This policy describes what COMPANY NAME, operating the service at DOMAIN ("Tokex"), collects when you use Tokex, what it does with it, and what it does not do. It is written to be checked against the product, and the product is the honest description of it.
1. What this covers
Tokex is an exchange for LLM credits: you buy credits denominated in a provider and model, spend them on inference routed through our API, and trade them with other users. This policy covers the account, the ledger, the requests you send, the payments you make, the mail we send you, and the website with its waitlist. It does not cover the upstream model providers, the payment processor, the mail provider or our hosts, each of which handles your data under its own terms, named in section 3.
2. What we collect, and why
- An email address, if you sign in by email. It is the only identity we keep: no name, no profile, no phone number, no password. It exists to open a session, to recover a frozen account, and to warn you when something important changes, such as the destination cash is paid to.
- Credentials as hashes. API keys and session secrets are shown to you once and stored only as hashes. We cannot read them back; we can only revoke them. Sign-in codes are stored the same way and die after ten minutes, one use, or a handful of wrong guesses.
- The ledger. Every movement of credit on your account: purchases, spends, trades, transfers, redemptions, with amounts, timestamps and the idempotency keys your software chose. The ledger is append-only by design, because that is what makes balances auditable, so entries are never edited or deleted; see section 6.
- Receipts for inference, one per request: the model, the token counts, the credits charged and their value in dollars, latency, the key that made the request, and any label you attached. Receipts store no prompt and no response. Nothing you send to a model is kept by Tokex after the request completes, except in one case: when you leave the response record switched on, an exact repeat of a request is answered from a stored copy for a short time so it costs you nothing; you can switch this off per request.
- Moderation verdicts. When the prompt screen is switched on, a flagged request is refused before it runs and the refusal is recorded by category only, never by content. Repeated flags freeze the account.
- Payment records. The amount, the fee, the credits bought, the payment processor's identifiers for the session and the charge, and any refund or dispute the processor reports. Card numbers never reach Tokex; see section 3.
- A payout destination reference, if you register one for the cash rail: the payment processor's identifier for the account money is sent to, never a bank detail.
- Network addresses, used in memory to limit request rates and to check the source of payment callbacks. They are not written to the ledger or to any record about you.
- The waitlist, if you join it on the website: your email address, which form you used, the campaign tags in the link you arrived by (utm_source and the like), the referral code you came through, when you joined, which version of the sign-up wording you agreed to (the record Canada's anti-spam law asks us to keep), whether your welcome and invite emails went out, and whether you confirmed your email or were invited. Your address is also kept in a folded form (letter case, dots in Gmail addresses and anything after a plus removed) so one inbox holds one place in line. Your network address is stored only as a keyed hash, used to limit how many sign-ups one network can make and to stop people referring themselves; the address itself is not kept. Your place in line is computed when you ask, never stored. A secret link to your place is derived from your address and referral code and is never stored either; only a one-way hash of it is.
- Messages you send us through the contact form: your email, the message and the page you wrote from.
3. What leaves Tokex
- Your prompts go to the provider that runs them. Tokex is the customer of record with upstream model providers; your request content is forwarded to the provider whose model you asked for (or the one the router chose), under that provider's terms and privacy policy. Tokex does not add your identity to it.
- Card details go to the payment processor and nowhere else. Checkout happens on the processor's pages. Tokex receives confirmation that a charge succeeded, the amounts, and the processor's identifiers; it never sees or stores a card number.
- Sign-in codes and alerts go through a mail provider, which receives your address and the message. So do waitlist emails: the confirmation when you join, your link again if you join twice (at most once an hour), and your invite. Waitlist mail is sent through Resend.
- Our hosts store what the website collects. The website runs on Vercel; the waitlist and contact messages are stored in a database run by Supabase, and, if that database cannot be reached, in Vercel's file store until it can be.
- Where it is processed. Vercel, Supabase and Resend process this data in the United States, where it may be accessible to the courts, law enforcement and national security authorities there.
- Operator alerts. Events that need a person (a purchase whose payment record disagrees with the processor, an account frozen for repeated flags) are written to our own logs and, where configured, sent to our own alert endpoint. They carry account identifiers and amounts, not content.
We do not sell, rent or share your information with anyone else, and we do not use it to train models.
4. What we do not do
- No analytics, no tracking pixels, no third-party scripts, no third-party fonts. The app and the public pages load only from our own origin.
- No cookies. Your credential is held in your own browser's storage and sent only to Tokex. The website also keeps, in that storage and only after you act: your Light or Dark choice, your chart layout on the Terminal, the referral code you arrived with (for that visit), and, once you join the waitlist, the link to your place in line.
- No advertising, no profiling, no automated decisions about you beyond the ones the product states plainly: spend limits you set, the moderation screen, and the freeze rules in the terms.
5. How long we keep it
- The ledger and its receipts: for as long as the account exists, and after that for as long as accounting and tax rules require, because they are the record of money.
- Sign-in codes: until used, expired or superseded, then only as a dead row.
- Stored responses (the response record): a short time, measured in hours, then gone.
- The waitlist: until you leave it, or until WAITLIST RETENTION after Tokex opens to you, whichever comes first. Leaving deletes your entry at once.
- Contact messages: until they are answered, then MESSAGE RETENTION.
- Mail we sent you: as long as the mail provider keeps it under its own terms.
- Logs: RETENTION PERIOD days, then rotated.
6. Your choices and rights
- Freeze the account at any time (the panic action under Keys, or the API). It revokes every other credential and stops everything that moves money. Reads stay open.
- Revoke any credential at any time.
- Redeem what you no longer want, under the bounds the terms describe.
- Leave the waitlist at any time from your place in line on the website, or with the unsubscribe link in any waitlist email. Your entry is deleted.
- Ask us to send you what we hold about you, to correct your email, or to close the account. Closing an account removes the email and revokes every credential. The ledger entries stay, because a ledger that forgets is not a ledger; they remain tied to an account identifier and to no other identity.
- Where the law where you live grants you more (for example under the GDPR or the CCPA), those rights apply and we will honour them; write to the address in section 9. JURISDICTIONAL RIGHTS LANGUAGE, to be confirmed by counsel
7. Children
Tokex is not for anyone under 18, and we do not knowingly collect information from them.
8. Changes to this policy
We may update this policy. Material changes will be announced in the product and by email at least 14 days before they take effect. The version in force is always published at URL.
9. Contact
COMPANY NAME, ADDRESS, EMAIL.
Read next: Terms of service, draft. Questions answers the common ones in plain words.