Privacy Policy
Last updated: July 28, 2026
This Privacy Policy explains how Tokenly (“Tokenly,” “we,” “us”) collects, uses, and shares information when you use tokenly.dev and the Tokenly API (the “Service”). Tokenly provides access to third-party AI models, funded by optional surveys and ads. By using the Service you agree to this policy.
Information we collect
- Account information: your email address, a hashed password, and a phone number used for one-time SMS verification to keep accounts real and prevent fraud.
- Usage information: API requests you send are metered by token count so we can bill credits. We record model, timestamp, token counts, and the credits charged.
- Prompt content: the prompts and completions you send through the API or Chat are transmitted to the AI provider that serves your selected model in order to generate a response. For each successful request we also retain a copy of your most recent prompt message (not your full conversation history) and the model's response, together with the model, route, timestamp, and content size, stored in our cloud infrastructure and accessible only to authorized Tokenly personnel for security, fraud prevention, abuse investigation, and support. We do not sell this content or use it to train models.
- Technical information: IP address, approximate location, and device/ browser details, used for security, abuse prevention, and to satisfy legal obligations.
- Earn activity: when you choose to earn credits, we record which surveys/offers you completed and the credits granted.
How we use information
- Operate, meter, and secure the Service and your credit balance.
- Verify accounts, detect and prevent fraud, abuse, and duplicate accounts.
- Route your requests to the appropriate AI provider and return the response.
- Credit rewards you earn and communicate service-related notices.
- Comply with legal obligations and enforce our Terms of Service.
Third parties we share information with
We share only what is necessary to deliver the Service. We do not sell your personal information.
- AI model providers (such as Anthropic, OpenAI, and DeepSeek): receive the prompts you submit for your selected model and process them under their own privacy policies and terms.
- Survey and offer providers (such as CPX Research and TheoremReach): when you open a survey wall we send a Tokenly user identifier so the reward can be credited back to your account. Where you have supplied them, we also send the profile details these partners use to match you to a survey — which may include your date of birth, postal code, and gender — together with your IP address. We send them so that fewer surveys end in “you didn’t qualify”. These partners also receive your survey answers directly and handle all of this under their own privacy policies. Taking surveys is optional, and you can leave these profile fields blank in Settings; doing so reduces how many surveys match you but does not reduce your free daily credits.
- Infrastructure and communications providers (such as our hosting, database, SMS, and email vendors): process data on our behalf to run the Service.
- Legal: we may disclose information if required by law or to protect the rights, safety, and integrity of the Service and its users.
Cookies
We use strictly necessary cookies to keep you signed in and to protect the Service (for example, anti-bot verification). We use Google Analytics to understand how the Service is used.
Data retention
We keep account and usage records while your account is active and as needed to provide the Service, resolve disputes, prevent fraud, and meet legal obligations. Prompt and response records are kept while your account is active and for a reasonable period afterward for those same purposes.
When you delete your account we remove your email address, phone number, and password from it, revoke your API keys, and forfeit any remaining credits. We do not intend to retain information that identifies you after that point. We do keep a record of transactions already settled with advertising and survey partners, no longer linked to you, because those settlements can be reversed months later and we need to be able to account for them.
Your choices and rights
You may access or update your account information at any time in Settings, and you can delete your account yourself from Settings → Delete account — no request or email is needed. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to access, correct, delete, or restrict processing of your personal data. We will honor verified requests as required by applicable law.
Children
The Service is intended only for users who are at least 13 years old. We do not knowingly collect personal information from children under 13.
Security
We use reasonable technical and organizational measures to protect your information, including hashing passwords and restricting access to credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated through the Service.
Contact
Questions or requests about this policy can be sent to support@tokenly.dev.