Tokenisation makes sense if you have a few very small pieces of highly sensitive data, like credit card data. But almost all data stored in an application might be something you legally must delete in certain circumstances. It's also the case that for some applications, all data is “sensitive”, for example a medical journal application, an application used by a trade union, a facial recognition system, or something as mundane as an HR system.