Skip to content
apiToken.sale
How it worksIntegrationsModelsGuidesPricingDocs
Log inSign up
Log inSign up
Legal information

Privacy Policy

How apiToken.sale collects, uses, shares, and protects information when you use the website, dashboard, payments, and API gateway.

Privacy PolicyUser AgreementSupportPrices & tariffs
Effective and last updated: July 16, 2026Privacy requests are handled at apitokensale@gmail.com.apitokensale@gmail.com

1. Scope and operator

This Privacy Policy applies to apiToken.sale, its website, dashboard, authentication flows, payment flows, support, and API gateway (together, the “Service”). The Service operator is apiToken.sale. The official privacy and support contact is apitokensale@gmail.com.

By using the Service, you acknowledge this Policy. Where consent is required by applicable law, we will request it separately.

2. Information we collect

  • Account information: email address, account identifier, verification status, customer type, and account settings.
  • Authentication information: a securely hashed password for password accounts, or identifiers and profile data returned by Google or GitHub when you choose OAuth sign-in. We do not receive your Google or GitHub password.
  • Technical and security information: IP address, browser and device details, timestamps, session identifiers, security events, and diagnostic logs.
  • Website analytics: page path without query strings or fragments, timestamp, referrer, approximate location, device type, operating system, browser, and interaction data such as clicks, link activity, and session replay. We receive aggregated traffic statistics through Vercel Web Analytics and behavior analytics through Yandex Metrica, and do not intentionally link them to your account identity.
  • API and billing metadata: API key identifier, selected model, request time, token and usage totals, official API cost, discount, balance charge, ledger reference, and request status.
  • Payment information: top-up amount, currency, payment status, provider transaction identifiers, and webhook records. Full payment-card credentials are handled by the payment provider and are not stored by apiToken.sale.
  • Support information: messages, attachments, account or order identifiers, and other information you voluntarily send to support.

3. API request and response content

Prompt, message, tool, and response content necessarily passes through our infrastructure so the Service can route your request to the selected upstream model provider and return the result. We do not use this content for advertising or sell it.

Operational records are designed around usage and billing metadata rather than prompt content. Content may still be processed temporarily in memory, transport buffers, security systems, or error diagnostics, and upstream model providers may process or retain it under their own terms. Do not submit secrets, regulated data, or personal data unless you have a lawful basis and appropriate safeguards.

4. Why we use information

  • Create and secure accounts, authenticate sessions, and provide OAuth sign-in.
  • Route API requests, calculate usage, apply the active discount, maintain balances, and show the request ledger.
  • Create and reconcile payments, prevent duplicate credits, process refund requests, and maintain financial records.
  • Detect abuse, fraud, compromised keys, attacks, and violations of the User Agreement.
  • Provide support, send essential service notices, improve reliability, and comply with legal obligations.

5. Legal grounds

Depending on applicable law, we process information to perform the contract with you, comply with legal and financial obligations, protect our legitimate interests in operating and securing the Service, and act on consent where consent is the appropriate basis. You may withdraw consent without affecting processing already performed, but some features cannot work without required data.

6. When information is shared

We do not sell personal information. We share only what is reasonably necessary with infrastructure, hosting and analytics providers, authentication providers you select, payment providers shown at checkout, upstream model/API providers, security and monitoring vendors, professional advisers, and public authorities when lawfully required.

A provider may act in another country and under its own privacy terms. We select providers for a defined operational purpose and limit access where reasonably possible.

7. Cookies and local storage

The Service uses an essential secure, HttpOnly session cookie to keep you signed in. Language, theme, referral attribution, and anonymous first-use milestone markers may be stored in your browser's local storage. These technologies support the requested functionality and product measurement and are not used by us to sell advertising profiles.

We use Vercel Web Analytics for anonymous, aggregated page-view and product-funnel statistics, such as completed login, API-key creation, checkout, and first-use milestones. Event properties use coarse categories and exclude account identifiers, email addresses, secrets, raw referral or promo codes, and exact payment amounts. Vercel Web Analytics does not use third-party analytics cookies. apiToken.sale removes sensitive query parameters and URL fragments before analytics events are sent.

We also use Yandex Metrica for page-view and interaction analytics, including click maps, outbound-link tracking, and Session Replay. Yandex Metrica may use cookies and browser storage to distinguish visits. apiToken.sale removes query strings and URL fragments from page-view URLs, masks authentication and dashboard content from Session Replay, and prevents API-key fields and examples from being recorded.

8. Retention

We retain account information while the account is active and for a reasonable period afterward. Billing, payment, ledger, fraud-prevention, and security records may be kept longer where needed for accounting, dispute resolution, enforcement, backup integrity, or law. Support correspondence is retained as needed to resolve and document the request.

When information is no longer required, we delete or anonymize it through normal operational cycles. Backup copies may remain until the relevant backup expires.

9. Security

We use access controls, encrypted transport, secret hashing, restricted administrative access, and monitoring appropriate to the Service. No system is completely secure. You must keep your password, session, and API keys confidential and revoke a key immediately if you suspect exposure.

10. Your choices and rights

Subject to applicable law, you may request access, correction, export, restriction, objection, or deletion of your personal information by emailing apitokensale@gmail.com. We may need to verify your identity. Some records cannot be deleted immediately where retention is legally required or necessary to resolve payments, fraud, or disputes.

You may disconnect OAuth access through the relevant provider and may stop using the Service at any time. You may also complain to the data-protection authority available in your jurisdiction.

11. Age and third-party links

The Service is not directed to children. You must have legal capacity to enter this agreement and, where required, be at least 18 years old. Third-party sites and services linked from the Service are governed by their own policies.

12. Changes and contact

We may update this Policy when the Service, providers, or legal requirements change. The current version and effective date will remain published on this page. Questions and privacy requests: apitokensale@gmail.com.

apiToken.sale

Claude, GPT and Gemini API access platform for developers.

Product

PlansModelsPricingHow billing works

Developers

DocumentationQuickstartAPI referenceGitHub

Integrations

Claude CodeCodex CLICursoropencodeAll integrations

Support

SupportGuidesError codesTool errorsAboutContactsChangelogStatusapitokensale@gmail.com

Legal

User AgreementPrivacy PolicyPricing
© 2026 apiToken.sale. All rights reserved.GuidesPrivacy PolicyUser AgreementSupportPricing

apiToken.sale is an independent platform and is not affiliated with or endorsed by Anthropic, PBC or OpenAI.

apiToken.sale