Privacy Policy
Last updated: 21 August 2026
IAM-Token (“I amToken”, “we”, “us”) operates an AI routing gateway: we route your requests to third-party model providers and bill on a Pay-per-Saving basis. This policy explains what we collect, what we send downstream, and what we do not do. It is written for customers in the United Kingdom and the United States as well as elsewhere.
Related: Cookie Policy · Data Processing Addendum (UK / EU / US business) · Subprocessors · Terms
1. Who we are
For your account, billing, website, and our own logs, we are the controller. For content that a business customer sends through the API or workspace, we act as a processor on that customer's instructions. Model providers that fulfill a request are independent parties under their own terms.
Privacy requests: privacy@iam-token.com. Support: support@iam-token.com.
2. What this policy covers
This policy applies to iam-token.com, the product, the developer API, workspaces, billing, and related emails. It does not cover third-party model providers, Stripe, or sites we link to. Those have their own policies.
We drafted this against how comparable routers describe the same problem (OpenRouter, Weave Router / WeaveOS, Requesty, Together AI, Eden AI, Portkey, Helicone, LiteLLM). Two rules we will not copy from that market: we do not take an irrevocable commercial license over your content, and we do not train our own models on your Inputs or Outputs.
3. The data we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email, name, hashed password, optional TOTP secret, session tokens, plan, workspace membership | Create and secure your account |
| Customer content | Content you submit so we can complete a request (including files you attach) | Provide the Service |
| Routing metadata | Model id, provider, tokens, cost, savings, latency, request id, department / workspace ids — not the prompt text | Billing, analytics, budgets, abuse prevention |
| BYOK keys | Your provider API keys, encrypted at rest (Fernet). We show only a masked suffix after save | BYOK routing |
| Billing | Plan, wallet balance, invoices, auto-recharge flags, Stripe customer id. We do not store card numbers | Charge fees and top up wallets |
| Security logs | Logins, MFA events, key create/revoke, account deletion, plan changes | Security and audit |
| Preferences | IR toggle, strategy, allowed providers, privacy and media settings | Remember Settings |
| Technical | IP address and user-agent on authenticated API calls; browser local storage for session and UI state | Operate and secure the service |
We do not collect government IDs, precise GPS, advertising graphs, or payment card PAN. Contact-form messages are stored long enough to answer them.
4. How we process your requests
To provide the Service we send the content of your request to the model provider selected for that call (or that you choose with BYOK). Providers in the catalog include, for example, OpenAI, Anthropic, Google, and Mistral. Billing uses routing metadata (tokens, cost, savings) — not the text of your request.
- IAM-Token does not train models on your Inputs or Outputs.
- We do not sell your content.
- We may use aggregated, de-identified routing metadata (model mix, token volumes, savings) to operate the product. That metadata does not include request text.
5. Your privacy controls
Settings stores routing and media preferences on your account (strategy, allowed providers, privacy and image options, BYOK keys). BYOK keys are encrypted at rest and never shown in full after save. Personal accounts can be closed from Settings, with a 30-day restore window before purge.
6. How we use data
We use personal data to:
- Provide routing, workspaces, keys, and billing (contract).
- Charge Pay-per-Saving fees and wallet draws (contract).
- Prevent abuse, fraud, and security incidents (legitimate interests / legal obligation).
- Comply with tax and accounting rules (legal obligation).
- Send transactional email (verification codes, receipts, security alerts) (contract).
- Send product updates only if you have not opted out of those messages (consent or legitimate interests, with unsubscribe).
We do not use your data for third-party advertising networks, and we do not “sell” or “share” personal information as those words are used in the CCPA/CPRA.
7. How we share data
We share the minimum needed with:
| Recipient | What | Role |
|---|---|---|
| Model providers (OpenAI, Anthropic, Google, Mistral, others in the catalog) | The request payload needed to complete the call | Independent providers you (or auto-routing) select |
| Stripe | Customer id, email, charges, saved payment method for subscriptions and auto-recharge | Payment processor. See Stripe Privacy |
| Email delivery (SMTP2GO by default; SendGrid or SMTP if configured) | Address and message body for verification codes, login codes, password reset, and receipts. The contact form is emailed to our inbox and is not kept as a product table | Transactional mail |
| E2B (only if code-execution tools are enabled on the deployment) | Model-generated code and document specs for a short sandbox run | Optional tools. Default is off |
| Workspace members you invite | Name, email, role, department, usage attributed to the seat | Your organization |
| Authorities / successor | What the law requires, or what transfers in a merger | Legal / corporate |
Hosting and the application database run on infrastructure we operate or contract (currently including the environment you deploy into). We will keep a living subprocessor note at privacy@iam-token.com on request, and will post a public list as the production footprint stabilizes. We do not currently use Google Analytics, session replay, or ad pixels on the product.
8. Cookies and local storage
The app is a single-page client. We store the session token and a small set of UI flags (sidebar, key mode, draft) in the browser's local/session storage so you stay signed in and the layout is remembered. Those are strictly necessary. We do not set third-party advertising cookies. You can clear storage in the browser; you will be signed out.
9. Retention and deletion
| Data | Kept until |
|---|---|
| Account profile and credentials | Account remains open, then 30-day grace after you delete, then purge / anonymize |
| Usage / invoice metadata | Account life, then as required for tax and dispute (typically up to 7 years for invoice rows) |
| Security logs | As long as needed for security investigations, then deletion with the account where feasible |
| Stripe records | Governed by Stripe; we keep only the customer / payment-intent references |
Personal accounts: Settings → Delete account → 30 days to restore → API keys, BYOK keys, wallet, sessions, and the profile are removed or anonymized. We keep what we still need to bill, audit, or fight abuse: invoices, some security logs, routing-quality scores, and the deletion request itself. Stripe keeps the customer record under its policy; we cancel the subscription at period end rather than deleting the Stripe customer. Business accounts close through support so workspace seats and invoices can be settled. There is no in-app bulk export yet — email privacy@iam-token.com for a copy of what we hold.
10. Security
- Passwords hashed with PBKDF2-SHA256; optional TOTP MFA.
- BYOK keys encrypted at rest; never logged in full.
- HTTPS in transit on deployed environments.
- Session tokens hashed in the database.
- Least-privilege admin access and audit events for security-relevant actions.
No internet service is perfectly secure. You are responsible for keeping your password, MFA device, and API keys private. Report suspected incidents to privacy@iam-token.com.
11. International transfers
We and many model providers process data in the United States and other countries. If you are in the EEA, UK, or Switzerland, that is an international transfer. We rely on adequacy decisions where they exist and on Standard Contractual Clauses with processors where they do not. Provider-side transfers follow that provider's terms. Regional-only routing is not a general feature of the current product.
12. Your rights
Depending on where you live (including GDPR and CCPA/CPRA) you may request to:
- Access a copy of personal data we hold about you
- Correct inaccurate account data
- Delete personal data (subject to legal keeps, e.g. invoices)
- Export a portable copy of account data we hold
- Object to or restrict certain processing
- Withdraw consent where processing was based on consent
- Appeal a denied request, and complain to a supervisory authority
Email privacy@iam-token.com. We will verify the request against the account. Workspace end-user requests for content the company submitted should go to that company first; we will assist the customer as processor.
We do not sell personal information. We do not use sensitive personal information to infer characteristics. We honor browser Global Privacy Control signals as an opt-out of sale/share to the extent they apply — today we do not sell or share in that sense anyway.
United Kingdom: UK GDPR and the Data Protection Act 2018 apply. You may complain to the ICO at ico.org.uk. Business customers also have the DPA (UK IDTA + processor terms).
United States: If you are a California resident, the categories, purposes, and recipients above are the CCPA/CPRA notice at collection. You may request know, delete, correct, and non-discrimination. We do not sell or share personal information as those terms are defined in the CPRA. Nevada residents: we do not sell covered information as defined in NRS 603A. Other state laws (Virginia, Colorado, Connecticut, Texas, and similar) provide access, deletion, correction, and appeal; email the same address. Authorized agents may submit a request with proof of authority.
13. Children
The service is not directed to children under 16, and we do not knowingly collect their data. If you believe we have, contact privacy@iam-token.com and we will delete it. You must be old enough to form a binding contract in your jurisdiction to create an account.
14. Changes
We will post the new date at the top of this page. If we add advertising trackers or change who we share customer content with, we will email the address on the account (or in-app notice). Continued use after a notice means you accept the update for future processing.
15. Contact
Privacy and DSAR: privacy@iam-token.com
Support: support@iam-token.com
This policy describes current product behavior. UK/US business customers should also read the DPA. A HIPAA BAA is a separate signed agreement and is not offered by this public pack.