← Tollgate

# Privacy Policy

**Effective date:** [EFFECTIVE_DATE]

This Privacy Policy explains how [COMPANY] ("Tollgate", "we", "us") handles
information in connection with the Tollgate Service at [WEBSITE_URL]. We built the
Service around **data minimization** — we keep as little of your data as possible.

## The short version

- We **do not retain the text you send to the API.** Your request Input is purged
  immediately after it is processed.
- We keep your **result (Output) only briefly** — for a short retrieval window
  (default 24 hours) — then it is automatically purged.
- We permanently keep only **metadata** needed to run the business: your account
  email, and per-request facts like the endpoint used, cost, status, timing, and
  the IP address of the request (for security and rate limiting).
- We **do not sell your data** and **do not use your Input or Output to train any
  model.**
- Card payments are handled by our payment processor; **we never see or store your
  full card number.**

## Information we collect

**You provide:**
- **Account email** — to create your account and issue an API key.
- **API Input** — the payload you send to an endpoint. Used only to compute your
  result, then purged (see Retention).

**Collected automatically:**
- **Request metadata** — endpoint ("kind"), priority, compute weight, cost,
  status, timestamps, and latency.
- **Technical data** — IP address and similar request data, used for security,
  abuse prevention, and rate limiting.
- **Local storage** — the dashboard stores your API key in your browser's local
  storage so you stay signed in. It is not sent to us except as your API key on
  requests you make.

**From our payment processor:**
- When you buy credits, [PAYMENT_PROCESSOR] processes the payment. We receive a
  confirmation and limited details (e.g., that a payment succeeded and an
  identifier). **We do not receive or store your full card details.** See
  [PAYMENT_PROCESSOR]'s privacy policy for how they handle your payment data.

## How we use information

- To provide the Service (process requests, return results, maintain balances).
- To bill accurately and prevent fraud and abuse (including rate limiting).
- To communicate with you about your account or the Service.
- To comply with law and enforce our Terms and Acceptable Use Policy.

We do **not** use your Input or Output to train models, and we do not sell your
personal information.

## Data retention

| Data | Retention |
|---|---|
| API Input (your submitted text/payload) | **Purged immediately after processing** |
| API Output (your result) | Kept for a short retrieval window (default **24 hours**), then purged |
| Request metadata (kind, cost, status, timing, IP) | Retained while your account is active, for billing, security, and history |
| Account email + API key (hashed) | Retained while your account is active |
| Payment records | As required for accounting/tax and by our payment processor |

You can request deletion of your account and associated metadata (see Your rights).
Some records may be retained where required by law (e.g., tax records).

## How we share information

We share information only with:
- **Service providers** strictly necessary to operate the Service — currently our
  **payment processor** ([PAYMENT_PROCESSOR]) for purchases. The Service itself is
  hosted on infrastructure we control.
- **Legal** — where required by law, regulation, legal process, or to protect the
  rights, safety, or property of [COMPANY], our users, or the public.
- **Business transfer** — in connection with a merger, acquisition, or sale of
  assets, subject to this Policy.

We do not sell or rent personal information.

## Security

We use reasonable technical and organizational measures to protect data, including
storing API keys only as hashes and minimizing retained data. No method of
transmission or storage is 100% secure, and we cannot guarantee absolute security.

## Your rights

Depending on where you live, you may have rights to access, correct, or delete your
personal information, or to object to or restrict certain processing. To exercise
these, email [CONTACT_EMAIL]. Because we minimize data, most of what we hold is
your email and request metadata; your Input has already been purged.

## Children

The Service is not directed to children and is not intended for anyone under 16.
We do not knowingly collect personal information from children.

## International users

We operate from the United States. If you access the Service from outside the U.S.,
you understand your information may be processed in the U.S.

## Changes

We may update this Policy. Material changes will be posted at [WEBSITE_URL] with a
new effective date.

**Contact:** [CONTACT_EMAIL]