Privacy Policy
Last updated:
We process your prompts and outputs only to serve your requests. We never use them to train or fine-tune models, we do not log their content for interactive requests, and we do not sell personal information.
Who we are
PerToken is an OpenAI-compatible inference service operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("PerToken", "we", "us"). This policy covers the marketing site at pertoken.ai, the customer portal at app.pertoken.ai, and the API at api.pertoken.ai (together, the "Service").
For account, billing, and support information we decide how the data is used. For the content you send to the API, we process it on your behalf and only to provide the Service to you.
The short version
- We do not use prompts, messages, images, audio, completions, embeddings, or any other API content to train, fine-tune, or evaluate models.
- We do not write prompt or completion content to logs for interactive requests. It exists only in memory while your request is processed.
- Batch jobs are the exception: their inputs and results are stored so you can retrieve them. See the Data Retention and Logging Policy.
- We keep usage metadata such as token counts, model, status code, and latency so we can bill you and run the Service.
- Requests are processed on GPU servers that we rent from third-party hosts through Vast.ai. We list every subprocessor on the Subprocessors page.
- We do not sell or rent personal information, and we do not use it for advertising.
Information we collect
- Account information: your name, email address, and sign-in records, collected when you create an account in the portal.
- API keys: we store a SHA-256 hash of each key together with its key ID, name, short prefix, owner and workspace, scopes, status, and creation, expiry, and revocation times. We do not store the full key after it is shown to you.
- API content: the prompts, messages, images, audio, and other inputs you send, and the outputs the models return. How long each type is kept is described in the Data Retention and Logging Policy.
- Usage metadata: for each API request we record a request ID, your account or workspace ID, the API key ID, the model, the endpoint, the serving deployment, the HTTP status, input, output, and cached token counts, audio seconds, latency, whether the request streamed or was cancelled, its priority class, any batch job ID, and the computed charge.
- Network and device data: Cloudflare processes connection data such as IP address, user agent, and TLS details to deliver and protect the Service. Our gateway platform logs record request metadata such as time, method, path, and status.
- Billing information: payment details are collected and stored by [PAYMENT PROCESSOR]. We do not store full card numbers.
- Communications: messages you send to our support, security, or abuse addresses.
How we use information
- To provide the Service: authenticate requests, route them to a model, return results, and run batch jobs.
- To meter usage, calculate charges, and bill you.
- To plan capacity, monitor reliability and latency, and fix errors.
- To detect, investigate, and prevent fraud, abuse, and security incidents, and to enforce our Terms of Service and Acceptable Use Policy.
- To respond to support requests and send service and account notices.
- To comply with legal obligations.
- To improve the Service using aggregated usage metadata. We never use API content for this.
Your content is not used for training
We do not use API content to train, fine-tune, distill, or evaluate any model, and we do not provide it to anyone else for those purposes. We do not review API content, except for batch job data that is stored for you, and then only when needed to investigate a specific abuse report, security incident, or support request you raise, or when required by law.
Where information is processed
Cloudflare processes requests in the data center closest to the caller. Account and usage records are stored with Supabase in [SUPABASE PROJECT REGION]. GPU servers rented through Vast.ai may be located in several countries. Where the law requires a transfer safeguard, we rely on [INTERNATIONAL TRANSFER MECHANISM].
How long we keep information
Each type of data has its own retention period, described in the Data Retention and Logging Policy. In short, interactive API content is not stored, usage metadata is kept for billing and operations, and account data is deleted within [ACCOUNT DATA DELETION PERIOD] after you close your account, unless we must keep it longer by law.
Security
We encrypt traffic in transit with TLS, store only hashes of API keys, scope keys to the permissions they need, remove headers, request bodies, cookies, and query strings from error reports before they leave our gateway, and limit internal access to production systems. No system is perfectly secure. To report a vulnerability, see the Contact page.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, and to object to or restrict certain processing. To make a request, email support@pertoken.ai with the subject "Privacy request". We will verify your identity and respond within the time the law requires. You may also complain to your local data protection authority.
If your personal information reached us inside API content sent by one of our customers, please contact that customer first. We will help them respond.
Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal information from children.
Changes to this policy
We will post any change on this page and update the date above. If a change materially affects how we handle your information, we will notify account holders by email or in the portal before it takes effect.
Contact
Questions about this policy: support@pertoken.ai. Postal address: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].