- Credential owner
- Customer workspace
- Recipient
- Selected model provider or contracted inference processor
- TokenSpend retention
- No content storage by default; optional encrypted 30-day request logging
- Downstream data use
- Governed by the customer's provider account, policy, and agreement
- Provider retention
- Set by the customer's provider account, configuration, policy, and agreement
- Training boundary
- Set by the customer's provider terms and configuration. TokenSpend makes no training-use claim.
- Region
- Customer provider configuration for direct APIs; US or EU default for open-weight routing
- Retention scope
- TokenSpend does not store content by default. Downstream retention follows the customer's provider agreement.
- Contractual ZDR
- No downstream ZDR guarantee unless a signed Enterprise order expressly provides one