This Privacy Policy explains how One Solution LLC ("One Solution," "we," "us," or "our" collects, uses, discloses, protects, retains, and deletes personal information when you use Tokend, including its mobile applications, web application, websites, APIs, and related services (collectively, the "Services"). Tokend is the sole intellectual property of One Solution LLC.
1. Scope and Roles
This Policy applies to information processed through the Services. In many cases, a business or organization uses Tokend to manage its own workspace, members, AI agents, integrations, and usage information. For organization-controlled information, the organization may determine why and how that information is processed, and One Solution acts as a service provider or processor on its behalf. This Policy also covers information One Solution processes for its own business purposes, including account administration, security, billing, support, and service improvement.
2. Information We Collect
2.1 Account and profile information
Name, email address, authentication identifiers, login method, profile image, workspace logo, and account preferences.
Organization name, membership, role, invitation status, and related administrative information.
Information received from an identity provider, such as Google, when you choose that sign-in method.
2.2 Workspace and configuration information
AI agent names, descriptions, platforms, status, configuration, activity timestamps, and associated workspace information.
API connection and email-provider information, including provider name, labels, status, key fingerprints, sending addresses, and encrypted credentials or secrets that an authorized user chooses to store.
Telegram bot, AI bot identity, connection-grant, access-token, gateway-token, and other integration configuration information.
Health-check configurations, health-check results, response-preview metadata, spend-alert rules, notifications, and administrative audit logs.
2.3 AI usage and telemetry information
Provider, model, agent, input-token count, output-token count, call count, estimated or provider-reported cost, latency, status, timestamps, and diagnostic metadata.
Event identifiers and ingestion information used to prevent duplicate telemetry records and to distinguish when an event occurred from when Tokend received it.
Metadata identifying the workspace, bot identity, integration source, or connection associated with a usage event.
Tokend is designed to track operational usage and token information. We do not require customers to submit the full content of prompts or model responses for ordinary usage reporting. Limited response-preview or diagnostic metadata may be processed when an authorized administrator configures and runs a synthetic agent health check.
2.4 Billing and subscription information
Workspace plan, subscription status, billing-period dates, cancellation status, transaction references, and related subscription metadata.
Payment-card details are processed by Stripe or the applicable app-store payment provider and are not intended to be stored directly by Tokend.
2.5 Device, log, and support information
Internet Protocol address, browser or device type, operating system, request timestamps, error information, security events, and server logs generated when you access the Services.
Messages, files, and other information you provide when requesting support or communicating with us.
Photo-library content that you actively select to upload as a profile image or workspace logo. Tokend does not request camera or microphone access for this feature.
3. How We Use Information
Provide, authenticate, maintain, and secure the Services.
Create and administer accounts, workspaces, roles, invitations, permissions, and subscriptions.
Connect authorized AI providers, email services, bots, and other integrations selected by a workspace administrator.
Measure AI usage, calculate or estimate token spend, generate reports, perform health checks, deliver notifications, and enforce plan limits.
Process payments, manage subscriptions, prevent fraud, and maintain transaction and accounting records.
Respond to support requests, troubleshoot problems, communicate service notices, and improve reliability and usability.
Detect, investigate, and prevent misuse, unauthorized access, security incidents, or violations of our Terms and Conditions.
Comply with law, enforce agreements, and protect the rights, safety, and property of users, One Solution, and others.
4. How We Disclose Information
We may disclose information in the following circumstances:
Within your organization. Workspace owners, administrators, and authorized members may access information according to their role and the workspace's configuration.
Service providers. We use vendors that support hosting, authentication, database services, application deployment, email delivery, payment processing, app distribution, and related operations. These may include Supabase, Vercel, Expo/EAS, Stripe, Apple, Google, and email-delivery providers.
Customer-selected providers. When an authorized user connects an AI provider, email provider, Telegram bot, custom endpoint, or other integration, Tokend transmits information as needed to provide that connection. The third party's own terms and privacy policy apply to its processing.
Business transfers. Information may be disclosed in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law.
Legal and safety purposes. We may disclose information when reasonably necessary to comply with law or legal process, enforce agreements, protect rights or safety, investigate fraud, or respond to a security incident.
With your direction or consent. We may disclose information when you direct us to do so or otherwise provide consent.
We do not sell personal information. We do not disclose personal information for cross-context behavioral advertising, and Tokend does not include third-party advertising SDKs.
5. Data Storage and Security
Tokend uses administrative, technical, and organizational safeguards designed to protect information. Network traffic uses HTTPS/TLS. Mobile authentication sessions are stored using encrypted device storage where supported. Workspace data is protected by role-based access controls and database row-level security. Provider secrets are handled server-side and are designed to be encrypted at rest when stored; raw provider credentials are not returned to the mobile or web client after saving. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Data Retention
We retain information for as long as reasonably necessary to provide the Services, maintain security, satisfy contractual obligations, resolve disputes, enforce agreements, and comply with legal, tax, and accounting requirements. Retention periods depend on the type and purpose of the information.
Raw AI usage events may be retained for approximately 90 days and then pruned, while aggregated daily usage records may be retained longer for reporting and historical analysis.
Account, workspace, subscription, audit, security, and transaction records may be retained while an account or workspace remains active and for a reasonable period afterward.
Backups may retain deleted information temporarily until overwritten through normal backup cycles.
We may retain a limited record of a deletion request, security event, transaction, or legal hold when necessary for compliance, fraud prevention, dispute resolution, or protection of legal rights.
7. Account and Data Deletion
All Tokend users may initiate deletion of their personal account through the account settings in the Tokend mobile application or web application. Tokend also provides a public web-based deletion pathway for users who no longer have access to the app.
Personal account deletion removes or deidentifies the user's Tokend login, profile information, preferences, active sessions, and organization memberships, subject to the retention exceptions described in this Policy.
Deleting a personal account does not automatically delete an organization, workspace, or information owned or controlled by that organization.
A user who is the last owner of a workspace must transfer ownership or separately delete the workspace before deleting the personal account.
Workspace deletion is a separate administrative action and may remove agents, integrations, usage records, configuration, member access, and other organization data, subject to legal and operational retention requirements.
We may require reauthentication or another reasonable verification step before processing deletion.
Account access may be revoked promptly, while deletion from active systems and service providers may take up to 30 days. Residual copies may remain in backups until those backups are overwritten.
To request assistance with deletion or another privacy request, email [email protected]. Requests should identify the Tokend account email and the nature of the request. We may need to verify identity and authority before acting.
8. Your Privacy Rights
Depending on where you live and subject to applicable exceptions, you may have the right to request access to, correction of, deletion of, or a copy of personal information; to object to or restrict certain processing; and to appeal a denied request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
You can update certain account information directly in Tokend.
You can delete your account using the in-app or web account settings.
You can submit other privacy requests by emailing [email protected].
Where permitted, an authorized agent may submit a request on your behalf. We may require proof of authorization and identity verification.
Because Tokend does not sell personal information or use personal information for cross-context behavioral advertising, there is no sale or targeted-advertising opt-out to exercise for Tokend. We will evaluate legally recognized browser-based opt-out signals where applicable to our public websites.
9. California Privacy Notice
California residents may have rights under the California Consumer Privacy Act, as amended, if that law applies to One Solution's processing. The categories described in Section 2 may include identifiers; commercial information; internet or electronic-network activity; professional or employment-related information supplied in a business account; account credentials; and inferences drawn from usage or configuration information. We use and disclose these categories for the business purposes described in Sections 3 and 4. We do not sell or share personal information for cross-context behavioral advertising.
California residents may request to know, access, correct, or delete covered personal information and may appeal or use an authorized agent where applicable. One Solution will not discriminate against a person for exercising an applicable privacy right.
10. Children's Privacy
Tokend is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Users must be at least 18 years old, or the age of legal majority where they live, to create or administer a Tokend account. If we learn that we collected personal information from a child in violation of applicable law, we will take reasonable steps to delete it.
11. International Processing
Tokend is operated from the United States. Information may be processed and stored in the United States and other countries where our service providers operate. Those countries may have data-protection laws different from the laws where you live.
12. Third-Party Services and Links
The Services may connect to or contain links to third-party products and services. One Solution does not control those parties' privacy practices. Review the privacy notices and terms of each connected provider before enabling an integration or transmitting information to it.
13. Changes to This Policy
We may update this Policy periodically. We will post the revised version with a new effective date and provide additional notice when required by law. Continued use of the Services after an update becomes effective is subject to the revised Policy.
14. Contact Us
Questions, privacy requests, and deletion assistance may be directed to:
Company: One Solution LLC
Product: Tokend
Email: [email protected]
One Solution LLC is based in Phoenix, Arizona, United States.
© 2026 One Solution. All rights reserved. Tokend is a trademark of One Solution.