HeyToken Privacy Policy
Effective date: 20 August 2026
This Privacy Policy explains how VITANCE TECHNOLOGY (HK) LIMITED (doing business as HeyToken, we, us, or our) collects, uses, discloses, retains, and protects personal data when you use heytoken.io, our console, APIs, and related services (collectively, the Services).
This Policy is intended to be read with our Terms of Service. If you provide personal data about another person, you must have authority to do so and provide any required notice or obtain any required consent.
1. Data We Collect
Depending on how you use the Services, we may collect:
- Account information: email address, username, password credentials (stored in protected form), account settings, and communications with us.
- Payment and transaction information: payment status, amount, currency, transaction and order identifiers, and billing records. Our payment providers process payment-card and wallet details; we do not store full payment-card details.
- Usage and technical information: API keys and key names, model selected, token and request counts, timestamps, request duration, error information, IP address, device and browser information, log data, and security signals.
- API content: prompts, inputs, files, code, and outputs submitted through or generated by the Services, where necessary to provide the API, usage logs, troubleshooting, abuse prevention, and support.
- Cookies and similar technologies: information needed to operate the website, keep you signed in, remember preferences, measure performance, and protect the Services.
Please do not submit sensitive personal data, confidential information, or regulated data through the Services unless you have assessed the risks and have a lawful basis and all required permissions.
2. How We Use Data
We use personal data to:
- create, authenticate, administer, and secure accounts and API keys;
- provide, operate, maintain, and support the Services;
- process payments, maintain wallet balances, measure usage, and prevent billing errors;
- send service, security, transactional, and policy-related communications;
- detect, investigate, and prevent fraud, abuse, misuse, security incidents, and violations of law or our terms;
- troubleshoot, improve reliability and performance, and develop aggregated or de-identified analytics;
- comply with legal obligations and enforce our agreements; and
- send marketing communications only where permitted by law and, where required, with your consent. You may opt out of marketing at any time.
We do not use your API Inputs or Outputs to train or improve HeyToken's own models.
3. Legal Bases and Hong Kong Privacy Practices
We process personal data for the purposes described above where necessary to provide the Services, comply with legal obligations, pursue legitimate business and security interests, or with your consent where required. We collect data by lawful and fair means and seek to provide clear notice of the purposes for which it is collected.
For personal data subject to Hong Kong's Personal Data (Privacy) Ordinance, we seek to comply with the applicable data-protection principles, including appropriate collection, use, security, access, correction, and retention practices.
4. How We Share Data
We may disclose personal data to the following categories of recipients, only as necessary for the purposes in this Policy:
- Model and inference providers. API Inputs, Outputs, and necessary metadata are sent to the provider or providers needed to fulfil your selected model request.
- Infrastructure and service providers. Hosting, cloud, content-delivery, logging, security, analytics, email, customer-support, and other vendors that help us operate the Services.
- Payment providers. Independent payment processors that process your selected payment method and fraud-prevention checks.
- Professional advisers and corporate transaction parties. Accountants, auditors, insurers, lawyers, and prospective or actual purchasers, investors, or successors in connection with a business transaction.
- Authorities and others where required. Law-enforcement, regulators, courts, or other parties where required by law or where reasonably necessary to protect rights, safety, security, and the integrity of the Services.
We do not sell personal data. We do not provide personal data to third parties for their direct marketing without the notice and consent required by applicable law.
5. International Data Transfers
HeyToken is operated from Hong Kong. The Services use global infrastructure and third-party model providers. Personal data, including API content and technical data, may be processed in Hong Kong, Mainland China, the United States, and other countries or regions where we, our providers, or a selected model provider operate.
Privacy laws in another location may differ from those in your jurisdiction. Where required, we take reasonable steps to ensure an appropriate level of protection for transferred data, such as contractual commitments, provider assessments, technical and organisational safeguards, or another lawful transfer mechanism.
6. Retention and Deletion
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including legal, tax, accounting, dispute-resolution, fraud-prevention, and security requirements.
- API content and detailed request/response logs: retained for up to 30 days by default, then deleted or de-identified, unless a longer period is reasonably necessary for an active security investigation, legal obligation, dispute, or a feature you have chosen.
- Usage and billing records: retained for up to 7 years where reasonably necessary for accounting, tax, fraud prevention, legal, and audit purposes.
- Account and support information: retained while your account is active and thereafter for the period reasonably necessary for the purposes above.
You may delete available logs in the console or request deletion by contacting [email protected]. Deletion is subject to technical limitations, legal obligations, and the need to retain limited records for security, fraud prevention, billing, or dispute resolution. Information already sent to a third-party model provider is also subject to that provider's retention practices.
7. Security
We use reasonable technical and organisational safeguards designed to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. No method of transmission or storage is completely secure. You are responsible for protecting your account credentials and API keys and for promptly reporting suspected unauthorised access.
8. Your Choices and Rights
Subject to applicable law, you may have the right to request access to, correction of, deletion of, or information about the personal data we hold about you; to object to or restrict certain processing; to withdraw consent; and to complain to an appropriate privacy regulator.
You may request access to or correction of your personal data by emailing [email protected]. We may ask for information to verify your identity and authority before responding. We may charge a fee where permitted by law for an access request, and we will explain any fee before proceeding.
9. Cookies
We use cookies and similar technologies that are necessary for core functionality and may use them to understand website performance and usage. You can control many cookies through browser settings. Disabling cookies may affect the availability or functionality of parts of the Services.
10. Children
The Services are not directed to children and are not intended for anyone under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact [email protected] so that we can take appropriate action.
11. Third-Party Services
The Services may link to or integrate with third-party services, including model providers and payment providers. Their data practices are governed by their own policies, not this Policy. We encourage you to review the relevant policies before using those services or submitting data to them.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated Policy with a revised effective date and, where a change is material, use reasonable efforts to provide advance notice. Your continued use of the Services after the effective date is subject to the updated Policy to the extent permitted by law.
13. Contact Us
For privacy questions, data requests, or complaints, contact:
VITANCE TECHNOLOGY (HK) LIMITED
UNIT 11, 9/F THE CLOUD NO.111, TUNG CHAU ST TAI KOK TSUI, HONG KONG
Company registration number: 79526227
Email: [email protected]