Data Policy

Last updated 22 July 2026 · tokentoken OÜ, Tallinn, Estonia

This Data Policy explains how tokentoken OÜ handles the content you send to and receive from our inference API — your prompts, context, and generated outputs (“API Data”). API Data is content we process on your behalf as a processor. Personal data about you as a customer is covered by our Privacy Policy.

Template notice. This document is a starting template modelled on common industry practice. It is not legal advice. Have qualified counsel review and adapt it before you publish or rely on it.

1.We do not train on your API Data

Your prompts and outputs are never used to train, fine-tune, or improve any model. We serve open-source models on our own infrastructure and pass your requests through without adding them to any training corpus. We do not sell or share API Data with third parties for their own purposes.

2.Retention of API Data

We do not retain the content of your prompts or completions. Prompt and completion content is processed only in memory to generate your response and is never written to persistent storage. Once your response is returned, the content is discarded. We retain only non-content metadata:

DataRetentionPurpose
Prompt & completion contentNot stored — discarded after the response
Request metadata (token counts, request/response size, latency, model, timestamp)Retained for billing & analyticsInvoicing, capacity, reliability
Cached prefixes (KV cache)Transient in memory; evicted automaticallyLatency & throughput optimisation

Because content is not stored, it is not human-reviewed and is not available for retrieval after your request completes.

3.Zero data retention by default

Zero data retention is the default for every account — there is nothing to enable. No prompt or completion content is written to disk; only the non-content metadata above (token counts, size, latency) is kept for billing and reliability. If you have specific data-processing requirements or need this in writing, contact privacy@tokentoken.club.

4.Sub-processors

We use a limited set of infrastructure sub-processors to run the Services, under contracts requiring confidentiality and data-protection safeguards:

An up-to-date sub-processor list is available on request.

5.Security

API Data is encrypted in transit (TLS). Because prompt and completion content is not stored, it is not retained at rest. Access to systems is restricted to authorised personnel on a need-to-know basis. We support GDPR-aligned processing and can enter into a Data Processing Agreement with customers on request.

6.Data location & transfers

We operate inference infrastructure with EU-region options. Where API Data is transferred outside the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses. Enterprise customers can request EU-only data residency.

7.Contact

Processor: tokentoken OÜ, Tallinn, Estonia. For data-handling, ZDR, or DPA requests, contact privacy@tokentoken.club.