All policies

Legal

Privacy Policy

Effective September 1, 2026

This Privacy Policy explains how Token Forge Cloud LLC (“TokenForge,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with the TokenForge website, console, APIs, model inference services, and related tools and services (collectively, the “Services”). Capitalized terms not defined here have the meaning given in our Terms of Service.

This Policy is incorporated into and supplements our Terms of Service. Where a separate data processing agreement applies to a Business Customer, that agreement governs our processing of personal data on that customer’s behalf to the extent of any conflict.

1. Who We Are and Scope

TokenForge is the controller of the personal data described in this Policy, except where we process Customer Content on a customer’s behalf, in which case the customer is the controller and we act as a processor. This Policy applies to visitors of our marketing website, users of our console (registration, login, dashboard, API keys, billing, playground), and developers who integrate our Services.

2. Information We Collect

Information you provide:

  • Account information — your email address, authentication credentials, and any profile information you choose to provide, such as a username or display name. Where you do not provide a display name, the console may derive one from your email address.
  • Billing information — prepaid credit purchases and related transaction records, and, where you pay by invoice, billing contact and company details. Card payments are processed by Stripe, and for card payments we do not receive or store full payment card numbers.
  • Communications — information you provide when you contact support or send us notices.

Customer Content:

  • Inputs and Outputs — text, data, or other materials you submit to the Services and the content generated in response. Our handling of Customer Content is described in Section 5.

Information collected automatically:

  • Usage and operational metadata — request identifiers, timestamps, model requested, token counts, request status, and billing and credit-reservation amounts, together with operational logs and account activity logs (such as login events, API key administration, and password changes) used to run, secure, and bill for the Services. These records do not include Inputs or Outputs.
  • Device and technical data — IP address, browser type, and similar information collected through server logs and, on our marketing pages only, through analytics.
  • Cookies and similar technologies — see Section 7.

3. How We Use Personal Data

We use personal data to:

  • provide, operate, and maintain the Services, and authenticate your account;
  • process credit purchases and calculate usage-based charges;
  • secure the Services and detect, prevent, and investigate fraud, abuse, security incidents, and violations of our Terms (including screening Customer Content as described in Section 5);
  • provide support and send transactional communications (for example, email verification, password reset, billing, and service or legal notices);
  • understand and improve our marketing website through analytics; and
  • comply with legal obligations and enforce our agreements.

4. How We Disclose Personal Data

We disclose personal data only as described here, and we do not sell personal data, and we do not share personal data for cross-context behavioral advertising (as those terms are defined under California law):

  • Third-party inference providers — to provide the Services, we transmit Inputs and related request data to third-party model inference providers. We describe the categories of these providers and their material data-handling practices (including retention and whether Customer Content is used to train models) in our service documentation. We are not required to identify specific providers by name in our public documentation, except to the extent required by applicable law or an applicable data processing agreement.
  • Payment processor — Stripe, to process credit purchases.
  • Email delivery provider — to send transactional email such as verification and password-reset messages.
  • Analytics and session-replay providers — Google (Google Tag Manager and Google Analytics) and Microsoft (Clarity), on our marketing pages only (see Section 7).
  • Hosting and infrastructure providers — who host and operate the Services on our behalf under confidentiality obligations.
  • Professional advisors, and legal/regulatory disclosures — where reasonably necessary to comply with law, respond to lawful requests, or protect our rights, users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

5. Customer Content (Inputs and Outputs)

Consistent with our Terms of Service:

  • We process and transmit Customer Content as necessary to provide, secure, and bill for the Services.
  • Inputs and Outputs are screened for unlawful activity, misuse, and security threats, but are not retained after processing, except as required by law.
  • We do not use Customer Content to train or improve AI models. We contractually require our third-party inference providers not to retain Inputs or Outputs after processing, and not to use Customer Content to train or improve AI models, except for retention required by law.

If you submit personal data within Customer Content, you are responsible for providing any notices and obtaining any consents required for that submission.

6. Data Retention

We retain account information for as long as your account is active and as needed to provide the Services. We retain usage, billing, operational, and account activity metadata as needed to operate the Services, resolve disputes, prevent fraud, and comply with law. We do not retain Inputs or Outputs after processing, except as required by law (see Section 5). We retain personal data for longer only where required or permitted by applicable law.

7. Cookies, Analytics, and Session Replay

Essential cookies. The console uses a strictly necessary, HttpOnly session cookie to keep you signed in. This cookie is required for the console to function and is not used for advertising.

Analytics and session replay (marketing pages only). On our marketing website, we use Google Tag Manager, Google Analytics, and Microsoft Clarity (which may record page interactions such as clicks and scrolling) to understand and improve the site. These technologies are not loaded in the console, so pages where you enter credentials, prompts, or API keys are not subject to this analytics or session recording.

Your choices. You can control cookies through your browser settings. Where required by law, we obtain consent for non-essential cookies, and we honor recognized opt-out preference signals (such as Global Privacy Control) as applicable. You can opt out of Google Analytics via Google’s browser add-on.

8. International Data Transfers

We are based in the United States. You may select the United States or Singapore as the region in which your Inputs and Outputs are processed for inference, and your inference requests are processed in the region you select. Account, billing, and operational data are processed in the United States. Our service providers may process personal data in these and other countries whose data-protection laws differ from yours. Where required, we implement appropriate safeguards for cross-border transfers (such as the European Commission’s Standard Contractual Clauses or an equivalent mechanism).

9. Security

We use technical and organizational measures designed to protect personal data, including HttpOnly session cookies, storage of API keys as hashes rather than in plaintext, and access controls. Newly created API keys are shown only once at creation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please keep your credentials confidential and notify us at help@tokenforgecloud.com of any suspected unauthorized access.

10. Your Privacy Rights

Depending on where you live, you may have the right to:

  • access, correct, update, or delete your personal data;
  • request a portable copy, or restrict or object to certain processing;
  • withdraw consent where processing is based on consent; and
  • for California residents, know, delete, and correct personal data, opt out of any “sale” or “sharing” (we do neither), and not be discriminated against for exercising your rights.

To exercise these rights, contact us at help@tokenforgecloud.com. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where permitted. If we decline a request, you may appeal by replying to our response. Individuals in the EEA/UK also have the right to lodge a complaint with their supervisory authority.

11. Children’s Privacy

The Services are intended for users who are at least 18 years old. We do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us and we will take appropriate steps to delete it.

12. Third-Party Services

The Services may link to or interoperate with third-party websites and services that we do not control. Their privacy practices are governed by their own policies, and we encourage you to review them.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new Effective Date and, where required by law or for material changes, provide additional notice. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy, to the extent permitted by law.

14. Contact Us

Token Forge Cloud LLC
 [Mailing address]
 Email: help@tokenforgecloud.com