Privacy Policy
Effective July 28, 2026
- We receive the text you explicitly ask about — nothing is captured in the background.
- We do not store that text. Attribution is computed and the content is discarded when the response is returned.
- We keep usage records for billing. They count tokens; they do not contain your content.
- We do not sell your data, use it for advertising, or train models on it.
Who and what this covers
This policy explains how TokenPath handles data across the TokenPath API, the tokenpath.ai website and customer platform, and the TokenPath browser extension (“Chat with Attribution”). TokenPath provides token-level attribution: it maps spans of a generated answer back to the source spans that produced them.
If you use the API directly, you are the controller of the documents you send and are responsible for the notices and permissions your own users require. TokenPath processes that content to answer the request you made.
What the browser extension sends us
The extension reads a page only in response to something you do: selecting text and choosing TokenPath from the context menu, opening the side panel, or pressing an action such as Summarize or Simplify. Its content script has no network access of its own — it cannot send anything anywhere. It waits to be asked for text and returns it to the panel, which is the only component that talks to our API.
The text you selected, or the readable text of the page or PDF you asked about. PDF text is extracted locally in your browser and sent as plain text — we never receive the PDF file itself. Long documents are truncated before sending.
The scheme and hostname only — for example https://example.com. This tells the model what it is reading. The rest of the address, including the path, query string, and fragment, is never sent. Local and non-web pages are described only as “the current webpage”.
Your typed question, plus earlier messages in that conversation so follow-ups make sense. Earlier turns are truncated to fit the request.
Attribution is a second call that needs the answer, the question, and the source text together in order to map answer spans back to source spans.
Web pages and PDFs can contain personal information and private correspondence. Please treat the pages you send the same way you would treat pasting them into any hosted AI tool, and avoid sending content you are not permitted to share.
What the extension never sends
- Your browsing history, or the pages you visit while the panel is closed
- Full URLs — the path, query string, and fragment never leave your browser
- Cookies, credentials, passwords, autofill data, or form fields
- Page content from tabs you did not ask about
- Anything at all until you select text, open the panel, or choose a TokenPath action
The extension requests access to all sites because you may want to ask about any page you are reading. That permission is what lets it read a page on request; it is not used to observe your browsing.
API keys and account data
Your TokenPath API key is stored in your browser's local extension storage. It is sent only to TokenPath API hosts, as an HTTP Authorization header, over HTTPS. It is never sent to any other site, never included in page content, and never written to our logs in raw form. Removing the key in the extension, or uninstalling the extension, deletes it from your browser. You can revoke a key at any time from the customer platform, which immediately stops it from working.
If you hold a TokenPath account, we store your email address, your API key records, your token balance, and your purchase history so we can authenticate you and bill correctly.
How long we keep things
Request content — the page or PDF text, the site origin, your questions, and the answers — is processed to serve the request and is not written to a database. It exists in server memory for the life of the request and is discarded afterward. The extension does not use our document-storage feature, so nothing you ask about is saved to an account.
Usage records are kept indefinitely as billing history. Each record contains a customer ID, an API key ID, request and billing IDs, token counts, cost, and a status — and no part of your content.
Operational logs record the request path, HTTP status, latency, customer and key IDs, and billing decisions. They are retained for 30 days and then deleted automatically. Document text, questions, and answers are not logged, and raw API keys are not logged.
Conversation historyexists only in the open side panel's memory. Closing the panel, starting a new capture, or removing the extension discards it. TokenPath holds no stored copy.
Who else processes it
We use a small number of vendors to run the service. Generating an answer necessarily involves sending the page text and your question to a model provider; attribution itself runs on infrastructure we operate.
| Vendor | Purpose | Data involved |
|---|---|---|
| OpenRouter | Routes the generation request to the answering model | Page text, site origin, questions, chat turns |
| Google (Gemini) | Generates the answer, reached through OpenRouter | Page text, site origin, questions, chat turns |
| Amazon Web Services | Runs the API, the account database, and the log store (us-west-2) | Request content in transit and memory; usage metadata at rest |
| Cloudflare | Fronts and protects the API endpoint | Request content in transit; connection metadata |
| Vercel | Hosts tokenpath.ai and the customer platform | Website and dashboard traffic; not extension requests |
| Clerk | Signs you in to your TokenPath account | Email address and authentication data |
| Dodo Payments | Merchant of record for credit purchases | Billing and payment details |
Content passed to a model provider is handled under that provider's terms and privacy policy, linked above. TokenPath does not authorize them to use your content to train their models, but we cannot make guarantees on their behalf — if that distinction matters for your use case, contact us before sending sensitive material.
What we don't do
- We do not sell or rent your data, and we do not transfer it to third parties except to the vendors listed above.
- We do not use your content for advertising, profiling, or any purpose unrelated to answering your request.
- We do not train models on your documents, questions, or answers.
- We do not use your data to determine creditworthiness or for lending.
Your choices and deletion
Because request content is never stored, there is nothing on our servers to delete for a past question — it is already gone. What you can act on:
- Stop sending data at any time by closing the panel, removing your API key, or uninstalling the extension.
- Revoke or rotate API keys from the customer platform.
- Clear local conversation history from the side panel.
- Request access to, correction of, or deletion of your account data — email address, keys, and usage history — by writing to us. Deleting usage history may be limited where we must keep records for tax and accounting.
Depending on where you live, you may have additional rights over your personal data, including the right to object to processing or to lodge a complaint with your data protection authority. Write to us and we will honor them.
Security and transfers
All traffic to the TokenPath API is encrypted in transit over HTTPS. API keys are stored as hashes, and access to production systems is restricted to the people who operate them.
Our servers and databases run in the United States (AWS us-west-2), and our model providers may process requests in other countries. If you use TokenPath from outside the United States, your data will be transferred there.
Children
TokenPath is a developer tool and is not directed to children under 13, and we do not knowingly collect their personal information.
Changes to this policy
If we change how we handle data, we will update this page and move the effective date above. Material changes to what we collect or how long we keep it will be announced to account holders by email.
Contact
Questions about this policy, or a request about your data, go to support@tokenpath.ai. For enterprise agreements or a DPA, write to sales@tokenpath.ai.