Tokenless

Privacy Policy

What we collect, what we don't, and — most importantly — what we never keep: the content of your requests.

Last updated: July 6, 2026

The short version. Tokenless is a pass-through for AI model requests. We do not log, store, retain, or train on the content of your prompts or the model's responses. We keep only what we need to run your account and bill you accurately: your login details, your prepaid balance, and per-request token counts — never the text itself.

Our no-logs commitment

We built Tokenless around the same principle privacy-first VPNs are built on: the operator of the pipe should not be reading what flows through it. Mullvad states plainly that they “do not keep activity logs of any kind,” and Proton VPN does not log your online activity. We take the same stance for the content of your API traffic:

  • We do not store your requests or responses. Your prompts and the model's completions pass through our systems in memory only, for the moment it takes to fulfill and stream your call, and are then discarded. They are never written to a database or a log.
  • We do not train on your data. Your inputs and outputs are never used to train, fine-tune, or improve any model — ours or anyone else's.
  • We do not sell your data. Ever, to anyone, for any purpose.
  • We meter counts, not content. To bill you we record the number of tokens a request used (input, output, cached) plus the model and a timestamp. That accounting never contains the text of your prompt or the response.

In the interest of the same transparency those VPNs practice, here is the one unavoidable caveat: to actually generate a response, your request must be transmitted to the upstream AI model provider that serves the model you chose. That transmission is inherent to the service. Once the response streams back to you, we retain none of it.

Information we collect

Account information

When you create an account we collect your email address and, optionally, a display name. Authentication is handled by Google Firebase Authentication; your password is managed by Firebase and is never visible to us.

Billing information

Payments are processed by Stripe. We store a Stripe customer identifier, your prepaid balance, and a history of your top-ups and charges. We never see or store your full card number — that data lives with Stripe, a PCI Level 1 certified processor.

Usage metadata (not content)

For each API request we record the time, the model, the token counts, and the computed cost. This is what powers your dashboard and your bill. It does not include the content of the request or response.

Operational data

We keep transient, content-free system signals needed to run the service reliably — for example short-lived error diagnostics and abuse/rate-limit counters keyed to your API key or IP. These do not contain your prompt or completion text and are not used to profile you.

How we use information

  • To provide, maintain, and secure the API and dashboard.
  • To meter usage and charge your prepaid balance accurately.
  • To prevent fraud and abuse (e.g. blocking disposable-email sign-ups that exist only to farm the welcome credit).
  • To send you essential account and transactional email.
  • To comply with legal obligations such as tax and accounting.

Who we share information with

We share the minimum necessary with service providers who process data on our behalf. We do not sell personal information.

  • Upstream AI model providers — your request is forwarded to the provider of the model you call, solely to generate the response. Their handling of that request is governed by their own policies.
  • Stripe — payment processing and card storage.
  • Google Firebase / Firestore — authentication and storage of your account, balance, and usage metadata.
  • Hosting providers — the app and API run on managed cloud infrastructure (Vercel and Google Cloud).
  • Disposable-email screening — at sign-up we check only the domain of your email address against a third-party service to detect throwaway providers. We never send your full address.

We may also disclose information if required by law, or to protect the rights, safety, and property of Tokenless and its users.

Data retention

Request and response content is not retained at all. Account and billing records are kept for as long as your account is open and thereafter only as required for legal, tax, and accounting purposes. Usage metadata (token counts and costs) is retained to power your history until you delete your account.

Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example under the GDPR or CCPA). You can update your profile in the dashboard, and you can request access or deletion at any time by emailing tokenless.support@gmail.com. Deleting your account removes your account and usage records; some billing records may be retained where the law requires.

Security

All traffic is encrypted in transit with TLS. API keys are shown once at creation and stored only as hashes — we cannot recover the plaintext, so keep yours safe and rotate it if exposed. Authentication and payment data are handled by Firebase and Stripe respectively.

Cookies

We use only the essential cookies and local storage needed to keep you signed in and remember your theme preference. We do not run third-party advertising or cross-site tracking.

International transfers

Our providers may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as standard contractual clauses.

Children

Tokenless is not directed to children and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the “last updated” date above and, where appropriate, communicated by email.

Contact

Questions or requests? Email tokenless.support@gmail.com. See also our Terms of Service.

Questions about this document? Email tokenless.support@gmail.com.