EastToken

EASTTOKEN / POLICIES

Privacy notice

Understand what is processed, who receives it, and how to ask for help. A global audience does not mean identical privacy rules in every country.

Last updated: 2026-09-19

This public website

This website provides information and email contact links. It does not accept account registrations, payments, API prompts or uploaded files. It contains no advertising or analytics scripts. When hosted on Cloudflare Pages, Cloudflare processes connection and request information to deliver and protect the website. Email enquiries are handled through Zoho Mail. The account, API and payment sections below describe those features when used, not additional data collected by browsing these pages.

1. Responsibility and contact

EastToken is operated by an individual based in China who uses the public-facing name TaoOu. Privacy contact: support@easttokenapi.com. We determine the purposes and means of processing account, billing and security data for our service. Processing personal data submitted on behalf of a business may also require separate data-processing terms.

2. Data and purposes

Account data includes email, password hashes, security settings and authentication records. Usage and billing records may include account and key identifiers, model, timestamps, token counts, request identifiers, charges and balance changes. These support access, billing, fraud prevention and troubleshooting. Connection information such as IP addresses is also processed for access control and security checks.

To answer your requests, submitted messages, context and attachments where supported are transmitted to the API service provider for your selected route and may be forwarded to the relevant model service provider. Responses pass back through the same service chain. Error diagnostics may contain response excerpts. This is not a promise of zero retention or exclusion from model training across all providers; avoid submitting secrets or unnecessary sensitive data.

Support messages and attachments are used to resolve requests. Transactional email involves recipient addresses, message content and delivery status; provider settings may also collect open and click events. Do not email passwords, API keys, payment card details or complete private prompts.

3. Purposes and legal grounds

Where GDPR or UK GDPR applies, we rely on contract necessity for required account and API processing, legitimate interests where permitted for proportionate security and fraud prevention, and legal obligations for legally required records. Optional marketing and non-essential tracking require their own applicable legal basis, including consent where required. Acceptance of service terms is not blanket consent to unrelated processing.

Your email and the data needed to fulfill a request are required for the corresponding features. Without them, those features may not be available. Account emails and security notices are service communications, not an automatic subscription to marketing.

4. Recipients and international processing

Zoho Mail handles support correspondence, and Brevo sends transactional email. API and model service providers process the content needed to answer requests. Hosting and infrastructure providers support storage and delivery where used. For a payment, the seller and payment providers identified at checkout and on the receipt process transaction information under their applicable notices.

We operate from China. Depending on the route and service provider, data may also be processed in other countries or regions, whose privacy protections may differ from those where you live. We do not offer a universal data-residency, transfer-safeguard or provider-retention guarantee. If your workload requires specified processing locations, contractual safeguards or a data processing agreement, contact us before submitting personal data; do not use a route that cannot meet those requirements.

5. Storage and retention

The browser stores login/session information and preferences such as language and theme in local storage. Clearing browser storage signs you out but does not delete server records. Some enabled security integrations can introduce additional storage or network requests.

Retention is assessed by data category and purpose: account records support the account relationship; usage and billing records support settlement, accounting and disputes; support and diagnostic records support issue resolution and security. Applicable record-keeping duties and unresolved claims may require continued retention. You may request account closure or deletion through support; deletion is not necessarily immediate or simultaneous across backups and independent service providers. We do not promise a single fixed retention period for every model route.

6. Requests and regional rights

Contact support to request access, correction, deletion or information about processing. Depending on applicable law, you may also have rights to portability, restriction, objection, withdrawal of consent and complaint to a supervisory authority. We may need proportionate identity verification; do not send identity documents unless a secure, necessary process is agreed.

Applicable EU/UK requests are generally answered within one month, subject to lawful extensions; other regions have their own rules. California privacy rights depend on statutory applicability, not simply visiting this site. No blanket waiver of privacy rights is required. The service is not intended for children.

support@easttokenapi.com