TO
TokenTrim

Privacy Policy

Effective: 1 May 2026  ·  Dhisattva AI Pvt Ltd (TokenTrim)

1. What we collect

When you sign in we collect your email address and OAuth profile information to create and manage your account. When you route API requests through TokenTrim we collect request metadata: model name, token counts, latency, and a short redacted preview of your prompt (personally identifiable information is stripped before storage).

We do not store your full prompt text or response text. Provider API keys you submit are stored encrypted (AES-256-GCM) at rest.

2. How we use it

  • To authenticate you and route your API requests.
  • To display your usage analytics in the dashboard.
  • To enforce budget limits and send usage alerts you configure.
  • To improve the proxy optimization pipeline (aggregate, never individual).

3. Data sharing

We do not sell, rent, or share your personal data with third parties except as required to operate the service (Turso for database hosting, Google Cloud Run for compute, Resend for transactional email) or as required by law. All sub-processors are bound by data processing agreements.

4. Data retention

Account data is retained while your account is active. Usage logs are retained for 90 days. You may request deletion of your data at any time by emailing privacy@tokentrim.in.

5. Security

Provider API keys are encrypted with AES-256-GCM before storage. All data in transit uses TLS 1.2+. We follow DPDP Act 2023 (India) obligations for personal data protection.

6. Your rights

You have the right to access, correct, export, or delete your personal data. Contact privacy@tokentrim.in and we will respond within 30 days.

7. Changes

We will notify you of material changes by email or a prominent notice in the dashboard at least 14 days before they take effect.

8. Contact

Dhisattva AI Pvt Ltd, India · ceo@tokentrim.in