What we store, who sees it, and for how long.
Effective 2026-09-27.
Who we are
The service is operated by TokenOS, from the United States. These terms and this notice are governed by the law of the United States, and its courts have jurisdiction. Nothing here takes away a right you have under the consumer or data-protection law of the country or state you live in. Privacy questions go to TokenOSAI@gmail.com.
What we store about your account
- · Your email address, and a normalised form of it used only to stop duplicate signups.
- · A hash of your password, never the password.
- · Your Solana wallet address if you link one, and the time it last changed (used for the withdrawal holding period).
- · Your roles (buyer, operator, both) and whether the account is disabled.
- · API keys you create, with their permissions, the last four characters for display, and last-used time. Every key is stored only as a hash; we cannot read a key back, and neither can anyone with a copy of the database. Keys minted before 13 August 2026 were stored readably until 4 September 2026, when the remaining ones were converted in a single pass.
- · Your identity-verification status, the date it was approved, and whether a payout hold is in place.
- · If you choose to give it, the legal name, taxpayer identification number, address and jurisdiction you enter for the year-end earnings export. The number is shown back to you masked to its last four digits.
What we store when you rent
- · Every compute request: GPU class, count, duration, price, payment source, status, and timestamps.
- · The SSH public key you supply for a rental, and the session token we issue alongside it. Access to a rented machine is by public key only, so that token is not itself a way in. The token is cleared when a rental ends, whether it ran to completion, was terminated, or was cancelled before it ever started, and it is withheld from you once its own expiry has passed.
- · Your balance ledger: every top-up, spend, refund and withdrawal, with the on-chain transaction signature where one exists.
- · Metering records for inference calls made with your API keys: model, token counts, cost and latency. Prompts and completions are not stored in the database. A sampled fraction of calls is shadow-duplicated to other operators to verify their answers; for those, the request body is held transiently in a queue with a short expiry, and only hashes of the outputs are kept.
- · Ratings you leave for operators. Published ratings show a redacted label, never your email or full wallet.
What we store when you operate
- · Your nodes: declared and benchmarked GPU class, region, heartbeat times, and the software version reporting them.
- · Your operator profile (display name, slug), earnings, payouts and payout destination. If you never set a display name, it defaults to the part of your email address before the @, and that is what is published.
- · Public listing is on by default when you onboard a node, and you can turn it off in settings. Turning it off removes you from the operator catalog, the public search, your operator profile and the bulk listings.json and listings.csv feeds, which all read that one setting.
Technical data
- · IP addresses are used for two things. For rate limiting, the counters live in a short-lived cache and expire with their window. For security attribution on certain account actions, we record the action with the IP address and browser user-agent it came from in an audit log, and that record is retained.
- · The portal reports client-side errors to Sentry, tagged with the release and environment. Error reports can include the page and the request that failed; they are not used to profile you.
- · Sign-in tokens are kept in your browser's local storage for the portal only. We do not set tracking cookies and do not use advertising or analytics trackers.
Who processes it
- · Hosting: the API and database run on Render in the United States (Oregon); the marketplace and portal are served by Vercel. If you are outside the United States, using the service involves your data being stored and processed there.
- · Card payments: Stripe receives your card details directly; we store the payment reference, never the card.
- · USDC deposits and withdrawals settle on the public Solana blockchain, where transaction amounts and addresses are public by nature.
- · Identity verification and wallet screening: when an identity check is required, you complete it on Didit's hosted page, so Didit receives the document and liveness data directly; we never receive or store the images. We keep the outcome of each verification session (approved, declined, in review or expired), the country code your document was issued in and the country your connection came from as Didit reported them, the date verification was approved, and whether an admin review is pending. When you link a Solana payout wallet, and again before a payout when the last screen is missing or stale, Didit screens the wallet address and we keep each result. Any hold we place on payouts as a result is stored with its date and reason, and you are told only that a manual review is needed.
- · Transactional email (verification, withdrawal confirmation, rental notices, identity and payout notices, and a weekly operator summary you can turn off) is sent through our email provider.
- · Operators receive the SSH public key you supply and serve your workload; they do not receive your email, wallet or ledger.
How long
Account and ledger records are kept for as long as the account exists and for the period after closure needed to settle balances and meet our record-keeping obligations. Rental session tokens are revoked at rental end. Market rate history is pruned after 90 days. Rate-limit counters expire within minutes. Security audit records are retained.
Your choices
In the portal you can change your email, password and linked wallet, revoke API keys, and turn off public listing of your operator profile. Account closure and deletion are handled by hand rather than by a button: write to us at the contact address above and we will withdraw your remaining balance under the Terms of service, disable the account, and delete what is not required to keep the ledger and our records consistent. We will tell you what is kept and why.