Privacy Policy

Last updated: 21 September 2026

This policy explains what personal data TokenRoc collects, why we collect it, who we share it with, and what control you have over it. TokenRoc is operated by Shenzhen Rocfly Blue Electronic Co.,Ltd. (深圳市瑞科福来科技有限公司), which is the data controller for the purposes of this policy.

01What we collect

Category Examples Why
Account data Email address, password hash, account identifier, registration date To create and secure your account
Usage data Timestamps, model requested, token counts, response status, cost per request To meter billing and provide usage reporting
Technical data IP address, browser type, device and operating system Security, fraud prevention, abuse investigation
Payment data Transaction amount, currency, timestamp, payment method type, last four digits of a card To process payments and keep financial records
Support data Name, email address, optional company, enquiry type, and messages you send us To answer your enquiries

When you use the contact form, the information you voluntarily provide is transmitted through TokenRoc's systems to the company's support mailbox. Do not include passwords, API keys, payment details, or other secrets in a contact submission.

We never receive your full card number. Card details are entered directly with our payment provider and are never transmitted to or stored on our servers.

02Your API request content

The prompts you send and the outputs you receive are transmitted through our gateway to the upstream model provider you selected.

Once your request reaches an upstream provider, that provider's own privacy policy applies to its handling of the content. Their retention and training practices are outside our control, so review the policy of any provider whose models you use.

03Who we share data with

We do not sell your personal data, and we do not share it with advertisers.

04International transfers

TokenRoc serves users worldwide, and our infrastructure and providers operate across multiple countries. Your data may therefore be transferred to and processed in countries other than your own, which may have different data protection standards. Where required by law, we put appropriate safeguards in place for such transfers.

05How long we keep it

06Security

We use encryption in transit, hashed password storage, and access controls restricting internal access to those who need it. API keys are stored so we can authenticate API requests and are masked in normal dashboard views; an authenticated account owner can retrieve or revoke their own key through the service.

No system is perfectly secure. Keep your API keys private, rotate them if you suspect exposure, and do not embed them in client-side code or public repositories.

07Your rights

Depending on where you live, you may have the right to:

To exercise any of these, contact us at the address in Section 10. We will respond within the period required by applicable law. We may need to verify your identity first.

08Cookies

The public website uses local storage to remember your analytics choice. The API console may use cookies that are strictly necessary to operate the service and keep you signed in.

Google Analytics is not downloaded, initialized or contacted unless you grant analytics consent through the cookie banner. After consent, Google receives analytics and technical information about use of the public website and may set first-party analytics cookies. More information is available in Google's Privacy Policy and Google Analytics privacy information.

You can withdraw analytics consent at any time through Cookie settings. Withdrawal disables further analytics measurement on the current page. While your saved choice remains denied, Google Analytics will not be initialized on later page loads. Withdrawal also attempts to delete known first-party Google Analytics cookies from this site. Deleting browser cookies cannot recall information that was already transmitted to Google while consent was active. You can also control storage through your browser settings.

09Children

TokenRoc is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10Changes and contact

We may update this policy. Material changes will be posted here with a revised date, and notified by email where practical.

Privacy questions or requests: info@tokenroc.com