Privacy Policy

This Privacy Policy explains how SINGHOME JOY PTE. LTD. (“Tokligence”, “we”, “us”, or “our”) collects, uses, stores, and protects your information when you use the Tokligence LLM API marketplace at llm.tokligence.ai (the “Service”). We are committed to transparency and to complying with global data protection regulations, including the GDPR, CCPA, and PIPL.

Last Updated: July 24, 2026

Overview

Tokligence operates an OpenAI-compatible API gateway that routes your requests to a range of third-party large language model (“LLM”) providers and meters your usage for billing. Because we act as a gateway, an important part of understanding our data practices is understanding that the content of your API requests is forwarded to the upstream model provider you select, and that provider processes it under its own terms and privacy policy. This document describes what we collect, how we handle it, and what choices you have.

1. Information We Collect

We collect information necessary to provide, secure, and bill for the Service:

  • Account Information: email address, name, password (stored hashed), and authentication credentials, including identifiers from OAuth providers (Google, GitHub) if you sign in with them.
  • Billing Information: prepaid credit balance, transaction and top-up history, and payment metadata. Card details are handled by our payment processor and are not stored on our servers.
  • API Keys: the API keys we issue to you. We store a hashed representation of each key together with a short non-secret prefix so you can identify it.
  • Usage Metadata: for each API request we record metadata such as the model requested, input/output token counts, timestamps, request status, latency, and error information. This metadata is the basis for usage metering and billing.
  • Bring-Your-Own-Key (BYOK) Credentials: if you configure your own upstream provider API keys, we store them so we can forward your requests on your behalf.
  • Device & Connection Information: IP address, browser type, operating system, and similar technical data collected automatically through logs.
  • Communications: support requests, feedback, and correspondence with our team.

2. Prompts, Completions & Model Requests

This is the most important section for users of an LLM gateway, so we describe it plainly.

Your content is forwarded to third-party model providers

When you send a request through the Service (for example a chat completion), the request content — including your prompts, messages, and any data you include — is transmitted to the upstream model provider that serves the model you selected (for example OpenAI, Anthropic, Google, DeepSeek, Moonshot, or Zhipu). That provider processes your content in order to generate a response and handles it under its own privacy policy and data usage terms. We encourage you to review the policies of the providers whose models you use. We do not control, and are not responsible for, how upstream providers use data you send to them.

How we handle content in transit

We process request and response content to route it to the appropriate provider, to return the response to you, and to derive the usage metadata (such as token counts) needed for billing. Our billing and metering pipeline is designed to operate on metadata rather than on the substance of your prompts and completions.

We do not use your content to train our own models

Tokligence does not use the content of your prompts or completions to train, fine-tune, or develop our own machine-learning models. Whether an upstream provider may use your content for its own model training depends on that provider’s policies and on any settings or enterprise terms you have with it.

Logging

We may retain limited operational logs to secure the Service, detect abuse, debug errors, and comply with law. The scope and retention of any content-bearing logs are described in Section 6 (Data Retention). See the note in that section regarding details that are subject to confirmation.

3. How We Use Your Data

  • To provide, operate, and maintain the Service and route your API requests.
  • To meter usage and bill your prepaid credit balance accurately.
  • To authenticate users, issue and validate API keys, and prevent fraud and abuse.
  • To provide customer support and respond to your requests.
  • To monitor, secure, and improve the reliability and performance of the Service.
  • To send service and account notifications.
  • To comply with legal, tax, and accounting obligations.

4. Data Sharing & Subprocessors

We do not sell, rent, or trade your personal information. We share data only as needed to run the Service and in the limited circumstances below.

Model providers (upstream subprocessors)

To fulfil your API requests we forward request content to the third-party model provider you select. Depending on the models you use, these may include OpenAI, Anthropic, Google (Gemini), DeepSeek, Moonshot (Kimi), and Zhipu (GLM), among others. Each such provider acts as an independent controller or processor of the content you route to it, under its own terms.

Infrastructure & operational subprocessors

  • Payment processing: we use Stripe, a PCI-DSS-compliant payment processor, to handle credit purchases. Your card details are stored and processed by Stripe under its own terms and privacy policy; we do not store full card numbers.
  • Cloud hosting: Google Cloud Platform and Vultr provide our compute and storage infrastructure.
  • Authentication: Google and GitHub OAuth, if you choose to sign in with them.

Other disclosures

  • Legal requirements: when required by law, subpoena, court order, or government request.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with notice to affected users.
  • Protection of rights: to protect the rights, property, or safety of Tokligence, our users, or the public.
  • With your consent: any other sharing will be based on your explicit consent.

5. International Data Transfers

Tokligence operates globally, and your data — including account and billing information — may be processed in countries other than your own. Where required, we rely on appropriate safeguards for cross-border transfers, such as the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, adequacy decisions. Requests you route to a model provider are transmitted to that provider’s infrastructure, which may be located in multiple jurisdictions, under the provider’s own transfer safeguards.

If you require specific data-residency guarantees, contact us at [email protected] before relying on the Service for regulated data.

6. Data Retention

We retain data only as long as necessary to provide the Service and meet legal obligations:

Data categoryRetention
Account informationWhile your account is active, plus 30 days after deletion for recovery
Billing & transaction recordsUp to 7 years, to meet tax and accounting requirements
Usage metadata (token counts, timestamps)For the life of your account, to power your usage history and dashboards; aggregated or anonymized analytics may be kept longer
Security & audit logsUp to 12 months, for security and abuse investigation
Prompt / completion content logsNot retained as part of billing; any transient operational logging is minimized and purged within 30 days

We keep personal data only as long as needed for the purposes above or as required by law. Contact us if you need the current values for a compliance assessment.

7. Data Security

We apply industry-standard safeguards to protect your information, including:

  • Encryption in transit: traffic is protected using modern TLS.
  • Credential protection: passwords and issued API keys are stored hashed, not in plaintext.
  • Access controls: role-based access control (RBAC) and least-privilege access to production systems.
  • Multi-factor authentication for administrative access.
  • Monitoring: logging, network segmentation, and regular review of our infrastructure.

No method of transmission or storage is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and regulators as required by applicable law.

8. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights over your personal data:

GDPR (EU / EEA / UK)

  • Access, rectification, and erasure of your personal data.
  • Restriction of, or objection to, certain processing.
  • Data portability in a machine-readable format.
  • The right to lodge a complaint with your local supervisory authority.

CCPA (California)

  • The right to know what personal information we collect and how it is used.
  • The right to request deletion of your personal information.
  • The right to opt out of the sale of personal information (we do not sell it).
  • The right not to be discriminated against for exercising your rights.

PIPL (China)

  • The right to be informed about, access, correct, and delete your personal information.

To exercise any of these rights, contact us at [email protected]. We will respond within the time required by applicable law (generally within 30 days).

9. Cookies & Analytics

We use strictly necessary cookies and similar technologies to keep you signed in, remember your preferences, and secure the Service. We may also use privacy-respecting analytics to understand aggregate usage and improve the product. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent parts of the Service from working.

10. Marketing Communications

We may send marketing emails — such as product news, feature announcements, and promotional offers — only to users who have explicitly opted in. Marketing consent is collected separately from your acceptance of our Terms of Service and is never a condition of using the Service.

  • Purpose: we use your email address for marketing solely to send you the communications described above; we do not share it with third parties for their own marketing.
  • Opt-in mechanism: marketing emails are off by default. You can opt in through the optional checkbox at registration or the “Marketing emails” toggle in your notification preferences; leaving it off has no effect on your use of the Service.
  • Consent records: we record the time you granted marketing consent (and the time you withdrew it) so that we can demonstrate compliance with applicable law, including Singapore’s Spam Control provisions under the PDPA.
  • Unsubscribing: every marketing email includes an unsubscribe link in its footer, and you can switch off marketing emails at any time in your notification preferences. Withdrawal of consent takes effect immediately.
  • Service emails are unaffected: transactional and security emails — such as receipts, password resets, and security alerts — are necessary to operate the Service and are sent regardless of your marketing preference.

11. Children’s Privacy

The Service is not intended for children under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at [email protected] and we will take appropriate steps.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last Updated” date above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact Information

If you have questions or requests regarding this Privacy Policy or our data practices, contact us:

See also our Terms of Service.