OceanToken

Privacy Policy

Last updated 21 September 2026

OceanToken is an API gateway for large language models, operated by NextForm AI ("we", "us"). This policy explains what we collect when you use it, why, who else sees it, and what you can ask us to do about it. It covers the OceanToken web console and the OceanToken API.

What we collect

CategoryWhat it isWhy we hold it
Account Your email address, a hashed password, your organisation and team membership, and your API key names. To let you sign in and to decide what you are allowed to reach.
Request content The prompts you send and the responses you receive, including uploaded files and generated images, audio and video. To show you your own conversation history, to let multi-turn requests continue from a previous response, and to investigate failures and billing disputes.
Usage records Per-request model name, token counts, cost, timing, cache status, and the IP address the request came from. To bill you accurately, to show your usage, and to detect abuse.
Payment An identifier issued by our payment processor, and your top-up history. To take payment and keep your balance correct. We never see or store your card number.

Please read this part

Because we store the text of your requests and responses, do not send material you are not willing to have stored. This matters most for regulated personal data, credentials, and anything under a confidentiality obligation you cannot extend to us and to whoever serves the model you choose.

Before a request reaches a model we automatically mask high-severity personal data we can detect, and we redact strings that look like API keys or secrets. Automated detection is not perfect and is not a substitute for your own judgement about what to send.

Who else processes it

We do not host the models ourselves, so a request leaves our systems to be answered. We rely on third parties in these categories:

Which company serves a given model changes as we add capacity and capability, so naming them here would go out of date. For the current list of the third parties we use, write to support@oceantoken.ai and we will send it.

We do not sell your data, and we do not use your request content to train models.

Where it is held

Our production systems run in Singapore. Models are served from several regions, so a request you send may be processed outside Singapore depending on which model you choose.

How long we keep it

Request content is deleted after one year. A daily job empties the stored prompt and response from any request older than 365 days. Saved conversations you have not opened in a year are deleted on the same schedule.

The billing record for a request - its model, token counts, cost and timestamp - is kept for as long as your account is open, because your balance and your invoices are built from it. Emptying the content does not change it.

When you close your account we stop processing for you. Write to us and we will delete the stored records associated with it.

What you can ask for

Write to support@oceantoken.ai. Depending on where you live you may also have the right to complain to a data protection authority.

Cookies

We set one cookie, which holds your signed-in session. It is not used for advertising and we do not run third-party analytics or tracking on the console.

Security

Passwords are stored hashed, never in readable form. Our database is not reachable from the public internet. API keys are stored hashed, which is why a key is shown to you once and cannot be shown again.

Changes

If we change this policy we update the date at the top. If a change materially affects what we do with your data, we will tell account holders by email before it takes effect.