Privacy Policy
Version 1 · Last updated April 14, 2026
Privacy Policy
**Last updated: January 15, 2026**
TokenFast ("we," "our," or "us") operates the tokenfast.ai website and API services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
1.1 Account Information When you create an account, we collect: - Email address - Name (optional) - Profile image (if using social login) - Authentication credentials (hashed passwords or OAuth tokens)
1.2 Billing Information When you make a purchase, our payment processor (Stripe) collects: - Credit/debit card details (stored by Stripe, never on our servers) - Billing address - Transaction history
1.3 Usage Data We automatically collect: - API request metadata (timestamps, model used, token counts, response codes) - IP addresses and approximate geolocation - Browser type and device information - Pages visited and features used within our dashboard
1.4 What We Do NOT Collect - **We do not store, log, or retain the content of your API prompts or model responses.** Your prompts are forwarded to the upstream model provider in real time and responses are streamed back to you. No prompt or completion content is persisted on our systems.
2. How We Use Your Information
We use the information we collect to: - Provide, maintain, and improve the Service - Process transactions and send billing notifications - Calculate usage and enforce budget limits - Send important service announcements and security alerts - Respond to support inquiries - Detect and prevent fraud, abuse, and security threats - Generate aggregated, anonymized analytics to improve our offerings
3. Information Sharing
We do not sell your personal information. We may share information with: - **Service Providers:** Stripe (payments), Vercel (hosting), upstream AI model providers (API routing — prompt content only, in transit) - **Legal Requirements:** When required by law, regulation, or legal process - **Business Transfers:** In connection with a merger, acquisition, or sale of assets - **With Your Consent:** When you explicitly authorize sharing
4. Data Retention
- **Account data** is retained for the lifetime of your account plus 30 days after deletion.
- **Usage metadata** is retained for 12 months for billing and analytics purposes.
- **Prompt/completion content** is not retained (see Section 1.4).
- **Billing records** are retained for 7 years as required by financial regulations.
5. Data Security
We implement industry-standard security measures including: - TLS 1.3 encryption for all data in transit - AES-256 encryption for data at rest - API keys are hashed before storage; full keys are shown only once at creation - Regular security audits and penetration testing - Role-based access controls for internal systems - SOC 2 Type II compliance (in progress)
6. Your Rights
Depending on your jurisdiction, you may have the right to: - Access the personal data we hold about you - Correct inaccurate data - Delete your account and associated data - Export your data in a portable format - Object to or restrict certain processing - Withdraw consent where processing is consent-based
To exercise any of these rights, contact us at support@tokenfast.ai.
7. Cookies and Tracking
We use essential cookies for authentication and session management. We use analytics cookies (which can be declined) to understand how the Service is used. We do not use third-party advertising trackers.
8. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses and other appropriate safeguards for international transfers.
9. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or a prominent notice on the Service. Your continued use of the Service after changes constitutes acceptance.
11. Contact Us
If you have questions about this Privacy Policy, contact us at: - Email: support@tokenfast.ai - Address: TokenFast, Inc., 548 Market St, Suite 35000, San Francisco, CA 94104