Data Policy
This Data Policy explains how tokentoken OÜ handles the content you send to and receive from our inference API — your prompts, context, and generated outputs (“API Data”). API Data is content we process on your behalf as a processor. Personal data about you as a customer is covered by our Privacy Policy.
1.We do not train on your API Data
Your prompts and outputs are never used to train, fine-tune, or improve any model. We serve open-source models on our own infrastructure and pass your requests through without adding them to any training corpus. We do not sell or share API Data with third parties for their own purposes.
2.Retention of API Data
We do not retain the content of your prompts or completions. Prompt and completion content is processed only in memory to generate your response and is never written to persistent storage. Once your response is returned, the content is discarded. We retain only non-content metadata:
| Data | Retention | Purpose |
|---|---|---|
| Prompt & completion content | Not stored — discarded after the response | — |
| Request metadata (token counts, request/response size, latency, model, timestamp) | Retained for billing & analytics | Invoicing, capacity, reliability |
| Cached prefixes (KV cache) | Transient in memory; evicted automatically | Latency & throughput optimisation |
Because content is not stored, it is not human-reviewed and is not available for retrieval after your request completes.
3.Zero data retention by default
Zero data retention is the default for every account — there is nothing to enable. No prompt or completion content is written to disk; only the non-content metadata above (token counts, size, latency) is kept for billing and reliability. If you have specific data-processing requirements or need this in writing, contact privacy@tokentoken.club.
4.Sub-processors
We use a limited set of infrastructure sub-processors to run the Services, under contracts requiring confidentiality and data-protection safeguards:
- Cloud & GPU compute providers — to host inference workloads.
- Cloud storage providers — for operational and account data.
- Payment processors — for billing (they do not receive API Data).
An up-to-date sub-processor list is available on request.
5.Security
API Data is encrypted in transit (TLS). Because prompt and completion content is not stored, it is not retained at rest. Access to systems is restricted to authorised personnel on a need-to-know basis. We support GDPR-aligned processing and can enter into a Data Processing Agreement with customers on request.
6.Data location & transfers
We operate inference infrastructure with EU-region options. Where API Data is transferred outside the EEA, we rely on appropriate safeguards, including Standard Contractual Clauses. Enterprise customers can request EU-only data residency.
7.Contact
Processor: tokentoken OÜ, Tallinn, Estonia. For data-handling, ZDR, or DPA requests, contact privacy@tokentoken.club.