Privacy at tokenmask.ai

What we ask for, what we process, and who else is involved.

Updated September 9, 2026

Signup without personal details

You do not need to submit a name, email, phone number or postal address to create an account. We generate an account ID and secret key. The key gives access to your balance and must be kept safe. No email-based account recovery is available.

How AI requests work

Your prompts, supplied conversation context and requested model settings pass through our Cloudflare-hosted service to OpenRouter and the selected model provider. Those services receive the content needed to answer. Our normal completion path does not write a prompt or response history to our account database. This is not a guarantee about every provider's retention or processing. Content you include can identify you even when signup does not.

Zero Data Retention routing

Our model catalog includes eligible endpoints that OpenRouter designates Zero Data Retention (ZDR). Each request explicitly requires a ZDR route. This relies on OpenRouter’s endpoint policy information; we cannot independently audit provider behavior. OpenRouter’s definition permits implicit in-memory prompt caching. ZDR routing does not erase our account, payment or support records and is not a guarantee of anonymity.

Account and billing records

We retain account IDs, access keys, balances, invoice and payment identifiers, credited amounts, usage-cost and reconciliation records, and promo redemption records to operate accounts and keep billing correct. These records can link activity within an account. Credit balances and operational records are not anonymous merely because no name is required.

Lightning payments

Strike creates and processes our Lightning payment requests and reports completed payments so we can credit your dollar-denominated balance. Your wallet and Strike have their own data handling and transaction records. Lightning payment does not guarantee untraceability. We do not ask you to enter credit-card details in this application.

Network and operational data

Cloudflare processes network requests to host and protect the service. Account creation uses an IP-derived hash and timestamp for abuse prevention, with daily cleanup of records older than 24 hours. Operational logs and reconciliation records may include timestamps, account or request identifiers, error categories and costs. They are separate from model conversation history. A hash of an IP address is not a promise that the address cannot be inferred.

Support conversations

Messages you send to support are stored with account IDs and timestamps so we can respond. Please avoid including private keys, wallet recovery phrases or unnecessary personal information. Support records are different from AI model conversations.

Browser storage and third parties

Account cookies maintain your session. Your browser may also hold conversation state and copies you save. OpenRouter, selected model providers, Strike and Cloudflare process data for their respective parts of the service. This application does not use advertising pixels or sell account data. Their policies govern their own processing; we cannot independently guarantee every upstream provider's behavior.

Retention and questions

Account and financial records are retained for account operation, reconciliation and applicable recordkeeping needs. Support and operational records may persist; we do not currently promise a fixed automatic deletion period for those categories. To ask about your account or request deletion of eligible records, use support in your dashboard. Records needed for financial or security purposes may need to be retained.

Routing details: OpenRouter ZDR definition. Service policies: OpenRouter, Strike, and Cloudflare. Check your selected model provider's policy as well.