Token Boat Privacy Policy
Last updated: September 12, 2026
1. Scope
This policy explains how Token Boat handles information when providing the website, accounts, API gateway, billing, logs, and support. Data processed through a selected model provider may also be governed by that provider's privacy and data-use terms.
2. Information we process
Depending on the features you use, we may process:
- Account data: username, email, organization or group information, sign-in status, and settings.
- Authentication data: protected password representations, OAuth identifiers, and credentials needed for second-factor or passkey features. Support never needs your complete password or API key.
- API and operational data: model ID, endpoint, request time, token or media usage, response status, latency, Request ID, errors, and necessary network diagnostics.
- Request content: prompts, messages, files, images, audio, or video submitted for a model call and the resulting output. Whether body content is logged depends on service configuration, product features, and applicable rules.
- Billing data: balance, recharge, consumption, orders, invoices, and payment status. Payment-card credentials are generally handled by payment providers.
- Device and network data: IP address, browser or device type, language, timestamps, cookies, session identifiers, and security-event data.
- Support data: issue descriptions, Request IDs, attachments, and communications you submit.
3. Why we process information
We process necessary information to create and protect accounts, authenticate API requests, route model calls, calculate usage and charges, display logs, diagnose incidents, prevent abuse, improve reliability, perform contracts, and meet legal obligations.
We do not need sensitive information unrelated to the service. Minimize, de-identify, or redact personal and confidential content before sending a request.
4. Legal bases
Depending on applicable law and context, processing may rely on performing a contract with you, your consent, legal obligations, account and platform security, or another lawful basis. Where separate or written consent is required, the relevant feature should provide a specific notice and consent flow.
5. Model providers and service providers
To complete a selected model call, Token Boat sends the necessary request content and technical information to the corresponding upstream model provider. Changing models may also change the party processing the request.
We may also use cloud infrastructure, content delivery, monitoring, payment, authentication, and customer-support providers. They should process data only as needed to deliver the contracted service and remain subject to appropriate contractual and security duties.
6. Cross-region processing
Model providers and infrastructure may operate in different countries or regions, so request content may be processed outside your location. Where cross-border transfer rules apply, we will use required assessments, notices, contractual measures, or consent. Models or regions may be unavailable where those requirements cannot be met.
7. Retention
We keep information only as long as necessary for the purposes in this policy, contract performance, disputes, and legal, financial, or security requirements. The period depends on the data category, account status, legal limitation periods, security needs, and necessary processing cycles of service providers.
When information is no longer needed, we delete, anonymize, or restrict it as required. Backups and security logs may remain for a limited cycle.
8. Security
We use reasonable measures based on data type and risk, which may include access controls, authentication, key isolation, transport protection, audit logging, backups, remediation, and incident response. No system can guarantee absolute security, so you should also protect accounts, enable available security features, and rotate API keys.
If you suspect exposure or unauthorized access, revoke the key immediately and report the time, Request ID, and affected scope through the Support Center. Never place a complete key in a support request.
9. Cookies and local storage
The website may use necessary cookies or local storage for sign-in, language preferences, security checks, and page settings. If non-essential analytics or marketing technology is introduced, an appropriate notice and choice mechanism should be provided before activation.
10. Your rights
Subject to applicable law, you may request access, a copy, correction, deletion, or restriction of personal data, withdraw consent, or close an account. Some records cannot be deleted immediately when required for law, security, billing, or dispute handling.
Use the console for available account and key controls. Submit other requests through the Support Center. We may verify identity before acting to protect the account.
11. Children
The service is designed primarily for developers and organizations with the necessary technical and legal capacity, not for children. A minor should use it only with guardian consent and guidance and should not submit unnecessary personal or sensitive information.
12. Updates and contact
We may update this policy for changes in products, providers, law, or security practices. Material changes will be communicated through reasonable means and identified by the updated date.
For privacy, data-security, or individual-rights requests, use the Support Center or email support@quantumnous.com. We may verify your identity before acting to protect accounts and personal data.