Privacy Policy
Last updated: September 2026. Short, because we collect little. Questions: hello@agenttokens.dev.
Prompts and completions
Text you send to the API and the text the model returns are processed in memory and not persisted. They aren't written to disk, logged, or used for training. Prompt prefixes may sit in GPU KV cache on the serving node for a few minutes to speed up your next request; that cache is not readable by other customers and is evicted automatically.
What we do store
| Account | Your email address, sign‑in timestamps, and a Stripe customer id. |
|---|---|
| API keys | A SHA‑256 hash and the first few characters of each key, its name, and when it was created, last used, and revoked. Never the key itself. |
| Usage | Per request: a request id, model, input / cached / output token counts, cost, and timestamp. No prompt text. |
| Payments | Top‑up amounts, status, and Stripe session ids. Card details go directly to Stripe; we never see them. |
| Website analytics | Page views and clicks on this site (not the API), with a random per‑browser id, the page path, referrer, and UTM parameters. No cookies are set for this. If configured, we also load Google Ads conversion tracking and PostHog on the marketing pages. |
| Server logs | Request method, path, status, duration, and IP address for the control‑plane site, kept for up to 30 days for security and debugging. |
| Provider leads | Whatever you enter in the providers form, used only to reply to you. |
Cookies
Two first‑party cookies: a session cookie when you're logged in, and a CSRF token. Both are functional; nothing for advertising.Third parties
- Stripe — payments. Their privacy policy applies to card data.
- Amazon Web Services — hosting for this site and outbound email (sign‑in links).
- GPU providers — inference may run on hardware operated by partners under contract with us; they run our serving stack and are bound by the same "don't persist prompts" rule.
- Google Ads / PostHog — optional marketing analytics on the public pages only, if enabled for this deployment.
We don't sell your data and we don't share it with anyone else unless required by law.
Retention and deletion
Account, key, usage, and payment records are kept while your account exists, and for as long afterwards as tax and accounting law requires. Email hello@agenttokens.dev from your account address to delete your account; we'll remove everything we're legally allowed to.
Your rights
Depending on where you live you may have rights to access, correct, export, or erase your data. Email us and we'll do it — no forms, no waiting period beyond what it takes to verify it's you.
Changes
If this policy changes materially we'll update the date above and mention it on the dashboard.