Privacy Policy
What we collect when you visit TokWork and when you send requests through the API, and what you can ask us to do about it.
1. What we collect
Account data. When you create an account we store your email address, a hashed password, and the billing records needed to operate your balance.
API usage data. For each request we record the API key used, the model requested, the timestamp, the number of input and output tokens, and the resulting charge. This is what makes usage reporting and billing possible.
Prompts and responses. To forward a request we necessarily transmit its contents to the upstream provider you selected. We relay requests; we do not use prompt or response content to train models. Retaining request bodies for debugging is off by default and can only be enabled on request.
Website data. The marketing site uses privacy-friendly analytics (page views, referrer, coarse device information). If analytics is switched off in the site settings, no analytics script is loaded at all.
2. Why we hold it
To provide the service you asked for: authenticating requests, routing them, metering usage, charging your balance, preventing abuse, and answering support requests. We do not sell personal data.
3. Who we share it with
Upstream model providers. A request is sent to the provider that serves the model you asked for. Their own terms apply to that processing.
Infrastructure and billing processors. We use third-party cloud hosting, database, object storage and payment providers to run the service.
We may also disclose data where we are legally required to, or where it is necessary to investigate abuse of the service.
4. How long we keep it
Usage records and billing history are kept for as long as your account is active, and afterwards for the period required by tax and accounting rules. Support conversations are kept for a limited period. You can ask us to delete your account and the data that we are not required to keep.
5. Your rights
Subject to the law where you live, you can ask for a copy of your personal data, ask us to correct or delete it, object to certain processing, or withdraw consent to marketing email at any time.
6. Security
Traffic is encrypted in transit. API keys are stored so that the full key is only shown once at creation, and access to production systems is limited to staff who need it.
7. Contact
Email support@tokwork.com for any privacy question or request.