Privacy Policy

This policy describes how Indexsy Consulting Ltd. (“we”) handles personal information when you use Token Broker. It is meant to satisfy PIPEDA and British Columbia’s PIPA. If you do not agree, do not use the Service.

What we collect

  • Account. Email, password hash, business name, country, optional tax ID, seller application details, wallet address if you sell.
  • Billing. Top-up amounts, tax, Stripe customer and payment-method identifiers once card billing is on. We do not store full card numbers.
  • API use. Key identifiers (hashed), model, token counts, latency, error codes, request id, IP and user-agent on console and API calls.
  • Content. Prompts and completions are transmitted to the filling party to run your request. We do not keep prompt or completion bodies in the billing ledger. Short snippets may appear in operational logs (canaries, upstream error tails) for debugging and abuse review, and are retained only as long as needed for that purpose.
  • Auth mail. Magic-link and password-reset messages, and the fact that they were requested.

How we use it

To operate the exchange (route, meter, bill, pay sellers), authenticate you, prevent fraud and AUP abuse, comply with law, and communicate about the Service. We do not sell personal information. We do not use your prompts to train foundation models.

Who we share with

  • Infrastructure. Cloudflare (Workers, D1, KV, DNS, Email Sending) processes data to host the Service. Traffic may be handled in the region Cloudflare selects.
  • Payments. Stripe, when card billing is enabled.
  • Filling parties. The seller or managed supply that wins a request receives the prompt in order to return a completion. We do not send them your name, email, or API key.
  • Law. If we are legally compelled, or if we believe disclosure is necessary to prevent serious harm.

Cookies and sessions

We use a session cookie after you sign in, and similar tokens for API keys. No third-party advertising cookies. Local storage may hold console UI state.

Retention

Account and ledger records are kept for the life of the account plus up to seven years for tax and dispute records. Request metadata is kept to operate the book and handle chargebacks. You may ask us to delete an account; we will delete or anonymize personal information we do not need to keep for legal or security reasons. Unused credits are handled under the Terms.

Your rights

You may request access, correction, or deletion of personal information, and withdraw consent where we rely on it, by emailing desk@thetokenbroker.ai. We will respond within the time PIPEDA requires. You may complain to the Office of the Privacy Commissioner of Canada or the BC Office of the Information and Privacy Commissioner.

Security

Passwords and API keys are stored hashed. Seller keys are encrypted at rest. No method of transmission or storage is perfectly secure. You must protect your own keys.

Children

The Service is for businesses and adults. We do not knowingly collect information from anyone under 19 (the age of majority in British Columbia).

International

We are based in Canada. Cloudflare and other processors may handle data in other countries with different laws. By using the Service you accept that transfer.

Changes

We will post updates here with a new effective date. Material changes may also be emailed to the address on the account.

Contact

Privacy requests: desk@thetokenbroker.ai
Indexsy Consulting Ltd., Vancouver, British Columbia, Canada.