Privacy

Privacy policy

Last updated: 27 July 2026

Tokenator sits between your applications and AI model providers. This policy explains what we handle, what we store, and what we never do with your prompts and data.

The short version

  • We do not train any model on your prompts or outputs.
  • Zero-retention workspaces store nothing — no cached responses, no captured prompt or output content.
  • Prompt/response capture is opt-in and off by default.
  • Your provider API keys are encrypted at rest and never logged.
  • Each tenant is strictly isolated — one customer's data never touches another's.

What we collect

Account data. Your email and workspace/organization details, via our identity provider, to sign you in and associate usage with your account.

Usage metadata. For each request we record operational metadata — timestamp, model requested vs. served, token counts, cost and savings, cache hit/miss, and latency — so we can meter usage, show your savings dashboard, and enforce budgets. This metadata carries no prompt or output content unless you explicitly opt into content capture.

Prompt & output content. By default we do not persist the content of your prompts or the model's responses beyond the moment needed to serve the request. If you enable capture (for Prompts/Evals features), that content is stored in your tenant only, and can be disabled or deleted. Zero-retention workspaces cannot capture content at all.

How your requests are handled

To serve a request we forward it to the model provider you chose (or that routing selected within your rules). Providers act as sub-processors: OpenAI, Anthropic, Google, OpenRouter, Moonshot, or a self-hosted/custom endpoint you configure. Each provider handles the request under its own terms. When you bring your own key (BYOK), the call settles directly with that provider on your account.

Caches are checked before a model is called and are strictly per-tenant — never shared across customers. Zero-retention workspaces skip the cache entirely.

Provider keys & secrets

Provider API keys you add are encrypted at rest and are never returned to the browser or written to logs. They are used only to make the calls you request.

Data location, retention & deletion

Operational metadata is retained to power your dashboard and billing history. You can request deletion of your workspace data by contacting us. Enterprise engagements can pin an EU region, sign a DPA, or self-host so that nothing leaves your perimeter.

Website analytics & cookies

Cookies. Inside the product we use only the cookies required to keep you signed in and remember your theme preference. We do not use third-party advertising cookies.

Visitor identification (marketing site). On our public marketing website we use RB2B, a third-party visitor-identification service, to understand which businesses and visitors are interested in Tokenator and to improve our outreach. This may identify visitors (for example, associated company or professional contact details) and involves sharing website-visit data with that provider. It applies to the public website only — it never has access to your prompts, model outputs, workspace data, or anything that flows through the gateway.

If you'd prefer not to be identified, you can browse with tracking protection / an ad-blocker, or contact us at support@tokenator.ai and we'll honor an opt-out.

Changes & contact

Tokenator is in beta and this policy may change; we'll update the date above. Questions or a data request? Email support@tokenator.ai.

This is a beta draft provided for transparency and is not a substitute for a contract or legal advice.