1.The short version
We collect what we need to run an account, bill it accurately and keep the Service secure. We do not sell your data, we do not train models on your prompts, and we do not store the content of your prompts or completions.
This notice explains the detail. If anything is unclear, ask us.
2.Who is responsible
Graviti Technologies Inc., 11 Broadway, Suite 700, New York, NY 10004, USA, is the controller of the personal data described here. Contact privacy@tokenify.dev about anything in this notice.
3.What we collect
Account data: your email address, your name if you give one, a hash of your password, and — if you sign in with Google — the account identifier, email address and profile picture Google returns.
Billing data: your payment history, credit balance and ledger. Card details are handled by our payment processor and never reach our servers; we store only the processor's reference and the outcome.
Usage metadata, for each API request: the time, model, supplier, token counts, cost, latency, finish reason and status code, together with your account and API key identifiers.
Technical data: IP address, user agent and session records, used for security and abuse prevention.
Analytics and attribution data: the pages you visit on our website, the advertising click identifier and campaign parameters in the link that brought you, and the identifiers Google Analytics assigns to your browser. Where an account results, we keep the campaign that brought it so we know which advertising works.
4.What we do not collect
We do not store the content of your prompts or of the completions returned to you. Request and response bodies are streamed between you and the Supplier and are not written to our databases or logs.
We do not train models on anything you send. We have no models to train.
We do not sell personal data. We do use Google Analytics and Google Ads to measure our advertising, which is described under "Analytics and advertising" below; we share no account, billing or request data with them.
5.Why we use it
To provide the Service — authenticating you, routing your requests and metering them.
To bill you accurately and to answer questions about a charge.
To keep the Service secure: rate limiting, fraud and abuse detection, and investigating incidents.
To contact you about your account — verification, password resets, receipts, and material changes to the Service. Marketing email is separate and only sent with consent you can withdraw.
To meet our legal obligations, including tax and accounting records.
Where the law requires a basis: performing our contract with you, our legitimate interest in running and securing the Service, your consent where we ask for it, and compliance with legal obligations.
7.How long we keep it
Per-request usage metadata: 90 days, then deleted automatically.
Aggregated usage, ledger entries and payment records: as long as tax and accounting law requires, currently up to seven years.
Account data: until you close your account, then deleted or anonymised except where we must keep it.
Security logs: up to 12 months.
8.Where it is processed
Our infrastructure runs in the United States. Suppliers may process requests in other countries; which ones depends on the model you call.
Where personal data leaves the UK or EEA we rely on the safeguards the law provides for such transfers, including standard contractual clauses.
9.Your rights
Depending on where you live, you may have the right to:
- get a copy of the personal data we hold about you;
- have inaccurate data corrected;
- have data deleted, where we do not need to keep it;
- object to or restrict certain processing;
- receive your data in a portable format;
- withdraw consent you have given, without affecting what was done before;
- complain to your data protection regulator.
Exercise any of these at privacy@tokenify.dev. We will respond within one month and will not charge you or treat you differently for asking.
We do not sell or share personal information in the sense those terms are used in California law, and we do not use it for cross-context behavioural advertising.
10.Security
Passwords are stored using Argon2id. API keys are stored only as a hash — we cannot show you a key again after it is created, which is also why losing one means creating another.
Supplier credentials are encrypted at rest. Traffic is encrypted in transit.
Changing your password signs out every other session, and revoking an API key takes effect within seconds rather than at the end of a cache period.
No system is perfectly secure. If we discover a breach affecting your personal data we will notify you and the relevant regulator as the law requires.
12.Analytics and advertising
We advertise through Google Ads, and we use Google Analytics to measure it. Unless you turn it off, Google Analytics records which pages you saw and the campaign parameters in the link you arrived by, under an identifier it assigns to your browser. Once you turn it off, Google receives no identifier and no advertising data from your visit, and we ask you to confirm so it does not happen by accident.
We also run our own analytics — a self-hosted instance of Plausible, on our own infrastructure. It stores nothing on your device, assigns you no identifier, and its data goes to no third party. We use it because it answers questions about the site that we should not have to open an advertising account to ask.
When a payment is made, we send the amount paid and our own reference for that payment to both — to Google with the browser identifier, so the advertising that produced the sale can be identified, and to our own analytics without one. We do not send your email address, your name, your API keys, your request contents or your balance to either. Payment records are how we account for revenue, so they are reported whatever you chose; what your choice controls is whether they can be connected to your browsing.
Google acts as our processor for analytics and, for advertising personalisation, as an independent controller. Its own notice is at policies.google.com/privacy. We have advertising personalisation enabled, which means Google may use this activity to show you our advertisements elsewhere.
To opt out: choose "Only essentials" when the choice appears, or change your answer later from "Cookie preferences" in the footer. You can also install Google’s browser add-on at tools.google.com/dlpage/gaoptout, block the cookies described above, or turn off ad personalisation in your Google account. None of this affects the Service.
13.Children
The Service is not for anyone under 18 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
14.Changes
We will post any change here and update the date at the top. If a change is significant we will email the address on your account. Last updated 21 September 2026.