This Policy describes what data the Tokenly service collects, how it uses that data and how it is protected. By using the Service, the User confirms acceptance of this Policy.
1. Data we collect
The Service processes: an email address and a password (stored as a cryptographic hash) required for authentication; payment information passed through to the payment provider (the Service does not store card numbers); request metadata for proxied calls (the API key identifier, model name, number of input and output tokens, timestamp and response status); IP address and browser information used for security and abuse prevention.
2. Purposes of processing
Collected data is used solely to: provide the Service's functionality (authentication, request routing, charge accounting); bill the User and present usage statistics in the dashboard; ensure security and investigate incidents; comply with obligations imposed by applicable law.
3. Forwarding to model providers
The content of the User's requests (prompt text, messages, files, etc.) is forwarded directly to the provider of the selected model — Anthropic, OpenAI, Google or any other provider in the catalogue. The Service acts as a transparent proxy and does not store request or response bodies. Processing by the provider is governed by that provider's own policies; the User is expected to review them.
4. Retention
Account and payment data are retained for the lifetime of the account and afterwards for the period required by applicable law (in particular for accounting and tax purposes). Request metadata is retained for as long as required to provide usage statistics and to investigate billing disputes.
5. Cookies and similar technologies
The Service uses cookies and similar technologies to maintain the User's session, to remember language and theme preferences and for basic protection against automated abuse. The Service does not use cookies for advertising targeting and does not share them with advertising networks.
6. Data protection
The Service applies technical and organisational measures to protect data: transport encryption (HTTPS), password hashing, encryption of sensitive fields in the database, and restricted access to production systems. Despite these measures, no service can guarantee absolute security; the User is advised to use a strong password and not to share API keys with third parties.
7. User rights
The User may request access to the data associated with their account, may request its correction, restriction or deletion. Account deletion is available from the dashboard and removes or anonymises account data, except for data the Service is required to retain by law.
8. Changes and contact
The Service may update this Policy from time to time. The current version is published on the website; the date of the latest update is shown at the top of this document. For questions related to personal data processing and data-subject requests: support@tokenly.plus.