1. Information We Collect
When you use Anytokens, we may collect the following information:
- Account Information: Email address, username, hashed password
- Payment Information: Processed by Stripe or NOWPayments — we do not store full card numbers or crypto wallet private keys
- Usage Data: API call logs, model name, token usage, latency, IP address
- Device Information: Browser type, operating system (via User-Agent)
- OAuth Data: If you sign in via Google/GitHub/Discord, we receive your public profile and email
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process payment and top-up transactions
- Calculate and log per-token API call costs
- Send service notifications (welcome emails, receipts, balance alerts)
- Prevent fraud and abuse (rate limiting, anomaly detection)
- Generate anonymous, aggregated statistics
3. Information Sharing
We do not sell your personal data.
We share information with third parties only when necessary:
- Stripe — credit card payment processing
- NOWPayments — cryptocurrency payment processing
- Resend — transactional email delivery
- AI Model Providers (SiliconFlow / Google / Groq / OpenAI) — forwarding your API requests to obtain model responses
These providers receive only the data necessary to process requests and are governed by their respective privacy policies.
4. Data Retention
| Data Type | Retention Period |
|---|---|
| API call logs / audit logs | 90 days |
| Payment / transaction records | 7 years (regulatory compliance) |
| Database backups | 7 days (auto-rotated) |
| Account data | Until account deletion |
5. Security Measures
We employ industry-standard security measures to protect your data:
- Encryption in Transit: Site-wide HTTPS with TLS 1.2/1.3
- Password Storage: bcrypt hash (salt round 12), plaintext is never stored
- API Key Storage: bcrypt hashed; the full key is shown only once at creation
- Session Management: JWT signed tokens, 7-day expiration
- Rate Limiting: Redis token-bucket algorithm to prevent brute force
- Security Headers: Helmet.js (X-Frame-Options, CSP, HSTS)
7. Third-Party Services
We use the following third-party services, each with its own privacy policy:
8. Children's Privacy
Anytokens is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
9. International Data Transfers
Our servers are located in Singapore. When you access Anytokens from other regions, your data is transferred to Singapore for processing and storage. We ensure your data is protected during transfer through encrypted transmission and access control measures.
10. Your Rights
You have the following rights regarding your personal data:
Access
View personal data we hold about you
Correction
Correct inaccurate or incomplete data
Deletion
Request deletion of your account and data
Export
Export your data in CSV format
To exercise any of these rights, email privacy@anytokens.net. We will respond within 30 days.
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email at least 7 days in advance and post the updated version on our website. Continued use of our services constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: privacy@anytokens.net
Website: anytokens.net