Token Engine Privacy Policy
Effective date: 2026-09-28
This Privacy Policy explains how RUNSUN CLOUD PTE. LTD. ("Token Engine", "we", "us") collects, uses, shares and protects personal data when you use Token Engine. It is prepared with reference to Singapore's Personal Data Protection Act 2012 ("PDPA"). Our core commitments: by default we do not store your prompts or outputs (Section 2 lists the exceptions), we do not sell personal data, and we do not use your content for model training without your consent.
1. Information We Collect
| Category | Details | Source |
|---|---|---|
| Account information | Email, name or display name, password hash, identifiers from third-party sign-in (Google, Microsoft or X: the provider's ID for your account, and the email address, name, user name or @handle it shares with us), the public address of a crypto wallet you sign in with, organization name | You / sign-in provider |
| Payment information | Order and payment IDs, amount, and your card's brand, last four digits and fingerprint (a code that identifies a card without revealing its number). Card details and billing details are collected directly by our payment processor; we keep only the limited data listed here | You / payment processor |
| Referral information | If you sign up through a partner's referral link: the partner and referral code that referred you, and the commission your usage earns the partner. Partners see only counts and commission totals, never who you are | Referral link / generated automatically |
| Usage metadata | Timestamp, model, Provider, token counts, cost, latency, status code, API key identifier | Generated automatically |
| Inputs and Outputs | Prompts, files and model responses. By default held only transiently in memory to process the request, and not written to disk, except as described in Section 2 | You |
| Device and log data | IP address, browser type, operating system, pages visited, cookie identifiers | Generated automatically |
| Security and anti-abuse data | The result of the CAPTCHA check on our sign-up, sign-in and password reset pages; your payment card's fingerprint, brand and last four digits, and your email address in a normalized form, which we use to give each person one trial credit and keep after your account is closed to prevent repeat trials | CAPTCHA provider (hCaptcha or Cloudflare Turnstile) / payment processor / generated automatically |
| Communications | Emails, support tickets and attachments you send us | You |
2. Prompt and Output Logging
- Off by default. Except as described below, we do not store the content of your Inputs or Outputs; we keep only the usage metadata described in Section 1.
- Opt-in logging. You may enable "content logging" in your account settings to view request history in the dashboard for debugging or auditing. Logged prompts and responses are stored encrypted, and are deleted when you delete them or automatically after 90 days. If an organization turns content logging on, its owners and administrators can read the prompts and responses of requests made with its API keys. We may offer a discount to users who choose to share logs to help improve the Service; this requires separate consent and can be turned off at any time.
- Safety and compliance exception. To detect abuse, meet legal obligations or respond to security incidents, we may automatically classify content and retain flagged requests for a short period, accessible only to authorized personnel.
- First-Party Services. Endpoints operated by Token Engine follow the same no-storage default and are not used for training without opt-in.
- Retries. If a request carries an Idempotency-Key header, we keep its response (up to 1 MiB) and a one-way fingerprint of the request for 24 hours after it completes, so that a retry with the same key gets the same answer.
3. How We Use Information
- To provide, route and maintain the Service, including forwarding requests to Providers;
- To meter usage, bill, issue invoices and prevent payment fraud;
- To secure accounts, detect abuse and troubleshoot;
- To produce aggregated, de-identified statistics (such as model rankings and usage trends) that do not identify any individual or organization;
- To send service notices, and, with your consent, marketing messages you can unsubscribe from at any time;
- To comply with legal obligations.
5. International Transfers
Our servers and those of Providers may be located in Hong Kong (Microsoft Azure East Asia, where our servers run), the United States and other regions where Providers operate. Calling a model means your Inputs may be transferred to the country where that Provider operates. Where we transfer personal data outside Singapore, we will ensure the recipient provides a standard of protection comparable to the PDPA, for example through contractual clauses. Each model page shows the Provider's data processing region, and you can restrict routing by region.
6. Retention
| Data type | Retention period |
|---|---|
| Account information | While your account is active; deleted or anonymized within 30 days after closure, except these records, which we keep: invoices, with the name and email address they were issued to, and credit and usage records without content (billing records); records of your acceptance of the Terms and this Policy, and audit records of actions on your account (evidence); your card's fingerprint, brand and last four digits and the normalized email address in Section 1 (to prevent repeat trials); and referral, commission and payout records, including referral codes you created as a partner (commission records). Our payment processor keeps its own records |
| Payment and billing records | As required by tax and accounting law, typically 5 to 7 years |
| Usage metadata | Shown in your dashboard for 12 months; kept afterwards, without content, only as part of billing records |
| Inputs and Outputs | Not stored by default; if content logging is on, kept until you delete them or automatically deleted after 90 days; a response kept for a retry under Section 2.5, 24 hours |
| Flagged abuse requests | 30 days, extended where needed for investigations or legal proceedings |
| Security logs (e.g. IP address) | 6 months (for a sign-in session, 6 months after it ends); the IP address and browser recorded with your acceptance of the Terms and this Policy are kept with that record |
Deleted or anonymized data can remain in our backups for up to 30 more days.
7. Security
We use encryption in transit (TLS) and at rest, hashed storage of API keys, least-privilege access controls and audit logging. Connections to Providers are encrypted. No system is completely secure. If a data breach occurs, we will notify you and the Personal Data Protection Commission (PDPC) as required by the PDPA.
8. Your Rights
Subject to applicable law, you have the right to:
- Access a copy of the personal data we hold about you (in the dashboard, "Download my data" gives your account data as a JSON file) and how it has been used or disclosed;
- Correct inaccurate data, including your name and email address, in the dashboard or by contacting us;
- Delete content logs and close your account, both in the dashboard (Section 6 says what we keep after closure);
- Withdraw consent, for example by turning off content logging or unsubscribing from marketing; withdrawal does not affect prior lawful processing;
- Export usage records and invoices in a common format (CSV for usage records, PDF for invoices) in the dashboard;
- Object to or restrict processing, and complain to the Personal Data Protection Commission of Singapore (PDPC) or the data protection authority where you live.
Send requests to tokenservice@runsun.com. We may need to verify your identity and will respond within 30 days.
10. Children
The Service is not directed to anyone under 18. We do not knowingly collect children's personal data and will delete it and close the account if we learn of it. If your product serves minors, you are responsible for obtaining any parental consent required by law.
11. Changes and Contact
We may update this Policy from time to time and will update the effective date above. We will give at least 15 days' notice of material changes by email or website notice before they take effect.
Organization: RUNSUN CLOUD PTE. LTD., 3 FRASER STREET #04-23A DUO TOWER SINGAPORE (189352)
Contact: tokenservice@runsun.com