TokenKiln is under maintenance. Logins and new accounts are paused. Existing API keys continue to work. Contact TokenKiln

Privacy Policy

Last updated 2026-08-05. Data controller: TokenKiln Pty Ltd (ABN 19 701 051 541), an Australian company. Contact support@tokenkiln.com for any privacy question or request.

Data we process

  • Account: email address, password hash (bcrypt), Terms acceptance timestamp and version, and the IP address from which your email address was verified
  • Google sign-in (if used): your Google account identifier and verified email address, received from Google
  • API keys: SHA-256 hash and a display prefix, never the raw key
  • Usage: model, token counts, cost, latency, status, timestamps, request ids
  • Billing: credit ledger and Stripe customer, session and invoice references; for large card top-ups, Stripe Identity verification status and related session identifiers
  • Support: ticket subjects and the message bodies you send us
  • Email verification and password reset tokens, which expire and are single-use
  • Diagnostics: server error records, which may include the account id associated with a failed request. These never contain prompt or response content

Data we do not store

API requests (chat completions, embeddings) are proxied to the inference backend and never written to our database. We keep only the resulting token counts, needed to bill you. Card numbers are handled by Stripe Checkout and never reach our servers.

Two features are deliberate exceptions, both under your control: the dashboard playground stores your conversation so you can resume it, and the Batch API stores queued job content until it runs. Both are deletable from your account and included in your data export.

Your IP address is used transiently, in memory, to rate limit sign-in and API requests, and is not written to our database, with two exceptions: we record the IP address from which your email address was verified (or from which you first signed in with Google), once, to help prevent fraud and to document account ownership if a payment is disputed; and, when you accept the high-value credit acknowledgment shown at checkout for purchases of US$1,000 or more, we record the IP address and browser user-agent of that acceptance, together with the amount and the version of the text you ticked, so the record can be produced with a statement of account activity. Our hosting provider keeps standard request logs.

Cookies and local storage

We use no analytics, advertising or tracking cookies, and load no third-party scripts. Visiting this site without signing in sets nothing at all. Because the two cookies below are strictly necessary to provide a service you asked for, they do not require consent under the ePrivacy Directive, and we therefore show no cookie banner.

  • tk_session — keeps you signed in. HttpOnly, Secure, SameSite=Lax. Expires 30 days after it is issued, or immediately when you log out
  • tk_oauth_state — set only during Google sign-in to prevent request forgery. Expires after 10 minutes and is deleted as soon as sign-in completes

Signed in, your browser also stores small interface preferences locally (whether you dismissed the setup guide, which language tab you last used in the docs). These stay on your device, are never sent to us, and clearing your browser data removes them.

Why we process it, and our legal basis

  • To provide the service — authenticating you, metering usage, billing, and support. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b))
  • To keep the service safe — rate limiting, abuse and fraud prevention, diagnosing errors. Legal basis: our legitimate interests in operating a secure service (Art. 6(1)(f))
  • To meet legal duties — tax, accounting and financial record keeping. Legal basis: legal obligation (Art. 6(1)(c))

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train models.

Subprocessors

  • Railway: application hosting and PostgreSQL database (United States)
  • Stripe: payment processing, invoices, receipts, tax ID collection, and (for card top-ups of US$1,000 or more) identity document verification via Stripe Identity
  • Resend: transactional and support notification email
  • Google: sign-in identity, only if you choose to sign in with Google
  • GitHub: stores our encrypted, off-site database backups. Backups are encrypted with a key GitHub does not hold, and are retained for 30 days
  • Operator-controlled GPU hosts: inference compute

Retention

Account and usage data are kept while your account is active. When you delete your account, conversation and queued batch content is erased, and personal identifiers are removed from the remaining records. Financial records are retained in anonymised form to meet Australian tax and accounting obligations. Encrypted backups age out after 30 days, so a deletion propagates fully within that window.

Your rights

From your dashboard you can export all of your data as JSON and delete your account yourself, at any time, without contacting us. You may also email support@tokenkiln.com to access, correct, or delete your information, or to object to or restrict processing.

If you are in the EEA or UK, you additionally have the right to data portability and to lodge a complaint with your local supervisory authority. If you are in California, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights; as noted above we do not sell or share personal information. In Australia, we handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles, and you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) if you are unsatisfied with our response.

Data breaches

If a breach of personal information occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and any other regulator where we are obliged to do so.

International transfers

We are based in Australia and our infrastructure and subprocessors operate in the United States and other regions. Where personal data is transferred out of the EEA or UK, that transfer relies on the standard contractual clauses offered by the subprocessor. If you need a signed data processing agreement, contact support@tokenkiln.com.

Changes

We will update the date at the top of this page when this policy changes, and will notify account holders by email of any change that materially affects your rights. Governing law references: New South Wales, Australia.

Related: Security, Terms.