1. Introduction
TokenGO ("TokenGO," "we," "us") provides a self-operated inference API. This Privacy Policy explains what information we collect when you use our website, dashboard, and APIs (collectively, the "Services"), how we use it, and the choices you have. By using the Services you agree to the practices described here.
2. Information we collect
We collect the following categories of information:
- Account data. Name, email, organization, and authentication identifiers you provide when signing up.
- Billing data. Payment method details, billing address, and transaction history, processed through our payment providers.
- API request metadata. API keys, timestamps, model identifiers, token counts, latency, and routing decisions associated with your requests.
- Prompt and response content. Inputs you send to models and the outputs returned. We process this content only to deliver responses and, where you have opted in, to provide debugging assistance.
- Usage and device data. IP address, user agent, referrer, pages viewed, and product analytics events about how you interact with our website and dashboard. See Section 4 for the cookies and analytics technologies we use.
- Communications. Messages you send to support, sales, or via embedded forms.
3. How we use information
- To operate, secure, and improve the Services.
- To operate inference on contracted compute capacity and enforce rate limits and quotas.
- To bill customers and prevent abuse, fraud, and misuse of the platform.
- To provide customer support and respond to inquiries.
- To send transactional notices and, with consent where required, product updates.
- To measure marketing performance and understand how visitors find and use our website.
- To comply with legal obligations and enforce our Terms of Service.
4. Cookies and analytics technologies
When you visit our marketing website or dashboard, we and selected third parties use cookies, local storage, pixels, and similar technologies to collect usage information. This helps us understand traffic, improve the product, measure advertising, and diagnose errors.
The tools we use include:
- PostHog (product analytics). We use PostHog on our website and dashboard to understand how visitors and signed-in users interact with the Services—for example, page views, button clicks, form submissions, and application errors. PostHog may store identifiers in cookies and browser local storage. Where enabled, it may also record session replays to help us debug usability issues. Data is processed by PostHog, Inc. Learn more at posthog.com/privacy.
- Google Analytics (website analytics). We use Google Analytics on our marketing website to measure traffic, referrers, and general site usage. Google may set cookies and collect device and usage data. Learn more at policies.google.com/privacy. You can opt out of Google Analytics using Google's browser add-on.
Cross-subdomain tracking. PostHog may use cookies set on the tokengo.com domain so that activity on our marketing site and dashboard can be associated with the same anonymous visitor before you sign in. After you log in, we may associate that activity with your account using the identifier you provide at registration.
Your choices. You can limit cookies through your browser settings (block, delete, or receive warnings). Blocking cookies may affect site functionality. Depending on your location, certain analytics or advertising cookies may require your consent before they are placed; where required by law, we will request that consent separately. While we never sell your data, under California law (CPRA) you can opt out of sharing for cross-context behavioral advertising on our Privacy Choices page. You may also use industry opt-out tools such as aboutads.info or youronlinechoices.eu.
5. Prompt and response data
We do not train our own models on customer prompts or responses. To deliver an inference, request content is processed on infrastructure we operate; official APIs serve as fallback where configured. By default we retain prompt and response content only for the period needed to deliver and bill the request, plus a short window for abuse review. Enterprise customers can configure zero-retention routing on supported models.
6. Sharing of information
- Infrastructure partners. We share request content and minimal routing metadata with datacenter partners and official API providers that support delivery.
- Service providers. Hosting, analytics (including PostHog and Google as described in Section 4), payment, email, and customer support vendors acting on our behalf under written agreements.
- Legal and safety. When required by law, to protect users, or to investigate suspected abuse of the Services.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality.
7. Payment processing
We use Stripe for payment, analytics, and other business services. Stripe collects identifying information about the devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including for fraud detection. You can learn more about Stripe and read its privacy policy at https://stripe.com/privacy.
8. Data retention
We retain account and billing data for as long as your account is active and for a reasonable period afterward to satisfy tax, accounting, and legal obligations. Request metadata is retained for analytics and abuse review. You can request deletion of your account data at any time, subject to legal retention requirements.
9. Security
We use industry-standard administrative, technical, and physical safeguards to protect your information, including encryption in transit, least-privilege access controls, audit logging, and regular review of our security posture. No system is completely secure; please protect your API keys and notify us promptly if you suspect unauthorized access.
10. Your rights and choices
Depending on your jurisdiction you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise these rights through your dashboard settings or by contacting us at the address below. We will not discriminate against you for exercising any of these rights.
For cookies and analytics, you can also use the browser and vendor opt-out options described in Section 4. If you are in the European Economic Area, United Kingdom, or California, you may have additional rights regarding targeted advertising and the sale or sharing of personal information; contact us to submit a request.
11. International transfers
We operate globally. Your information may be processed in countries other than the one in which you reside. Where required, we rely on appropriate safeguards such as standard contractual clauses for cross-border transfers.
12. Children
The Services are not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, provide additional notice through the Services.
14. Contact us
Questions about this policy or our data practices? Email us..