TokenRaBack to home

Privacy Policy

Version 1.0 · Last updated August 13, 2026

Please read this policy carefully before using the service. By using TokenRa, you acknowledge that you have read and understood this policy. We will notify you of material changes through the platform, your registered email, or another reasonable method.

1. Data Controller

The data controller for this service is the operator of TokenRa. TokenRa is the brand providing an AI API aggregation service. To confirm the applicable legal entity or submit a privacy request, contact us at the privacy email below.

  • Brand: TokenRa
  • Privacy contact: aiuser_aiuser@proton.me
  • Data Protection Officer: No separate DPO has been appointed; the privacy mailbox receives and routes data protection requests.

2. Personal Information We Collect

2.1 Information You Provide

  • Account information: Registration email, username or nickname, password credentials, and account settings. Passwords are stored using hashing or other appropriate security measures, not in plain text.
  • Top-up and transaction information: Top-up amount, credits, order ID, transaction status, refund records, and payment method identifier. Full card numbers and security codes are handled by the payment processor and are not stored on our servers.
  • API and usage information: API keys, requested models and interface types, request times, usage, billing records, and errors. Request content and model output may be temporarily processed to fulfill a request.
  • Communications: Emails, refund requests, privacy requests, and support records sent to aiuser_aiuser@proton.me.

2.2 Information Collected Automatically

  • Device and network information: IP address, browser, operating system, device information, language, timezone, and request source.
  • Security and logs: Login and request times, access paths, operation logs, rate-limit records, error logs, performance data, and security events.
  • Cookies: Used to maintain login status, save language and interface preferences, support core features, and improve the service.

We do not intentionally ask for sensitive information unrelated to providing the service. Do not submit personal information you are not authorized to process, card data, or highly sensitive information in API requests or communications.

3. How We Use Personal Information

Purpose Legal basis, where applicable
Create and maintain accounts, verify identity, and provide API services Contract performance
Process credit top-ups, billing, refunds, and account statements Contract performance; legal obligation
Respond to support, refund, privacy, and security requests Contract performance; legitimate interests
Send billing, security, service, and policy notices Contract performance; legitimate interests
Prevent fraud, abuse, unauthorized access, and security risks Legitimate interests; legal obligation
Diagnose issues, improve performance, analyze usage, and improve products Legitimate interests; consent where required
Comply with laws, court orders, and regulatory requirements Legal obligation

We may aggregate or de-identify information for statistics, capacity planning, and service improvement. Information that cannot reasonably identify an individual is not used as personal information.

4. Cookies and Tracking Technologies

Type Purpose Can be disabled
Strictly necessary Login, authentication, session security, and core functions No
Functional Language, interface, and account preferences Yes
Analytics No third-party advertising tracker is intentionally enabled; limited anonymized operational statistics may be used to improve the service Yes
Marketing Not currently enabled Not applicable

You may clear or restrict cookies through your browser. Disabling strictly necessary cookies may prevent login or core features from working.

5. Sharing and Disclosure

We do not sell your personal information, including “sales” as defined by laws such as the CCPA. We share or disclose information only when necessary:

  • Service providers: Cloud, network, security, customer support, logging, and payment providers receive the minimum information needed to operate the service.
  • Payment processing: Payment card data is handled exclusively by the PCI-DSS-compliant processor Waffo Pancake and is not stored on our servers. We generally receive transaction amount, status, order ID, and payment method identifier.
  • Third-party AI channels: Necessary request parameters may be forwarded to the upstream model or channel selected for your API request. Do not submit unnecessary personal information; upstream providers may apply their own privacy policies.
  • Legal and safety matters: We may disclose information when legally required or to protect users, the platform, the public, or third-party rights and safety.
  • Business transactions: Information may transfer in a merger, acquisition, reorganization, or asset transfer, subject to continuing protection obligations.
  • With your consent: For other purposes after obtaining your clear consent.

6. Data Security

  • TLS/HTTPS encryption in transit.
  • Hashed or otherwise protected password credentials.
  • Least-privilege access controls and important-operation logging.
  • API key management, rate limits, audit logs, and anomaly detection.
  • Regular review of dependencies, configurations, and access permissions.

If a personal information security incident may affect your rights, we will notify you and relevant authorities within the period required by applicable law. Where no shorter legal deadline applies, we aim to complete necessary notice or begin the notification process within 72 hours after confirming the incident.

7. Retention Periods

Data type Retention End-of-period handling
Account information While active; up to 90 days after closure Delete or anonymize
Transaction and billing records Up to 7 years, or as required by tax, accounting, and other laws Delete, anonymize, or archive as required
Support, refund, and privacy request records Up to 3 years after resolution Secure deletion or anonymization
API, operational, and security logs Typically no more than 12 months; security incidents up to 3 years after resolution Delete or anonymize
Cookies By type and browser settings; session cookies expire when the session ends Expire or clear automatically

We may retain information longer when necessary for legal obligations, disputes, security investigations, or preventing repeated abuse.

8. Your Data Rights

Where applicable, you may contact aiuser_aiuser@proton.me to request access, a copy, correction, deletion, restriction, portability, objection to processing, withdrawal of consent, or an opt-out from marketing communications.

To protect account security, we may verify your identity. We typically respond within 30 calendar days after receiving and confirming a request; where the law permits an extension, we will explain the reason and expected timing. You may also complain to your local data protection authority.

9. Marketing and Unsubscribe

With your clear consent, we may send product updates or other marketing communications. You can unsubscribe using the link in an email, account settings, or by emailing aiuser_aiuser@proton.me. Unsubscribing does not affect necessary billing, security, account, outage, or policy notices.

10. International Data Transfers

TokenRa and its cloud, payment, model-channel, and other service providers may process information in different countries. Where required by law, we use contractual protections, Standard Contractual Clauses (SCCs), adequacy decisions, or other appropriate safeguards, and transfer only information necessary to provide the service.

11. Children’s Privacy

The service is intended for users aged 18 or older. We do not knowingly collect personal information from children below that age. If you believe a child provided information, contact aiuser_aiuser@proton.me; we will investigate and delete or otherwise address it as appropriate.

12. Third-Party Links and Services

The service may contain third-party links or integrate with third-party payment, model, login, and other services. This policy applies only to information we collect directly. Third parties follow their own privacy policies.

13. Changes to This Policy

For material changes, we will provide notice through the platform, your registered email, or another reasonable method before the change takes effect, and update the version and date at the top of this page. Continued use after the effective date means you have read and understood the updated policy.

14. Contact Us

For privacy requests, privacy concerns, or questions about this policy:

This policy explains our service privacy practices and is not legal advice. Specific rights may vary by jurisdiction.