Effective: 1 May 2026 · Dhisattva AI Pvt Ltd (TokenTrim)
When you sign in we collect your email address and OAuth profile information to create and manage your account. When you route API requests through TokenTrim we collect request metadata: model name, token counts, latency, and a short redacted preview of your prompt (personally identifiable information is stripped before storage).
We do not store your full prompt text or response text. Provider API keys you submit are stored encrypted (AES-256-GCM) at rest.
We do not sell, rent, or share your personal data with third parties except as required to operate the service (Turso for database hosting, Google Cloud Run for compute, Resend for transactional email) or as required by law. All sub-processors are bound by data processing agreements.
Account data is retained while your account is active. Usage logs are retained for 90 days. You may request deletion of your data at any time by emailing privacy@tokentrim.in.
Provider API keys are encrypted with AES-256-GCM before storage. All data in transit uses TLS 1.2+. We follow DPDP Act 2023 (India) obligations for personal data protection.
You have the right to access, correct, export, or delete your personal data. Contact privacy@tokentrim.in and we will respond within 30 days.
We will notify you of material changes by email or a prominent notice in the dashboard at least 14 days before they take effect.
Dhisattva AI Pvt Ltd, India · ceo@tokentrim.in