Last updated 2026-08-05. Data controller: TokenKiln Pty Ltd (ABN 19 701 051 541), an Australian company. Contact support@tokenkiln.com for any privacy question or request.
API requests (chat completions, embeddings) are proxied to the inference backend and never written to our database. We keep only the resulting token counts, needed to bill you. Card numbers are handled by Stripe Checkout and never reach our servers.
Two features are deliberate exceptions, both under your control: the dashboard playground stores your conversation so you can resume it, and the Batch API stores queued job content until it runs. Both are deletable from your account and included in your data export.
Your IP address is used transiently, in memory, to rate limit sign-in and API requests, and is not written to our database, with two exceptions: we record the IP address from which your email address was verified (or from which you first signed in with Google), once, to help prevent fraud and to document account ownership if a payment is disputed; and, when you accept the high-value credit acknowledgment shown at checkout for purchases of US$1,000 or more, we record the IP address and browser user-agent of that acceptance, together with the amount and the version of the text you ticked, so the record can be produced with a statement of account activity. Our hosting provider keeps standard request logs.
We use no analytics, advertising or tracking cookies, and load no third-party scripts. Visiting this site without signing in sets nothing at all. Because the two cookies below are strictly necessary to provide a service you asked for, they do not require consent under the ePrivacy Directive, and we therefore show no cookie banner.
tk_session — keeps you signed in. HttpOnly, Secure, SameSite=Lax. Expires 30 days after it is issued, or immediately when you log outtk_oauth_state — set only during Google sign-in to prevent request forgery. Expires after 10 minutes and is deleted as soon as sign-in completesSigned in, your browser also stores small interface preferences locally (whether you dismissed the setup guide, which language tab you last used in the docs). These stay on your device, are never sent to us, and clearing your browser data removes them.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train models.
Account and usage data are kept while your account is active. When you delete your account, conversation and queued batch content is erased, and personal identifiers are removed from the remaining records. Financial records are retained in anonymised form to meet Australian tax and accounting obligations. Encrypted backups age out after 30 days, so a deletion propagates fully within that window.
From your dashboard you can export all of your data as JSON and delete your account yourself, at any time, without contacting us. You may also email support@tokenkiln.com to access, correct, or delete your information, or to object to or restrict processing.
If you are in the EEA or UK, you additionally have the right to data portability and to lodge a complaint with your local supervisory authority. If you are in California, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights; as noted above we do not sell or share personal information. In Australia, we handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles, and you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you are unsatisfied with our response.
If a breach of personal information occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and any other regulator where we are obliged to do so.
We are based in Australia and our infrastructure and subprocessors operate in the United States and other regions. Where personal data is transferred out of the EEA or UK, that transfer relies on the standard contractual clauses offered by the subprocessor. If you need a signed data processing agreement, contact support@tokenkiln.com.
We will update the date at the top of this page when this policy changes, and will notify account holders by email of any change that materially affects your rights. Governing law references: New South Wales, Australia.