Last updated: 27 July 2026
Tokenless is a product of Vertile AI Pty Ltd (ABN 11 688 480 499) ("Vertile AI", "Vertile", "we", "us", or "our"). This policy explains how the Tokenless command-line tool, user-installed local daemon, and managed Playwright browser profiles handle information.
This policy is intended to be read with:
- the Tokenless Terms of Service, which govern installation and use of Tokenless, including acceptable use and your responsibilities toward AI providers; and
- the Vertile AI Privacy Policy, which applies to visits to the Vertile website, support communications, and personal information Vertile otherwise holds.
Tokenless is an independent tool. It is not made by, affiliated with, endorsed by, or officially supported by any AI provider whose website it can operate.
1. Plain-language summary
- Tokenless is local software. It uses Playwright on your device to operate supported AI provider websites in a Tokenless-managed browser profile.
- Tokenless locally handles prompts, intentionally selected files, visible provider-page information, responses, and job state as needed to perform the action you requested.
- Your prompt and intentionally supplied context are sent directly from your device to the AI provider you selected through that provider's normal website. The provider handles that information under its own terms and privacy policy.
- Vertile does not operate a Tokenless relay or hosted AI service that receives your prompts, responses, files, provider-page content, browser profile, or provider credentials.
- Tokenless does not currently send product telemetry to Vertile. A future release may report one minimal usage measurement: a numeric estimate of tokens saved by using Tokenless. The estimate will be calculated locally, and the telemetry payload will not contain AI communications or workflow content.
- Tokenless does not sell personal information or workflow data, use it for advertising, use it to profile you, or transfer it to data brokers.
2. Scope and purpose
Tokenless lets local agents and tools route suitable work through supported web-based AI services using a local managed browser. It can submit user-authorised prompts and files through visible provider controls, read the resulting visible response, and return that response to the requesting local workflow.
Supported providers and features can change. Current product documentation identifies supported and experimental providers. Tokenless limits automated navigation to provider origins and trusted sign-in origins defined by its local provider configuration.
You install and run Tokenless on a device you control. Its command-line tool, local daemon, Playwright worker, job database, configuration, and managed browser profiles operate locally.
3. Information Tokenless handles locally
Tokenless may handle the following information on your device when necessary to perform an action you requested.
Requests and workflow content
- prompts and instructions submitted by you or your authorised local agent;
- text context you intentionally include;
- files you intentionally select for upload, including temporary integrity and staging information;
- provider responses, visible citations, and other visible results returned to your local workflow; and
- project, chat, task, job, and idempotency labels supplied by your local workflow.
Provider and browser information
- your Tokenless-managed browser profile and its provider sign-in state;
- visible provider-page text, controls, state, and allowed page locations needed to perform and verify an action;
- provider, model, capability, account-tier, browser-visibility, and session choices;
- sanitised snapshots or diagnostic information created by an action you explicitly request; and
- visible sign-in, CAPTCHA, consent, plan, payment, and confirmation states needed to pause automation and return control to you.
Local operational information
- Tokenless configuration and managed-profile registry information;
- local daemon authentication and connection state;
- job requests, results, status, timestamps, errors, blockers, and execution checkpoints;
- local logs and diagnostic records; and
- temporary staged attachment copies used to upload files through a provider's visible file control.
This information may contain personal, confidential, or sensitive information depending on what you submit and what a provider returns. Do not submit information you are not authorised to use or disclose.
4. Managed browser profiles and optional sign-in import
Tokenless creates separate managed browser profiles under its local data directory. Provider sign-in state remains inside those profiles on your device and is not exposed to the calling agent as authentication material.
Where the product offers sign-in import, it requires your explicit action and copies only supported provider sign-in records from a selected local Chrome or Brave profile into a separate Tokenless-managed profile. Current import support is limited to selected ChatGPT, Claude, and Grok sign-in records. Gemini and shared Google sign-in data are not imported.
Profile import is designed to exclude passwords, general browsing history, bookmarks, payment data, browser sync data, unrelated site data, extensions, and caches. Import does not modify the source browser profile. Imported authentication values remain local and opaque to agents.
5. How information is used
Tokenless uses locally handled information only to:
- validate, schedule, and perform the action you requested;
- open or reuse the approved provider website and managed browser profile you selected;
- locate and operate supported visible controls;
- submit your prompt and intentionally selected context or files;
- read and return visible provider responses and citations;
- preserve authorised conversation or workspace continuity;
- stage and verify selected files before visible upload;
- maintain local job state, settings, reliability, security, and diagnostics; and
- pause for user action when a provider requires sign-in, CAPTCHA, consent, payment, plan selection, or confirmation.
Vertile does not use local workflow content for advertising, marketing, credit decisions, behavioural profiling, or training AI models.
6. Where information goes
On your device
The command-line tool, daemon, Playwright worker, managed browser profiles, configuration, job database, logs, staged files, and snapshots operate on your device. The local daemon listens on a loopback interface and uses authenticated local communication for protected operations.
To your selected AI provider
Tokenless sends prompts and intentionally selected content directly through the normal HTTPS website of the provider you selected. Selected files are uploaded through that provider's visible file control. The provider may retain prompts, conversations, uploaded files, account activity, and generated responses under its own terms, privacy policy, settings, and retention rules. Vertile does not control provider collection or retention.
To Vertile
Vertile does not receive Tokenless prompts, responses, attachments, file names or paths, provider-page content, conversation URLs, managed browser profiles, provider authentication values, or local job databases unless you deliberately include information in a support request or otherwise send it to Vertile.
Tokenless does not currently transmit product telemetry. If lightweight savings telemetry is enabled in a future release:
- the product will calculate the estimate locally;
- the telemetry payload will contain only a numeric aggregate estimate of tokens saved;
- the payload will not contain prompts, instructions, responses, attachments, file names or paths, page content, page URLs, provider account information, authentication data, project names, chat names, task labels, error bodies, or a persistent user or device identifier; and
- product documentation or settings will provide a way to disable future transmissions.
As with any internet request, Vertile's receiving infrastructure may temporarily process unavoidable transport data such as an IP address, request time, and standard protocol headers to deliver and secure the telemetry endpoint. An IP address may be personal information where it identifies or can reasonably identify an individual. Vertile will not use that transport data to reconstruct workflows or link the savings number to AI communications.
The future telemetry endpoint may use infrastructure providers in Australia, the United States, or other countries where Vertile's providers operate. Where personal information is disclosed outside Australia, Vertile will take reasonable steps required by applicable law. The Vertile AI Privacy Policy contains broader information about service providers and international processing.
If you contact Vertile, we handle the contact details and information you choose to provide under the Vertile AI Privacy Policy.
7. Information telemetry does not collect
Future Tokenless savings telemetry will not collect or transmit:
- prompts, system instructions, agent messages, or other AI communications;
- AI responses, citations, or generated files;
- uploaded file content, file names, file paths, or local project content;
- provider-page text, HTML, screenshots, snapshots, URLs, or conversation identifiers;
- provider names, models, account tiers, subscription status, or account identifiers;
- cookies, passwords, browser-storage authentication values, or managed-profile contents;
- local job requests, results, errors, checkpoints, or task metadata; or
- advertising identifiers, contact details, or persistent user or device identifiers.
Tokenless does not inspect provider network traffic, call private provider backend APIs, export provider authentication material to Vertile, read general browser history, or silently fall back to a paid provider API.
8. Local storage, retention, and deletion
Tokenless stores local state in its home directory, which defaults to ~/.tokenless. Depending on the actions you use, this may include configuration, the daemon token, the local job database, managed browser profiles, provider sign-in state, logs, job requests and results, staged attachment data, and sanitised snapshots.
Local data remains under your control until removed through available product controls or by deleting the relevant local files. You may:
- inspect managed profiles with available Tokenless profile commands;
- remove a managed profile or all managed profiles with available profile-clear commands;
- stop or uninstall the Tokenless daemon and command-line tool; and
- remove
~/.tokenlessto delete Tokenless local runtime state.
Deleting Tokenless local state does not delete conversations, uploads, or account information held by an AI provider. Use the provider's own controls for provider-held information.
If future savings telemetry is enabled, Vertile will retain raw telemetry events and unavoidable transport logs for no more than 30 days for aggregation, security, and abuse prevention. Vertile may retain totals that have been aggregated and are no longer reasonably linkable to an individual or device.
Information you intentionally send to Vertile for support, and technical data generated when you visit the Vertile website, is retained under the Vertile AI Privacy Policy.
9. Security
Tokenless uses separate managed browser profiles, provider-scoped navigation rules, local file permissions, versioned local protocols, loopback-only daemon communication, authenticated local operations, and integrity-checked file staging to reduce unnecessary data exposure.
Provider communication occurs through the provider's HTTPS website. Sign-in, CAPTCHA, consent, payment, plan, and confirmation steps remain visible and under your control.
No security measure can eliminate every risk, especially on a compromised device. You remain responsible for securing your device, browser profiles, provider accounts, and local Tokenless files.
If Vertile becomes aware of a data breach involving personal information it holds, Vertile will assess and respond in accordance with applicable law, including the Notifiable Data Breaches scheme where applicable.
10. Third-party services
AI providers, browser vendors, package registries, source-code hosts, and the public Vertile website are independent services. Their collection and handling of information is governed by their own terms and privacy policies.
Tokenless may contact the public npm registry to check for package updates. Package-registry requests do not include Tokenless prompts, responses, attachments, managed profiles, or provider credentials.
The public Vertile website, including this policy page, may process limited website request and usage information through hosting and analytics providers. Website processing is separate from the local Tokenless workflow and is described in the Vertile AI Privacy Policy.
11. Your privacy rights and choices
Vertile manages personal information it holds in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles where applicable, and other applicable privacy laws.
Most Tokenless workflow data remains on your device or in your selected provider account rather than being held by Vertile. For local data, use the controls described in Section 8. For provider-held data, use the provider's privacy and account controls.
You may contact Vertile to request access to, correction of, or deletion of personal information Vertile holds about you. You may also object to or request restriction, portability, or withdrawal of consent where those rights apply. We may need to verify your identity before acting on a request. We aim to respond within 30 days and will not charge for making an access or correction request except where a charge is permitted by applicable law and disclosed in advance.
To make a request or complaint, email hello@vertile.ai with the subject "Tokenless privacy request". If we refuse an access or correction request, we will explain the reason and available complaint mechanisms where required by law.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another regulator available in your jurisdiction.
12. Children
Tokenless is not directed to children under 18, and Vertile does not knowingly collect personal information from children under 18 through Tokenless. Users must also meet the age and account requirements of each provider they select.
13. Changes to this policy
We may update this policy when Tokenless features, data practices, or legal obligations change. We will publish the updated policy at this URL and change the "Last updated" date.
Before enabling savings telemetry, we will keep this policy and relevant product documentation aligned with the implemented data fields, retention, and user controls. Where a change materially affects how Tokenless handles personal information, we will provide any additional notice or consent required by applicable law before the changed practice applies.
14. Contact
- Privacy contact: Privacy Officer
- Company: Vertile AI Pty Ltd
- ABN: 11 688 480 499
- Email: hello@vertile.ai
- Website: vertile.ai
- Location: South Australia, Australia