PrivacyTermsRefundSign in

Privacy Policy

Last updated: 29 August 2026

This Privacy Policy explains how TokenFlow (“TokenFlow”, “we”, “us”), operated by Prasad Swapnil Gundawar, collects, uses, and protects your information when you use our website, chat product, and developer API (the “Service”). By using the Service you agree to this Policy.

Who we are & how to contact us

TokenFlow is a pay-per-use platform that provides access to third-party AI models through a single prepaid wallet. For any privacy question or request, email support@tokenflow.co.in.

Information we collect

  • Account information. Your email address, display name, and the sign-in method you use (Google, GitHub, one-time email link, or email + password). For OAuth we store the provider’s user ID and whether your email is verified. If you set a password, we store only a one-way argon2id hash — never the password itself.
  • Wallet & payment records. Your prepaid balance and an append-only ledger of top-ups and usage (amounts, timestamps, and, where applicable, GST). Card, UPI, and bank details are handled entirely by our payment processor (Razorpay) — we never receive or store your full payment credentials.
  • Usage content & metadata. The prompts you send and the responses you receive through the chat product are stored so you can see your history (retained for the most recent 30 days). For every request we also log token counts, the model used, cost, and timestamps for billing and support.
  • API keys. When you create a developer API key we show it once and store only a SHA-256 hash plus a short display prefix (e.g. tf-live-••••3a9f). We cannot recover a lost key.
  • Technical & security data. IP address, request metadata, and logs used for rate limiting, fraud prevention, debugging, and abuse protection.

How we use your information

  • To provide, operate, and secure the Service and your wallet.
  • To route your requests to the appropriate AI provider and return the response.
  • To meter usage and bill your wallet accurately, and to keep an auditable ledger.
  • To send you transactional email (sign-in links, deposit receipts, low-balance and security notifications). We do not send marketing email without your consent.
  • To detect, prevent, and investigate fraud, abuse, and security incidents.
  • To comply with legal, tax, and accounting obligations.

AI providers & how your prompts are processed

To answer your requests, the content you submit (and the generated response) is transmitted to the third-party AI provider that serves the request — currently Anthropic and OpenAI. Those providers process the data under their own terms and privacy policies. We do not sell your content and we do not use your prompts or responses to train our own models.

When we share information

We share information only with service providers that make the Service work:

  • AI providers (Anthropic, OpenAI) — to fulfil your requests.
  • Payment processor (Razorpay) — to collect top-ups and confirm payments.
  • Email provider (Resend) — to deliver transactional email.
  • Hosting / infrastructure (Railway) — to run the Service and database.
  • Legal — where required by law, regulation, or valid legal process, or to protect our rights, users, and the Service.

We do not sell your personal information.

Data retention

  • Chat history is retained for the most recent 30 days.
  • Transaction and wallet ledger records are retained as required for accounting, tax, and legal purposes.
  • Account information is retained while your account is active and deleted or anonymised on request, subject to the legal retention above.

How we protect your information

Passwords are stored as argon2id hashes; API keys and email link tokens are stored only as hashes; data is transmitted over HTTPS; and all wallet checks are performed server-side. Payment authentication is confirmed via signed processor webhooks, never by the browser. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your data.

Your rights & choices

You may request access to, correction of, or deletion of your personal data, and you may close your account. To make a request, email support@tokenflow.co.in. We will respond within the timeframe required by applicable law.

Cookies

We use a single, essential, signed session cookie to keep you logged in. It is required for the Service to function; we do not use third-party advertising or tracking cookies.

Children

The Service is not directed to, and may not be used by, anyone under the age of 18.

Grievance Officer (India)

In accordance with applicable Indian law, complaints about the processing of your personal data may be addressed to our Grievance Officer: PRASAD SWAPNIL GUNDAWAR, support@tokenflow.co.in.

Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by the “Last updated” date above, and where appropriate we will notify you.

Contact

Questions about this Policy? Email support@tokenflow.co.in.

© 2026 TokenFlowPrivacy PolicyTerms of ServiceRefund Policy