Privacy Policy

Last updated: June 15, 2026

1. Introduction

TokenCode ("we," "our," or "us") operates the website and API gateway service at tokencode.dev. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By accessing or using the Service, you agree to the data practices described in this policy.

2. Information We Collect

2.1 Account Information

When you register, we collect your username, email address, and password. You may optionally provide a display name and link third-party OAuth accounts (GitHub, Discord, etc.).

2.2 API Usage Data

We log API requests routed through our gateway to provide the Service, including: model requested, token counts (input, output, cache), timestamps, request status, and latency. We do not log the content of your prompts or model responses.

2.3 Billing and Payment Data

We retain transaction records for top-ups, usage deductions, and refunds. Payment processing is handled by third-party providers; we do not store your full credit card number.

2.4 Device and Usage Information

We automatically collect certain information when you use our Service, including your IP address, browser type, operating system, referring URLs, and interaction data with the Service. We use this information to maintain security, prevent abuse, and improve the Service.

2.5 Cookies and Local Storage

We use cookies and browser storage for authentication sessions, language preferences, and analytics. You can disable cookies in your browser settings, but some features of the Service may not function properly.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process API requests and route them to upstream providers
  • Calculate and bill usage-based fees
  • Authenticate your account and secure the Service
  • Monitor and analyze usage patterns to improve the Service
  • Detect, prevent, and address fraud, abuse, and security issues
  • Communicate with you about your account, billing, and service updates
  • Comply with legal obligations

4. How We Share Your Information

4.1 Upstream AI Providers

When you make API requests through our gateway, your prompts and request parameters are forwarded to the relevant AI model provider (e.g., OpenAI, Anthropic, Google). Each provider processes your data according to their own privacy policy. We encourage you to review their policies before use.

4.2 Service Providers

We may share information with third-party service providers who perform services on our behalf, such as payment processing, infrastructure hosting, and analytics. These providers are contractually obligated to use your information only for the purposes we specify.

4.3 Legal Requirements

We may disclose your information if required to do so by law, in response to a valid legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

5. Data Retention

We retain your account information for as long as your account is active. API usage logs are retained for billing and operational purposes for up to 90 days, after which they are aggregated or deleted. Payment records are retained as required by applicable law. You may request deletion of your account and associated data at any time.

6. Data Security

We implement industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS), encrypted storage for sensitive data, access controls, and regular security reviews. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict certain processing activities
  • Data portability: receive your data in a structured, machine-readable format

To exercise any of these rights, please contact us at the email address below.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from your jurisdiction. By using the Service, you consent to such transfers. We take appropriate safeguards to ensure your data is treated securely and in accordance with this policy.

9. Children's Privacy

Our Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

TokenCode Email: [email protected] Website: tokencode.dev