Skip to main content
Last updated: 30 June 2026 This Privacy Policy explains how HK Word Origin New Wisdom Technology Limited (“TokensMind”, “we”, “us”, or “our”) collects, uses, stores, transfers, and protects personal data when you access tokensmind.ai, docs.tokensmind.ai, related dashboards, APIs, billing pages, support channels, and other TokensMind services (the “Services”). TokensMind is a trade name operated by HK Word Origin New Wisdom Technology Limited. Unless expressly stated otherwise, HK Word Origin New Wisdom Technology Limited is the service operator, contracting entity, merchant of record, data user, billing entity, and customer support entity for the Services.

1. Hong Kong privacy framework

We aim to handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”), including the Data Protection Principles covering collection, accuracy and retention, use, security, openness, and access/correction. If you access the Services from another jurisdiction, additional local privacy laws may apply. You are responsible for using the Services in compliance with laws that apply to you.

2. Personal data we collect

We collect only data that is reasonably necessary for account operation, API delivery, billing, fraud prevention, security, customer support, legal compliance, and service improvement.

2.1 Account data

  • Email address.
  • Username, display name, or account identifier.
  • Password hash or authentication credential.
  • Login status, authentication logs, and security events.
  • Organization name, team name, role, or business contact details if you use a business account.

2.2 API usage and technical metadata

When you use our API or dashboard, we may collect:
  • API key identifier.
  • Request timestamp.
  • Selected model, routed model, or model group.
  • Endpoint, request method, response status, error code, latency, and retry information.
  • Token usage, usage units, credit deduction, and balance change.
  • IP address, approximate location derived from IP, user agent, device/browser information, and network information.
  • Application identifier, project identifier, organization identifier, or other metadata needed to operate and bill the Services.

2.3 Payment and billing data

  • Order number, payment amount, currency, payment status, payment channel, payment timestamp, refund status, and invoice/receipt records.
  • Billing contact details and company information where applicable.
  • Card payment data is processed by our payment service providers. We do not store full card numbers, CVV/CVC, or 3DS authentication credentials on our own systems.

2.4 Support and dispute data

  • Information you provide when contacting support, requesting a refund, reporting abuse, or disputing a charge.
  • Screenshots, request IDs, API error details, and other materials you voluntarily provide.

2.5 Prompt and response content

TokensMind does not, by default, persistently store the prompt content you submit through the API or the response content returned by model providers. Prompt and response content is processed transiently for the purpose of routing the request to the relevant model provider, returning the output to you, enforcing security controls, and operating the Services. Model providers may process or retain content according to their own terms, data policies, contracts, and legal obligations. We do not use your prompt or response content to train our own models. We do not knowingly submit your prompt or response content to third parties for model training.

3. How we collect data

We collect data:
  • Directly from you when you register, log in, make a payment, create an API key, submit support requests, or configure your account.
  • Automatically when you use the Services, including through logs, cookies, SDKs, APIs, and security tools.
  • From service providers such as payment processors, fraud prevention providers, cloud infrastructure providers, analytics providers, and identity or compliance vendors.

4. How we use data

We use data to:
  • Provide, maintain, route, secure, and improve the Services.
  • Create and manage accounts, organizations, API keys, credits, usage limits, and billing records.
  • Process payments, credits, refunds, invoices, receipts, disputes, and chargebacks.
  • Calculate API usage, token consumption, account balances, and fees.
  • Detect and prevent fraud, abuse, illegal activity, unauthorized access, API key compromise, payment risk, and high-frequency automated misuse.
  • Enforce our Terms of Service, AI Safety & Abuse Policy, Credits & Refund Policy, and other policies.
  • Respond to customer support requests, refund requests, legal requests, and regulatory inquiries.
  • Send service notices, security alerts, billing notices, policy updates, and account-related messages.
  • Analyze aggregated or anonymized usage patterns to improve reliability, latency, routing, pricing, and product quality.
We do not sell personal data.

5. Sharing and transfers

We may share data with the following categories of recipients where necessary:
  • Model API providers and upstream service providers, for the purpose of completing API requests.
  • Payment processors, acquiring banks, card networks, fraud prevention providers, and chargeback management providers.
  • Cloud hosting, database, network, logging, monitoring, analytics, email, and customer support providers.
  • Professional advisers, auditors, insurers, legal counsel, and compliance consultants.
  • Affiliates, successors, or acquirers in connection with a merger, acquisition, restructuring, financing, or sale of assets.
  • Law enforcement, courts, regulators, payment partners, or other authorities when required by law or when necessary to protect rights, safety, security, or the integrity of the Services.
Where personal data is transferred outside Hong Kong, we take reasonable steps to protect it through contractual, technical, and organizational measures appropriate to the nature of the data and the processing.

6. Model providers

TokensMind may route requests to model providers such as OpenAI, Anthropic, Google, ByteDance, Qwen, Kimi, MiniMax, DeepSeek, Zhipu AI, or other providers shown in the dashboard or documentation. Available providers and models may change over time. Your prompt and response content may be transmitted to the selected or routed model provider solely to process your API request and return output. Each provider may have its own privacy, security, abuse-monitoring, logging, and retention practices. We encourage you to review the relevant provider policies for workloads involving sensitive data.

7. Data retention

We retain data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, accounting rules, tax rules, payment network rules, dispute resolution, fraud prevention, or security needs. Typical retention periods: When data is no longer needed, we delete, anonymize, aggregate, or securely isolate it.

8. Security

We use technical and organizational safeguards designed to protect personal data, including:
  • TLS encryption for data in transit.
  • Encryption or access controls for sensitive stored data.
  • Password hashing and credential protection.
  • API key management and revocation controls.
  • Role-based access controls and least-privilege access.
  • Logging, monitoring, rate limits, and abuse detection.
  • Payment data minimization through payment processors.
  • Internal access review and security incident response procedures.
No system is completely secure. You are responsible for keeping your account credentials, API keys, devices, and integration environments secure.

9. Abuse investigation without default content logging

Because TokensMind does not persistently store prompt/response content by default, we primarily investigate abuse through metadata and operational evidence, including account identifiers, API key identifiers, IP/device information, request timestamps, endpoint/model usage, token volume, error codes, payment records, support reports, user-provided samples, and upstream provider safety signals. Where legally permitted and necessary to investigate serious abuse, fraud, security incidents, payment disputes, or lawful requests, we may temporarily preserve relevant materials voluntarily provided by users, generated by our systems, or received from providers or authorities. Access is limited to authorized personnel with a need to know.

10. Cookies

We use cookies and similar technologies to operate login sessions, remember preferences, improve security, measure performance, detect fraud, and understand product usage. You may control cookies through your browser settings. Disabling cookies may affect login, payment, dashboard, or security functions.

11. Your rights and choices

Subject to applicable law, you may request access to or correction of your personal data. You may also request account deletion, subject to retention required for legal, billing, tax, dispute, fraud prevention, payment network, or security purposes. To submit a request, contact us at the address below. We may need to verify your identity before responding.

12. Children

The Services are not directed to children. You must be at least 18 years old, or the age of majority in your jurisdiction, to use the Services. We do not knowingly collect personal data from children.

13. Changes

We may update this Privacy Policy from time to time. The updated version will be posted on our website with a new “Last updated” date. Material changes may be notified through the dashboard, email, or website notice where appropriate.

14. Contact

Data user and service operator: HK Word Origin New Wisdom Technology Limited
Brand/Product: TokensMind
Email: leon@tokensmind.ai
Registered address: Room 1101D, 11/F, Lippo Sun Plaza, 28 Canton Road, Tsim Sha Tsui, Hong Kong