional technical and organizational measures where our transfer risk assessment calls for them. Customers may request a copy of the relevant safeguards at [email protected]. Where a transfer destination benefits from an adequacy decision, we may rely on that decision instead.

10. How Long We Keep Personal Data

We keep personal data no longer than needed for the purposes described in this policy, and then delete or de-identify it. Specifically:

  • Monitoring data (engineer identity, prompt text, project and file names) is retained for the period set in our agreement with the Customer or configured by the Customer within the Services, with a default retention period of 12 months. When a Customer's subscription ends, we delete or return its monitoring data within 30 days, except for limited backup copies that are deleted on a rolling schedule of no more than 35 days.
  • Account and billing data is retained for the duration of the Customer relationship and afterwards for as long as required by tax, accounting, and other legal obligations, and for the applicable limitation periods for legal claims.
  • Website and marketing data is retained until it no longer serves the purpose it was collected for, until you opt out or withdraw consent, or until the retention period set in our internal retention schedule expires, whichever comes first.

Where immediate deletion from backup archives is not technically practicable, we isolate the data from further processing until deletion completes.

11. How We Protect Personal Data

We apply technical and organizational measures appropriate to the risk of the data we handle, and we treat prompt text and file names as high-sensitivity data for this purpose. Our measures include encryption of data in transit and at rest, role-based access controls and the principle of least privilege for our personnel, multi-factor authentication, logging and monitoring of access to production systems, vendor security reviews, regular independent security testing, and a documented incident-response process. Our personnel with access to Customer monitoring data are bound by confidentiality obligations and receive privacy and security training.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify affected Customers and, where required by law, regulators and affected individuals without undue delay and within the timeframes the law prescribes.

12. Your Rights Under the GDPR and UK GDPR

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, you have the following rights over personal data for which we act as controller:

  • The right to be informed about our processing (which this policy serves).
  • The right of access to your personal data and to a copy of it.
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure in certain circumstances.
  • The right to restriction of processing in certain circumstances.
  • The right to data portability for data you provided to us and that we process by automated means on the basis of contract or consent.
  • The right to object to processing based on legitimate interests, and an unconditional right to object to direct marketing.
  • The right to withdraw consent at any time, where processing is based on consent.
  • The right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The Services do not make such decisions about Monitored Users; outputs are analytics for human review, and any employment decision based on them is made by your organization.

To exercise these rights, email [email protected] or write to us at Sepapaja tn 6, 15551 Tallinn, Estonia. We may need to verify your identity before acting on a request. We respond within one month, and we may extend that period by up to two further months for complex or numerous requests, in which case we will tell you within the first month. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.

If your request concerns monitoring data (engineer identity, prompt text, or project and file names), your employer or engaging organization is the controller. To make sure your request is handled by the party legally responsible for it, we will refer it to that organization and assist it in responding, as our contract with it requires. You can also raise the request with your organization directly.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of an alleged infringement, or with the UK Information Commissioner's Office if you are in the UK. We would appreciate the chance to address your concerns first, but you may contact a supervisory authority at any time.

13. Your California Privacy Rights (CCPA/CPRA)

This section applies to California residents. In the preceding 12 months, we have collected the following categories of personal information as defined by the California Consumer Privacy Act, as amended by the California Privacy Rights Act: identifiers (such as name, email address, username, and IP address); professional or employment-related information (such as employer, job title, team, and engineer identity within a Customer's deployment); internet or other electronic network activity information (such as prompt text, project and file names, AI-tool usage events, and website analytics); commercial information (such as billing records); and inferences drawn from usage data (such as aggregated productivity metrics). The sources, purposes, and recipients for each category are described in Sections 3, 6, and 8.

We do not sell personal information and have not done so in the preceding 12 months. We do not share personal information for cross-context behavioral advertising. We do not knowingly collect personal information of consumers under 16, so we have no actual knowledge of selling or sharing such information. We do not use or disclose sensitive personal information for purposes other than those permitted by the CCPA, and prompt text is used only as described in Sections 4, 5, and 6.

As a California resident, you have the right to know what personal information we collect, use, disclose, and the categories of sources and recipients; the right to access the specific pieces of personal information we hold about you; the right to correct inaccurate personal information; the right to delete personal information, subject to statutory exceptions; the right to opt out of sale or sharing (which does not apply, as we do neither); the right to limit the use of sensitive personal information as provided by the statute; and the right not to be discriminated against for exercising any of these rights.

To exercise these rights, email [email protected] with the subject line “California Privacy Request”, or write to us at Sepapaja tn 6, 15551 Tallinn, Estonia. You may use an authorized agent, in which case we will ask for proof of the agent's authority. We verify requests by matching the information you provide against information we hold, and we respond within 45 days, extendable by a further 45 days where reasonably necessary, with notice to you. Where we hold your personal information as a service provider to a Customer (as is the case for all monitoring data), we will direct your request to that Customer and assist it in responding.

California Civil Code Section 1798.83 (the “Shine the Light” law) permits California residents to request certain information about disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

14. Children's Privacy

The Services are business tools and are not directed to anyone under 16 years of age (or the higher minimum age that applies in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us at [email protected] and we will delete it.

15. Third-Party Websites and Services

Our website and the Services may contain links to, or integrations with, websites and services we do not operate, including the AI tools and development platforms that Customers connect to TrayToken. Those third parties have their own privacy policies, and this policy does not apply to their processing. We encourage you to read the privacy policy of every service you interact with. Connecting a third-party tool to TrayToken is a Customer decision, and the data that tool provides to us is processed as described in this policy.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in the Services, in law, or in our processing practices. When we do, we will revise the “Last updated” date at the top of this page, and for material changes we will provide more prominent notice, such as an email to account administrators or a notice within the Services, before the changes take effect. If you wish to continue to benefit from the Services please check back periodically for updates to this Privacy Notice, as continued use of the Services constitutes acceptance of all changes.

17. How to Contact Us

Questions, concerns, or complaints about this policy or our handling of personal data can be directed to:

TrayToken OÜ (operating as TrayToken)
Sepapaja tn 6, 15551 Tallinn, Estonia
Email: [email protected]

Our Data Protection Officer can be reached at [email protected]; mark your message “Data Protection Officer”. Because we are established in the European Union, we have not appointed a separate EU representative. We will respond to privacy inquiries as quickly as we can and within the timeframes the law requires.