Privacy policy

This policy explains what TokenPP collects while providing the service, how that information is used and protected, and which rights you can exercise.

1. What we collect

  • Account data: username, email address, password (stored only as a salted hash and not reversible), optional two-factor settings, account role and creation time.
  • Billing and usage data: model, input / output / cache token counts, charged amount, endpoint, whether the call was streamed, status code, latency and time-to-first-byte, client IP, and the identifier of the key used.
  • API key data: name, prefix, enabled state, rate limits and quota, expiry. The full key is returned once at creation; only its hash is stored.
  • Transaction data: top-up orders, redemption code redemptions, referral relationships and rebates.
  • Local storage: session token, theme and language preferences and similar UI settings kept in your browser's localStorage.

2. Request and response content

The platform does not write request or response bodies to its database.

Call logs record usage and billing fields only, never prompt or output content.

Only when troubleshooting might operators look at the necessary technical details. Your request content is not used to train models and is not made available externally.

3. How we use data

  • To authenticate you and deduct the right amount.
  • To produce usage and billing records so you and the platform can reconcile.
  • To detect abnormal traffic, abuse and security risks and keep the service stable.
  • To show in-app announcements and support links according to platform settings.

4. Sharing

The platform does not sell or disclose your personal information to third parties except when you clearly consent, or when required by law or a lawful request from a regulator or court.

5. Retention

Account data is kept while the account exists. After closure, records are deleted or anonymised except for accounting and transaction records that must be retained by law.

Usage and billing records are kept for as long as reconciliation and compliance require, then deleted or anonymised.

6. Your rights

  • Access and correction: view and change your email, password, two-factor setup and reminder settings on the console settings page.
  • Deletion: request account closure and deletion of related information through the support channel.
  • Withdrawal of consent: turn off optional features such as reminders, or stop using the service.

7. Security

  • Passwords are stored with bcrypt salted hashing, and API keys are stored only as hashes.
  • Traffic between you and the platform is carried over HTTPS.
  • Access to production data is limited to the operators who need it.
  • No system is perfectly secure, so keep your keys safe and rotate them periodically.

8. Updates and contact

Updates to this policy are published on this page, and material changes are announced in the app.

For privacy questions or to exercise the rights above, contact us through the in-app support channel (Telegram / QQ).

Back to home