1. Hong Kong privacy framework
We aim to handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”), including the Data Protection Principles covering collection, accuracy and retention, use, security, openness, and access/correction. If you access the Services from another jurisdiction, additional local privacy laws may apply. You are responsible for using the Services in compliance with laws that apply to you.2. Personal data we collect
We collect only data that is reasonably necessary for account operation, API delivery, billing, fraud prevention, security, customer support, legal compliance, and service improvement.2.1 Account data
- Email address.
- Username, display name, or account identifier.
- Password hash or authentication credential.
- Login status, authentication logs, and security events.
- Organization name, team name, role, or business contact details if you use a business account.
2.2 API usage and technical metadata
When you use our API or dashboard, we may collect:- API key identifier.
- Request timestamp.
- Selected model, routed model, or model group.
- Endpoint, request method, response status, error code, latency, and retry information.
- Token usage, usage units, credit deduction, and balance change.
- IP address, approximate location derived from IP, user agent, device/browser information, and network information.
- Application identifier, project identifier, organization identifier, or other metadata needed to operate and bill the Services.
2.3 Payment and billing data
- Order number, payment amount, currency, payment status, payment channel, payment timestamp, refund status, and invoice/receipt records.
- Billing contact details and company information where applicable.
- Card payment data is processed by our payment service providers. We do not store full card numbers, CVV/CVC, or 3DS authentication credentials on our own systems.
2.4 Support and dispute data
- Information you provide when contacting support, requesting a refund, reporting abuse, or disputing a charge.
- Screenshots, request IDs, API error details, and other materials you voluntarily provide.
2.5 Prompt and response content
TokensMind does not, by default, persistently store the prompt content you submit through the API or the response content returned by model providers. Prompt and response content is processed transiently for the purpose of routing the request to the relevant model provider, returning the output to you, enforcing security controls, and operating the Services. Model providers may process or retain content according to their own terms, data policies, contracts, and legal obligations. We do not use your prompt or response content to train our own models. We do not knowingly submit your prompt or response content to third parties for model training.3. How we collect data
We collect data:- Directly from you when you register, log in, make a payment, create an API key, submit support requests, or configure your account.
- Automatically when you use the Services, including through logs, cookies, SDKs, APIs, and security tools.
- From service providers such as payment processors, fraud prevention providers, cloud infrastructure providers, analytics providers, and identity or compliance vendors.
4. How we use data
We use data to:- Provide, maintain, route, secure, and improve the Services.
- Create and manage accounts, organizations, API keys, credits, usage limits, and billing records.
- Process payments, credits, refunds, invoices, receipts, disputes, and chargebacks.
- Calculate API usage, token consumption, account balances, and fees.
- Detect and prevent fraud, abuse, illegal activity, unauthorized access, API key compromise, payment risk, and high-frequency automated misuse.
- Enforce our Terms of Service, AI Safety & Abuse Policy, Credits & Refund Policy, and other policies.
- Respond to customer support requests, refund requests, legal requests, and regulatory inquiries.
- Send service notices, security alerts, billing notices, policy updates, and account-related messages.
- Analyze aggregated or anonymized usage patterns to improve reliability, latency, routing, pricing, and product quality.
5. Sharing and transfers
We may share data with the following categories of recipients where necessary:- Model API providers and upstream service providers, for the purpose of completing API requests.
- Payment processors, acquiring banks, card networks, fraud prevention providers, and chargeback management providers.
- Cloud hosting, database, network, logging, monitoring, analytics, email, and customer support providers.
- Professional advisers, auditors, insurers, legal counsel, and compliance consultants.
- Affiliates, successors, or acquirers in connection with a merger, acquisition, restructuring, financing, or sale of assets.
- Law enforcement, courts, regulators, payment partners, or other authorities when required by law or when necessary to protect rights, safety, security, or the integrity of the Services.
6. Model providers
TokensMind may route requests to model providers such as OpenAI, Anthropic, Google, ByteDance, Qwen, Kimi, MiniMax, DeepSeek, Zhipu AI, or other providers shown in the dashboard or documentation. Available providers and models may change over time. Your prompt and response content may be transmitted to the selected or routed model provider solely to process your API request and return output. Each provider may have its own privacy, security, abuse-monitoring, logging, and retention practices. We encourage you to review the relevant provider policies for workloads involving sensitive data.7. Data retention
We retain data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, accounting rules, tax rules, payment network rules, dispute resolution, fraud prevention, or security needs. Typical retention periods:
When data is no longer needed, we delete, anonymize, aggregate, or securely isolate it.
8. Security
We use technical and organizational safeguards designed to protect personal data, including:- TLS encryption for data in transit.
- Encryption or access controls for sensitive stored data.
- Password hashing and credential protection.
- API key management and revocation controls.
- Role-based access controls and least-privilege access.
- Logging, monitoring, rate limits, and abuse detection.
- Payment data minimization through payment processors.
- Internal access review and security incident response procedures.
9. Abuse investigation without default content logging
Because TokensMind does not persistently store prompt/response content by default, we primarily investigate abuse through metadata and operational evidence, including account identifiers, API key identifiers, IP/device information, request timestamps, endpoint/model usage, token volume, error codes, payment records, support reports, user-provided samples, and upstream provider safety signals. Where legally permitted and necessary to investigate serious abuse, fraud, security incidents, payment disputes, or lawful requests, we may temporarily preserve relevant materials voluntarily provided by users, generated by our systems, or received from providers or authorities. Access is limited to authorized personnel with a need to know.10. Cookies
We use cookies and similar technologies to operate login sessions, remember preferences, improve security, measure performance, detect fraud, and understand product usage. You may control cookies through your browser settings. Disabling cookies may affect login, payment, dashboard, or security functions.11. Your rights and choices
Subject to applicable law, you may request access to or correction of your personal data. You may also request account deletion, subject to retention required for legal, billing, tax, dispute, fraud prevention, payment network, or security purposes. To submit a request, contact us at the address below. We may need to verify your identity before responding.12. Children
The Services are not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use the Services. We do not knowingly collect personal data from children.13. Changes
We may update this Privacy Policy from time to time. The updated version will be posted on our website with a new “Last updated” date. Material changes may be notified through the dashboard, email, or website notice where appropriate.14. Contact
Data user and service operator: HK Word Origin New Wisdom Technology LimitedBrand/Product: TokensMind
Email: leon@tokensmind.ai
Registered address: Room 1101D, 11/F, Lippo Sun Plaza, 28 Canton Road, Tsim Sha Tsui, Hong Kong

