1. Information We Collect

2. Prompt and Output Logging

  1. Off by default. Except as described below, we do not store the content of your Inputs or Outputs; we keep only the usage metadata described in Section 1.
  2. Opt-in logging. You may enable "content logging" in your account settings to view request history in the dashboard for debugging or auditing. Logged prompts and responses are stored encrypted, and are deleted when you delete them or automatically after 90 days. If an organization turns content logging on, its owners and administrators can read the prompts and responses of requests made with its API keys. We may offer a discount to users who choose to share logs to help improve the Service; this requires separate consent and can be turned off at any time.
  3. Safety and compliance exception. To detect abuse, meet legal obligations or respond to security incidents, we may automatically classify content and retain flagged requests for a short period, accessible only to authorized personnel.
  4. First-Party Services. Endpoints operated by Token Engine follow the same no-storage default and are not used for training without opt-in.
  5. Retries. If a request carries an Idempotency-Key header, we keep its response (up to 1 MiB) and a one-way fingerprint of the request for 24 hours after it completes, so that a retry with the same key gets the same answer.

3. How We Use Information

4. How We Share Information

  1. Model Providers. When you call a model, your Inputs are sent to the Provider that serves the request. Each Provider handles data under its own policies; some retain data briefly for abuse monitoring, and some may use it for training. We disclose these policies on each model page and let you exclude Providers that do not meet your requirements. We do not share account identity information such as your email with Providers, except for abuse investigations or where required by law.
  2. Service providers. Cloud hosting, payment, email, CAPTCHA (hCaptcha or Cloudflare Turnstile), customer support, analytics and security vendors, and, if enabled, a blockchain node (RPC) provider that checks the signatures of smart-contract wallets at sign-in, process data only on our instructions and under contract. When you sign in with Google, Microsoft or X, that provider handles the sign-in under its own terms and privacy policy.
  3. Affiliates. Within the scope of this Policy, including affiliates that operate First-Party inference services.
  4. Organization administrators. If you belong to an organization account, its administrators can view your usage records. If the organization turns on content logging, its owners and administrators can also read the prompts and responses of requests made with its API keys.
  5. Legal and protection. To respond to lawful requests or to protect the rights and safety of us, our users or the public.
  6. Business transfers. In a merger, acquisition or sale of assets, the recipient will remain bound by this Policy.

We do not sell your personal data.

5. International Transfers

Our servers and those of Providers may be located in Hong Kong (Microsoft Azure East Asia, where our servers run), the United States and other regions where Providers operate. Calling a model means your Inputs may be transferred to the country where that Provider operates. Where we transfer personal data outside Singapore, we will ensure the recipient provides a standard of protection comparable to the PDPA, for example through contractual clauses. Each model page shows the Provider's data processing region, and you can restrict routing by region.

6. Retention

Deleted or anonymized data can remain in our backups for up to 30 more days.

7. Security

We use encryption in transit (TLS) and at rest, hashed storage of API keys, least-privilege access controls and audit logging. Connections to Providers are encrypted. No system is completely secure. If a data breach occurs, we will notify you and the Personal Data Protection Commission (PDPC) as required by the PDPA.

8. Your Rights

Subject to applicable law, you have the right to:

Send requests to tokenservice@runsun.com. We may need to verify your identity and will respond within 30 days.

9. Cookies and Similar Technologies

We use essential cookies for sign-in and security, and, with your consent, analytics cookies to understand how the website is used. At present the Service uses only essential cookies (one that keeps you signed in to the dashboard, a short-lived one that protects a sign-in through Google, Microsoft or X, and a short-lived one that keeps a sign-up in progress) and no analytics cookies. The CAPTCHA on some of our sign-up, sign-in and password reset pages is loaded from our CAPTCHA provider (hCaptcha or Cloudflare Turnstile), which may set its own security cookies on its own domain. We do not use cross-site advertising cookies. You can manage cookies through your browser (the Cookies section of the Privacy settings page in the dashboard describes the ones we use); disabling essential cookies may prevent sign-in. API calls do not use cookies.

10. Children

The Service is not directed to anyone under 18. We do not knowingly collect children's personal data and will delete it and close the account if we learn of it. If your product serves minors, you are responsible for obtaining any parental consent required by law.

11. Changes and Contact

We may update this Policy from time to time and will update the effective date above. We will give at least 15 days' notice of material changes by email or website notice before they take effect.

Organization: RUNSUN CLOUD PTE. LTD., 3 FRASER STREET #04-23A DUO TOWER SINGAPORE (189352)

Contact: tokenservice@runsun.com