This Privacy Policy explains what data noTOKEN.cloud (operated by JCFI, LLC) collects, why, and what you can do about it. The short version: your endpoint traffic is not stored — zero data retention — and we keep only the minimum needed to run your account.
Effective date: August 28, 2026
JCFI, LLC — 364 E Main St, Ste 1001, Middletown, DE 19709, USA. Email: tnt@tnt.chat. We are the data controller for the personal data described in this policy.
Your prompts, outputs, files, and all traffic to your endpoint are processed in memory on your dedicated server and are not stored by us. After inference completes, that content is gone. We do not use it to train models, for analytics, or for any other purpose. This is a core design property of the service, not an opt-in setting.
To run your account we store: your email address; a salted hash of your password (never the password itself); your credit balance and purchase history; per-request usage totals (token counts and cost, not content); your API key metadata (prefix, label, creation date, last-used date); your server settings (idle auto-stop, auto-refill threshold); and session metadata for AI support conversations (who, when, which channel — not the message content).
We store this data to: authenticate you; bill you accurately (prepaid credits, per-second metering); operate your server (settings, auto-stop, auto-refill); provide support; and comply with legal obligations (e.g., tax records). Our legal basis is performance of the contract with you and, where required, your consent.
Payments are processed by Stripe. We never see or store your full card number. Stripe stores payment details on your behalf under its own privacy policy; when you enable auto-refill, Stripe stores your card (as a payment method) and charges it off-session when your balance drops below your threshold. You can cancel auto-refill at any time from the dashboard.
The AI support assistant answers product questions. Your messages are sent to the support model to generate a reply and are not stored by us; only session metadata (account, channel, timestamp) is kept. If you share personal data in a support message, it is processed to answer your question and not retained.
We use one session cookie for authentication and one local-storage entry for your language preference. We do not use advertising cookies, analytics trackers, or third-party tracking pixels. No data is sold or shared for advertising.
We share data only with: Stripe (payments); the infrastructure providers that host the service (operational); and authorities when required by law. We do not sell personal data. We do not share your endpoint content with anyone — it is not stored.
Account and billing data is kept while your account is active and for a period afterward as required for tax and legal compliance. Usage totals are kept for the life of the account. You can request deletion of your account and data at any time (see below); we will delete or anonymize it, except records we are legally required to keep.
Depending on your jurisdiction (including GDPR and CCPA/CPRA rights), you may: access your personal data; correct it; request deletion; object to processing; request portability; and withdraw consent. To exercise any right, email tnt@tnt.chat. We respond within 30 days. If you are in the EU and believe we have not handled your data correctly, you have the right to lodge a complaint with your local supervisory authority.
The service is operated from the United States. If you are in the EU, UK, or another jurisdiction with data-transfer restrictions, your account data (not endpoint content) is processed in the US under the legal mechanisms available to us. Endpoint content is not stored, so no transfer of that content occurs.
All traffic is encrypted in transit (TLS). Passwords are stored as salted hashes. Servers are dedicated per account, so your workload is isolated from other customers. No internet transmission is fully secure; if you believe your account has been compromised, contact us immediately.
The service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy. Material changes will be announced on the site and, where possible, by email. Your continued use after the effective date constitutes acceptance.