Privacy Policy

This Privacy Policy explains how Token Market ("we", "us", or "our") collects, uses, discloses, retains, and protects personal data across its website, console, API gateway, multi-modal model routing (including text, image, video, and audio generation), billing, and support workflows. Token Market is operated by Prosperous AI Ltd.

Last updated:July 27, 2026

About this Policy

Prosperous AI Ltd. operates Token Market as a developer and enterprise AI gateway and orchestrator. This Privacy Policy applies to personal data processed through our website, user console, API endpoints, workspace management tools, documentation, and support channels that link to this Policy.

This Policy is designed to comply with applicable data protection laws, including the Personal Data (Privacy) Ordinance (Cap. 486 of the Laws of Hong Kong) ("PDPO"). Where applicable, Token Market acts as a "data user" (or "data controller") regarding account, workspace, and billing information, and as a "data processor" when routing API content on behalf of enterprise workspace clients.

Personal data we collect

The exact categories of personal data we collect depend on how you interact with the service, your workspace settings, and the specific AI models or upstream providers you select.

A. Information you provide directly

  • Account and Authentication Data: Email address, phone number, display name, user identifiers, password/passkey hashes, verification codes, and invite/referral codes.
  • Workspace and Organization Data: Company/organization name, Hong Kong Business Registration (BR) or Company Registration numbers (or local equivalents), workspace membership, administrator configurations, roles, permissions, and policy settings.
  • API and Security Controls: API token names, token secret hashes, status, permitted model routes, IP allowlists, and usage quota thresholds.
  • Billing and Transaction Records: Payment gateway tokens, transaction history, workspace Token/Credit balances, invoices, tax records, and communications regarding recharges. (Note: We do not store raw credit card numbers; payment processing is handled by PCI-DSS compliant payment gateways).
  • Prompts, Files, and Multi-modal Content ("Inputs and Outputs"): Text prompts, code, documents, images, audio files, video clips, embeddings, and generated responses submitted to or received from our API gateway.

B. Information collected automatically

  • Technical Request Metadata: API endpoint accessed, unique Request ID, requested model, routed provider, timestamps, input/output token counts, execution latency, HTTP status codes, error logs, and routing decisions.
  • Device and Network Diagnostics: IP addresses, approximate geographic location, browser/device characteristics, operating system, language preferences, referrer URLs, and network connection types.
  • Security Audit Logs: Account login attempts, password resets, API key creation/revocation, workspace setting modifications, and suspicious abuse/fraud detection telemetry.

How we use personal data

We process personal data for the following specific business purposes:

  • Service Provisioning and Routing: Authenticating users, enforcing workspace permissions, executing API gateway requests, routing multi-modal tasks to selected model providers, and delivering generated Outputs.
  • Billing and Accounting: Measuring token usage, deducting pre-paid Credits, maintaining transaction ledgers, issuing invoices, and fulfilling financial record-keeping under Hong Kong law.
  • Security and Service Integrity: Monitoring system reliability, preventing unauthorized API access, detecting fraud, mitigating DDoS attacks, enforcing Acceptable Use Policies, and protecting our infrastructure.
  • Operational Communications: Sending critical service alerts, API deprecation notices, billing notifications, security advisories, and responding to technical support inquiries.
  • Legal and Regulatory Compliance: Complying with statutory obligations, responding to lawful court orders, enforcing our Terms of Service, and resolving legal disputes.

Strict "No Model Training" commitment on API Content

TOKEN MARKET DOES NOT USE YOUR INPUTS OR OUTPUTS (INCLUDING TEXT PROMPTS, CODE, IMAGES, AUDIO, OR VIDEOS SUBMITTED VIA OUR API) TO TRAIN, FINE-TUNE, OR IMPROVE OUR OWN FOUNDATIONAL MODELS OR ANY THIRD-PARTY MODELS.

Your Inputs and Outputs are processed strictly to execute your requested API calls and provide the routing service.

Upstream Provider Data Practices

When you invoke an API request, your Inputs are transmitted to the upstream model provider (e.g., OpenAI, Anthropic, Midjourney, Kling, etc.) selected by you or determined by your automated routing configuration.

  • Upstream providers process your data in accordance with their independent terms and privacy commitments.
  • Certain model routes offer Zero Data Retention (ZDR) or "No-Training" API endpoints. Where available, these options are clearly indicated in our product documentation.
  • You are responsible for reviewing the data retention and privacy policies of your selected upstream model providers prior to routing sensitive data.

Biometric data, face data, and sensitive media

Multi-modal generation features (such as Image-to-Image, Face-Swap, or Video Generation) may involve processing photographs, video footage, or audio containing human faces, voices, or potential biometric identifiers.

  • User Responsibility: You represent and warrant that you have obtained all necessary prior explicit consents, licenses, and legal authorizations from any individuals whose likeness, face, voice, or personal data is included in your Inputs.
  • Prohibition on Unauthorized PII: You must not submit unencrypted, non-anonymized sensitive personal data (such as national identity card numbers, government IDs, unredacted health records, or biometric templates) into the API unless your workspace has executed a dedicated Enterprise Agreement with appropriate security safeguards.

Cookies and technical tracking

We use essential cookies, local storage, and session tokens on our website and user console solely to maintain signed-in sessions, remember workspace preferences, secure user accounts, and prevent Cross-Site Request Forgery (CSRF).

We do not use third-party advertising cookies or sell user browsing data. Disabling essential cookies may impair the functionality of the Token Market console.

Sharing and disclosure of personal data

We do not sell personal data. We may share personal data only with the following categories of recipients:

  • Selected Upstream AI Model Providers: To the extent necessary to fulfill your specific API request (e.g., sending a text prompt to an LLM provider or an image file to a video generation provider).
  • Core Infrastructure and Cloud Sub-processors: PCI-DSS payment gateways, cloud hosting providers, CDN/DDoS protection services, error monitoring tools, and transactional email providers operating under strict data processing agreements.
  • Workspace Administrators: Primary administrators of an enterprise workspace can view audit logs, API usage metrics, billing history, and member activities within that workspace.
  • Professional Advisers and Regulatory Authorities: External auditors, legal counsel, insurers, or Hong Kong law enforcement/government agencies when required by mandatory legal processes, subpoena, or court order.

Data retention and deletion

We retain personal data only for as long as necessary to fulfill the purposes set out in this Policy:

  • Account and Workspace Data: Retained for the active lifecycle of your account plus a reasonable period thereafter to facilitate account recovery.
  • API Processing Metadata & Logs: Technical request logs (excluding full prompt payloads where zero-retention is enabled) are retained for up to ninety (90) days for debugging, security auditing, and rate-limit enforcement.
  • Billing and Transaction Records: Retained for a minimum of seven (7) years following the end of the relevant financial year, in compliance with Hong Kong tax and accounting legislation.
  • Pre-paid Tokens Data: Balance records are maintained for twelve (12) months until token expiration or consumption.

Upon expiration of the retention period, personal data will be securely deleted, overwritten, or permanently anonymized.

Your privacy rights (Hong Kong PDPO & Global Standards)

Under the Hong Kong PDPO (and subject to applicable data protection laws in other jurisdictions), you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request the correction of inaccurate or incomplete personal data.
  • Erasure: Request the deletion of your personal data, subject to statutory retention exceptions (such as mandatory accounting requirements).
  • Opt-out: Object to receiving non-essential operational or promotional communications.

To exercise your rights, please submit a written request to our Privacy Team at the contact channel specified below. We may require identity verification before processing your request.

Security measures

We implement appropriate technical and organizational safeguards to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures include TLS/SSL encryption in transit, AES-256 encryption at rest for sensitive credentials, strict role-based access controls (RBAC), and automated threat detection.

However, no method of transmission over the Internet is 100% secure. You remain responsible for safeguarding your account passwords, passkeys, and API tokens.

International data transfers

Token Market is headquartered in Hong Kong. To deliver our global routing services, your personal data and API request content may be transferred to, stored, or processed in servers located in Hong Kong, the United States, Singapore, the European Union, or other regions where our cloud infrastructure or upstream model providers operate.

Where cross-border data transfers occur, we ensure appropriate safeguards are implemented in accordance with Data Protection Principle 3 of the Hong Kong PDPO and applicable cross-border data transfer mechanisms.

Changes, governing law, and contact

  • Governing Law: This Privacy Policy shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region.
  • Language Precedence: This Privacy Policy may be translated into Chinese or other languages for convenience. In the event of any inconsistency or ambiguity between the English version and any translated version, the English version shall prevail.
  • Updates: We may update this Policy from time to time. The revised date at the top of this Policy indicates when changes take effect.
  • Contact Channel: If you have questions or privacy-related requests, please contact our Data Protection Officer through the designated support ticket channel in the Token Market console or via email at contact@tokensmarket.ai.