Privacy Policy

Last updated: 26/12/2025

TokAI (“TokAI”, “we”) provides a SaaS platform for building and operating AI agents, ingesting sources (documents/web/media), and generating responses using third-party model providers.

1) Scope

This Policy applies to TokAI, including the dashboard, APIs, SDKs/widgets, integrations, and any website/service operated by TokAI (the “Service”).

2) Data we process

  • Account data: name, email, organization, roles, credentials, API keys/sub-keys.
  • Billing data: plan, payment status, transaction identifiers (we do not store full card data if handled by a payment processor).
  • Customer Content: documents, URLs, transcripts, prompts/instructions, chat messages, source metadata.
  • Technical data: IP, user-agent, logs, timestamps, events, metrics, errors.
  • Usage/cost data: tokens, requests, consumption per agent/sub-key, plan limits.

3) Purposes

  • Operate the Service (ingestion, indexing, search, RAG, responses).
  • Security, abuse prevention, and auditing.
  • Support, maintenance, and product analytics.
  • Billing, limits, and usage reporting.
  • Legal compliance.

4) AI and “training”

  • TokAI does not fine-tune or train models using Customer Content by default.
  • TokAI may vectorize content (embeddings) to enable semantic search and retrieval (RAG). This is not model training.
  • When a request requires a model provider, TokAI may transmit only the minimum necessary content to generate the response.

5) Third parties

We may share minimum necessary data with AI/LLM providers, infrastructure (hosting/storage/CDN), monitoring/analytics (telemetry/logs), and payment processors. Third-party integrations are governed by their own terms and policies.

6) Retention

We retain data as needed to provide the Service, security/auditing, and legal compliance. You may request deletion; certain technical logs may temporarily remain for integrity and security.

7) Security

We implement reasonable safeguards (encryption in transit, access control, logical tenant separation, monitoring). No system is 100% secure.

8) Your rights

Depending on your jurisdiction, you may request access, correction, deletion, portability, objection, or restriction via the Service’s official channels.

9) Changes

We may update this Policy. The current version is published with its updated date.