Skip to content

Draft, pending legal review

This text is a draft and has not been reviewed by a lawyer yet. It may change before it becomes final. Last updated 7 October 2026.

Privacy policy

For the Tokens for Good portal and the API.

In short

  • We keep what we need to run the service: accounts, organisation profiles, hashed keys and token counts.
  • We do not store the text you send to the AI or the answers. They pass through our servers in memory only.
  • The text is processed in plain text on a donated computer. Its owner could in principle read it. Only send personal data if your organisation is on the trusted tier.
  • We do not sell data and do not use it for advertising or to train AI models.

1. Who we are

This service is run by Tokens for Good (legal entity to be confirmed), based in the Netherlands. The General Data Protection Regulation (GDPR) applies. Questions about privacy: privacy@tokensforgood.nl.

For account data (section 2) we are the controller. For the text a school or cause sends through the API, the school or cause is the controller and we process it on its behalf. Schools and causes that send personal data need a data processing agreement with us; ask us for one.

2. What we collect and why

  • Accounts: email address, a hashed password and your role (school or cause, donor or admin). Needed to log you in.
  • Organisation profiles: for schools and causes the name, KvK number, website, description and intended use; for donors the company or person name. Needed to vet schools and causes and to show donors whom they help.
  • Sessions: a login cookie with a random token, stored hashed on our side and valid for 7 days. We use no tracking or advertising cookies.
  • API keys: we store only a hash (SHA-256) of each key, its name and when it was created and last used. We show the full key once, when you create it.
  • Usage: for each request the time, the API key, the model, the donor machine that served it and the number of tokens. Needed for budgets, rate limits, abuse handling and impact reports for donors.
  • Donor machines: a machine name, a hashed machine token, the operating system, chip type, memory size, agent version, measured speed, the models it offers and when it was last online.
  • Technical logs: our servers log errors and request metadata (such as time, path and status code) to keep the service running and secure. These logs never contain prompt or answer text.

Legal basis: performing our agreement with you (GDPR art. 6(1)(b)) and our legitimate interest in running a safe service (art. 6(1)(f)).

3. The text you send to the AI

When you call the API, your prompt goes to our coordinator. The coordinator passes it to a donor computer that runs the model, and returns the answer to you.

  • The coordinator never stores or logs prompt or answer text, not in the database, not in logs, not on disk. Our tests check this.
  • The donor computer processes the text in plain text. There is no end-to-end encryption and no hardware protection in this version. The owner of the computer could read what is processed on it, and we cannot technically prevent that. There are no donor terms yet; we plan to add terms that forbid donors to inspect content.
  • Open tier (default): any donor may serve your requests. Use it only for non-sensitive text.
  • Trusted tier: your requests only go to machines of donors who are under contract and a data processing agreement with us. Use this tier if you need to send personal data.
  • Donor computers may be located outside the European Economic Area. Rules for where trusted-tier machines may be located are set in their contracts.

4. Who else receives data

  • Donor computers: the prompt and answer text of the requests they serve, as described in section 3.
  • Donors see impact figures: which schools and causes they helped and how many tokens and requests. They do not see your usage details or content through the portal.
  • Hosting: Amazon Web Services, in the Frankfurt region (EU), stores our database and runs our servers.

5. How long we keep data

  • Account, profile and key data: as long as your account exists. API keys you revoke are kept as revoked records.
  • Usage records: as long as needed for budgets and impact reports. TODO (legal review): set a retention period.
  • Prompt and answer text: not kept by us.

6. Your rights

You can ask to see, correct, delete or receive your data, and object to or limit how we use it. Email privacy@tokensforgood.nl. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

7. Changes

We will update this policy when the service changes and show the date at the top. See also our terms of use.