TokenScale is built privacy-first. The text you paste into the calculator never leaves your browser, we don't use advertising cookies, and we never sell your data. This page explains exactly what is and isn't collected — and your rights under European law.
TokenScale (tokenscale.dev) is operated by Bilton Projects (Will Bilton), the "data controller" for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR. You can reach us about anything on this page at projectsbilton@gmail.com.
The token calculator runs entirely in your browser. When you paste an email, a prompt, or a whole document, the character, word and token counts are computed by JavaScript on your own machine. That text is never transmitted to any server — not ours, not a third party's. Your background/theme choice is stored locally on your device (in your browser's localStorage) so the site remembers it next time; it never leaves your browser and isn't visible to us. The first-timer assist stores one yes/no note so it does not interrupt you again, written once it has actually been on screen for a few seconds or as soon as you close it or act on it, so leaving the page immediately does not use up your one run. Pressing Turn off on its bar stores a second yes/no note so it stays off. Both stay only in your browser and neither is an identifier.
To understand which features are useful, we use two privacy-preserving measurement tools. Neither uses cookies, neither fingerprints you, and neither can identify you as an individual:
localStorage — it contains no identifier and no history, and the only thing reported is the word "new" or "returning"; you can clear it at any time by clearing your browser data. The calculator keeps two notes of the same kind for its "New to AI pricing?" explainer: whether you have opened it before, and whether you pressed "Got it" to shrink it to a small return control. Both are yes/no, both stay in your browser, and neither is an identifier. If you arrive via a link that carries a campaign label (for example ?from=newsletter), we record that label — it describes the link that was shared, not you. We also note a coarse device type — whether the visit was on a desktop, tablet or phone — worked out from your browser's user-agent as one of three broad buckets; we never store the full user-agent string or anything that identifies your specific device. We record the host of the page that referred you (for example google.com, or "direct" if you typed or bookmarked the address) — the hostname only, with any path or query stripped away so nothing personal in a referring link is ever seen, and visits from our own pages are marked simply "internal". Within the calculator, we distinguish at a coarse level whether someone moved a slider or switched a control versus typed or pasted their own text into the live counter — as everywhere else, the pasted text itself is never read or sent; only the fact that a paste happened. The front page opens with a provider wheel that starts on a random provider; we record which provider the wheel happened to open on (an automatic note about the page, not about you — it lets us check the wheel is being fair) separately from providers you actually chose. On the Price Moves page we record which price-move card was scrolled into view, clicked through to the live tool, or shared — identified only by a coarse label of provider, date and tier (for example "anthropic-2026-07-02-pro"). When you follow a link that leaves our site, we record the destination website's hostname only (for example openai.com) — never the full address, path or query. And if a broken link lands on our "page not found" screen, we record the missing page's path (path only, never the query string) so we can fix dead links. When you press through from the front-page wheel into the full calculator, we record the content size you had picked (for example "a novel" or "an email") together with the model the wheel was serving at that moment — as a single coarse label (for example novel~openai). No word counts, and none of the text you type or paste, are ever part of this. For the site tour we record only that a tour started, was completed, or was closed early, tagged as the short "quick" tour or the full "deep dive" (nothing about you, just which of the two flows ran). The front-page wheel and the calculator dock move the page to the thing you are changing, and we record only which of those four movements happened, as one of the fixed words "wheel", "sizes", "model" or "compound", once per page load. It carries no provider, model choice, content size, word count, reply count or typed text. On the comparison table you can now copy or download the table as a spreadsheet; if you do, we record only which format you took it in ("csv" or "tsv") — never the tier, the content size, the rows, or anything you had typed. On the front page's Explore panel we record that the panel came into view (once per page load) and which of its two links was followed — the price charts or the methodology page. Three fixed notes, with no provider, model, content size or typed text. These events are sent to our own endpoint and aggregated using Cloudflare Analytics Engine, where they are retained only for a limited period (around 90 days).External-link courtesy, added 10 September 2026: confirming the third-party notice records the existing anonymous navigation action with the fixed label "external-site". This tells us only that someone continued. The notice adds no destination address, typed text or personal information to that signal.
First provider pick, added 19 September 2026: the front page still counts every deliberate provider-selection tap as comparison interest. Separately, once per landing-page load, it records only the existing provider key from the first deliberate pick. Automatic wheel landings, restores and later comparison taps do not create this note. It measures initial stated interest only, not conversion or quality, and adds no personal data.
First-timer assist progress, added 4 September 2026: the optional guided assist for first-time visitors walks through five steps, across the front page and the calculator. It records only that it appeared and which step was reached, as single fixed words (the wheel, the size, the calculator button, the workload slider, the company switcher, plus whether the run finished, was closed, was switched off, or was asked for again). Each word is recorded at most once per page load. It carries no company, model, workload, token count or typed text, and says nothing about who you are. We use it only to see where first-time visitors get stuck, and whether the assist is helping or getting in the way.
Price-history disclosure measurement, added 23 August 2026: when someone opens the history controls on the front page, the event records only that the disclosure opened. It carries no provider, route, workload, token count or typed text.
Pricing-mode measurement, added 22 August 2026 and extended 1 September 2026: when someone chooses a processing price mode, the event records only standard, batch or cache. It carries no provider, model, workload, token count or typed text.
The lawful basis for this anonymous measurement is our legitimate interest in understanding and improving the site (Article 6(1)(f) GDPR). In our assessment, because it places nothing on your device, uses no cookies, and records no stored or cross-visit identifier, it does not require prior consent under the ePrivacy rules. The opt-out is built into the request itself: if your browser sends a Do Not Track or Global Privacy Control signal, the script does not send any of these events — you can confirm this in the page source. And because the measurement stores nothing that identifies you, there is no individual record for us to find, change, or switch off separately.
Like every website, our host — Cloudflare Pages — automatically processes limited technical data (such as your IP address and browser type) in order to deliver pages to you and to protect the site against abuse and attacks. We rely on our legitimate interest in running a secure, working website as the lawful basis for this. We don't use these logs to build profiles of visitors.
We keep our own systems to a minimum and rely on a small number of vetted providers who act only on our instructions as data processors under a data-processing agreement: Cloudflare (hosting, security, and the anonymous analytics described above) and, only if you sign up, Beehiiv (newsletter). Some processing may take place outside the EEA/UK; where it does, it is covered by the European Commission's Standard Contractual Clauses (or an equivalent safeguard) through these providers' data-processing terms.
The site's typefaces are self-hosted: every font file is served directly from tokenscale.dev, so displaying the site sends no request to Google Fonts, Fontshare, or any other outside service, and your IP address is never shared with a font provider. The fonts are licensed for self-hosting — the Google families under the SIL Open Font License, and Clash Display under the Fontshare licence.
If you choose to enter your email address in the signup form, we use Beehiiv to store your address and send you the updates you signed up for. The lawful basis is your consent, which you can withdraw at any time using the unsubscribe link in any email. The signup form is provided by Beehiiv and may set its own cookies; see the Beehiiv privacy policy for details. If you never use the form, we never receive your email.
TokenScale sets no advertising or cross-site tracking cookies. The site itself uses only local browser storage to remember your preferences and interface state — such as your theme, text size, which panels you've opened or closed, and a single anonymous yes/no note that you've visited before (described under analytics above) — never to track or profile you, and our analytics are cookie-free. The only cookies that may be set are those from the Beehiiv newsletter form, and only if you interact with it.
If you're in the EU or UK, you have the right to access, correct, delete, or receive a copy of any personal data we hold about you, and to object to or restrict its processing. In practice the only information that identifies you personally is a newsletter email address you chose to give us; the anonymous usage measurement described above isn't linked to your identity, so there's no individual record of you in it to retrieve or erase. To exercise any of these rights, just email projectsbilton@gmail.com. You also have the right to lodge a complaint with your local data protection authority.
TokenScale is a tool for developers and businesses and is not directed at children. We don't knowingly collect personal data from anyone under 16.
If we change what we collect, we'll update this page. Last updated: 20 September 2026: added three coarse notes for the front page's Explore panel — that the panel came into view (once per page load), and which of its two links was followed (the price charts or the methodology page). They carry no provider, model, content size or typed text. The page had been attempting these three notes for some time, but they were not on the site's allowed list and so were discarded in your browser before anything was sent; they are now both recorded and, as of today, disclosed here. Two existing notes also now cover more of the site: the "still here after 30 seconds" note is recorded on every page instead of the front page alone, and the scroll-depth notes now work on the front page too, whose content scrolls inside a panel rather than the window, so they had never fired there. Neither of those collects anything new — the same coarse notes simply work where they previously did not. Previously (19 September): once per landing-page load, the site can record the existing provider key from the first deliberate provider pick. It excludes the random wheel landing, restores and later comparisons. The provider-selection tap count remains separate: it records every deliberate comparison tap. The first-pick note measures initial stated interest only, not conversion or quality, and adds no personal data.
If we change what we collect, we'll update this page. Last updated: 5 September 2026: picking a model on the front-page wheel now settles the wheel at the top of the page, and the calculator's two header sliders bring the row of everyday sizes, or the compound reply bars, up under the header as you drag them. We record one coarse note of which of those three movements happened, as a single fixed word ("wheel", "sizes" or "compound"), once per page load and never more than once each; it adds no provider, model, content size, word count, reply count or typed text. Previously (4 September): the first-time guidance became an optional five-step first-timer assist across the front page and the calculator, announced by a bar that says it is on and can switch it off. It records only which step was reached and how the run ended, including if it was switched off or asked for again, as single fixed words, adding no company, model, workload or typed text. It keeps one yes/no note in your browser so it does not interrupt you again, written after it has been on screen a few seconds or as soon as you close or act on it, and a second yes/no note if you turn it off. Earlier the same day: the guide first shipped, reusing the existing anonymous "wheel coach shown" event, and then gained a coarse note of what happened after it appeared. Previously (1 September): the existing coarse pricing-mode note can report cache as well as standard or batch. It still records no provider, model, workload, token count or typed text. Previously (23 August): added one coarse note when the front-page price-history controls are opened. It records only that the disclosure opened, never which route was chosen. Previously (22 August): the comparison table can now be copied or downloaded as a spreadsheet, and we record one coarse note of which format was taken ("csv" or "tsv") — never the rows, the tier or the content size. Also added one coarse note when the first wheel coach is shown; it records only that the hint appeared, with no model or action. Previously (20 August): added one coarse note when the optional animated pricing conversation is opened; it records no message text or other detail. Also added one coarse Journal-reading note tagged only as "post" or "all" when a reader expands one post or the full Journal; it never records which post. Previously (19 August): added one coarse note recording that a link to the State of AI Pricing market report was followed, tagged only as "hero" or "teaser" to say which of the two front-page links it was, described under analytics above. Previously (18 August): added three coarse tour notes (a tour started, finished, or was closed early, tagged "quick" or "deep"), described under analytics above. Previously (20 July): added a note of the content size you pick on the front-page wheel together with the model the wheel was serving, recorded once when you enter the full calculator (a coarse label such as novel~openai; no word counts, no pasted text), described under analytics above. Previously (19 July): removed the Google Search Console paragraph (we don't use it, and decided not to); provider views are now counted only when you choose a provider (automatic page behaviour is no longer counted); added a note of which provider the front-page wheel randomly opened on (to check the wheel is fair), coarse Price-Moves card events (which card was seen, clicked through, or shared — identified by provider, date and tier only), the hostname of an external site you leave to (hostname only, no path or query), and the path shown on our "page not found" screen (path only) — all described under analytics above. Previously (7 July): added a coarse device type (desktop, tablet or phone), the referring page's host (hostname only, path and query stripped; our own pages marked "internal"), and a finer split of calculator use (moving a slider or control versus pasting your own text — the text itself is still never sent), all described under analytics above. Previously (5 July): added coarse, anonymous Model Graveyard events (which filter/section was chosen and whether the "Share view" link was used; a search term is never recorded), described under analytics above. Previously (4 July): added coarse, anonymous engagement events (the energy-usage lens being opened, a content-size button being pressed, a reader still being on the page after 30 seconds, and the overnight price-moves strip being clicked) and "help me choose" guide events (what was picked and which model it suggested), described under analytics above. Previously (3 July): added a single anonymous "been here before" note in your own browser (reported only as new/returning) and campaign-link labels (?from=…), both described under analytics above. Previously (26 June): web fonts became self-hosted, so displaying the site sends no request to Google Fonts or Fontshare and your IP address is never shared with a font provider.