Data we collect
Tokaroo collects account information such as name, verified email address, authentication identifiers, account and workspace IDs, API-key metadata, saved-card references, billing records, and support communications.
For API operations, Tokaroo records usage and reliability data such as requested Tokaroo mode, token or media quantities, latency, charge, balance effects, trace and request identifiers, errors, and internal provider/model lineage needed for routing, reconciliation, abuse prevention, and incident response.
Request content and caching
Tokaroo transiently processes prompts, messages, files, tool inputs, and model outputs to fulfill API requests. That content is sent only to the model and infrastructure services needed to complete the request.
Eligible text completions may be stored in account-scoped short-lived caches to improve speed and reduce repeated processing. Cache eligibility excludes sensitive routing classes and unsupported media. Separate features that a customer explicitly uses, such as persistent threads or knowledge tools, retain their submitted content until it is deleted or the applicable retention process removes it.
Standard usage and telemetry rows contain operational metadata and quantities rather than prompt or completion text. Internal lineage is not exposed through normal customer responses.
How we use data
Tokaroo uses data to authenticate accounts, route and fulfill requests, apply quality and compatibility checks, calculate charges, maintain balances, provide usage reporting, issue receipts, detect abuse, investigate failures, improve reliability, and support customers.
Aggregate and de-identified measurements may be used to evaluate model quality, latency, reliability, and savings. Tokaroo does not sell personal information or customer request content.
Service providers and model processors
Tokaroo shares data with model providers selected to fulfill requests and with infrastructure, authentication, payment, communications, and security providers needed to operate the service. These recipients receive only the information reasonably needed for their role.
Tokaroo may also disclose information when required by law, to protect users or the service, to investigate fraud or abuse, or as part of a corporate transaction subject to appropriate confidentiality protections.
Payments
Stripe processes card setup, payment authorization, top-ups, optional threshold auto-reload, refunds, disputes, and receipts. Tokaroo does not store full card numbers. Tokaroo stores Stripe identifiers, limited card display data, reload settings, charge records, and the accepted terms version.
Retention and deletion
Tokaroo keeps account, billing, usage, security, and operational records for as long as needed to provide the service, meet accounting and legal obligations, resolve disputes, and enforce agreements. Short-lived caches expire under service retention settings; backups may retain deleted data for a limited recovery period.
When an account is closed, Tokaroo deletes or de-identifies data that is no longer needed, subject to legal, financial, security, backup, and fraud-prevention requirements.
Security
Tokaroo uses access controls, scoped credentials, encryption in transit, protected secret storage, account isolation, logging, and operational monitoring. No system can guarantee absolute security, so customers must protect their API keys and report suspected compromise promptly.
Your choices and requests
You can revoke API keys, manage workspaces, review usage, disable auto-reload, and update payment details from the dashboard. Depending on applicable law, you may request access, correction, deletion, or portability of personal information, or object to certain processing.
Requests can be sent from the account email address to support@tokaroo.com. Tokaroo may verify identity before completing a request.
Policy changes
Tokaroo may update this policy as the service or legal requirements change. Material updates will be posted with a new effective date and, where appropriate, additional notice.
Contact
Privacy questions and data requests can be sent to support@tokaroo.com.