Trust center

Know where every boundary sits.

Fleet capture and Router traffic are different data paths. This page states what TokenSpend stores, what downstream providers control, and which facts are pinned to each receipt.

Capture and Router data

Token counts, timestamps, model names, repository names, branches, and git refs.

Fleet capture

Token counts, timestamps, model names, repository names, branches, and git refs. Never prompts, responses, source code, diffs, transcripts, or tool output.

Router traffic

TokenSpend does not store prompts or responses by default. Optional request logging keeps encrypted workspace history for 30 days. Disabling logging stops new storage; existing history keeps its expiry.

Before production

Availability and support, agent compatibility.

Review availability and support. The status page reports sampled checks, not a contractual uptime guarantee.

Check agent compatibility. API and SDK tests do not certify every coding-agent feature or client version.

Route boundary

Request logging governs TokenSpend storage only.

Request logging governs TokenSpend storage only. Downstream retention follows the applicable provider account, configuration, policy, and contract.

TokenSpend does not currently offer provider ZDR. Any existing downstream handling requirement remains enforced across retries and fallback. Missing or stale evidence blocks the attempt. Enforcement details

Boundary 2026-09-14.2, reviewed 9/14/2026. Open machine-readable route record

BYOK

Credential owner
Customer workspace
Recipient
Selected model provider or contracted inference processor
TokenSpend retention
No content storage by default; optional encrypted 30-day request logging
Downstream data use
Governed by the customer's provider account, policy, and agreement
Provider retention
Set by the customer's provider account, configuration, policy, and agreement
Training boundary
Set by the customer's provider terms and configuration. TokenSpend makes no training-use claim.
Region
Customer provider configuration for direct APIs; US or EU default for open-weight routing
Retention scope
TokenSpend does not store content by default. Downstream retention follows the customer's provider agreement.
Contractual ZDR
No downstream ZDR guarantee unless a signed Enterprise order expressly provides one

Managed credits

Credential owner
TokenSpend
Recipient
Selected model provider or contracted inference processor
TokenSpend retention
No content storage by default; optional encrypted 30-day request logging
Downstream data use
Governed by TokenSpend's provider agreement and service configuration
Provider retention
Provider-specific and not changed by TokenSpend request logging
Training boundary
Governed by the applicable provider agreement and configuration. TokenSpend makes no training-use claim.
Region
Provider-controlled for direct APIs; managed Muse Spark excludes Meta-restricted territories; managed Grok excludes sanctions-restricted territories; US or EU default for open-weight routing
Retention scope
TokenSpend does not store content by default. Downstream retention follows TokenSpend's provider agreement.
Contractual ZDR
No downstream ZDR guarantee unless a signed Enterprise order expressly provides one

Serving-host mappings stay private for security and routing resilience. Workspace admins can request the current processor list, applicable downstream terms, retention details, and deletion escalation through privacy@tokenspend.dev.

Pricing provenance

Registry 2026-09-17.3

Registry 2026-09-17.3

Observed 9/17/2026. New receipts carry this version, their token basis, and six-decimal USD rounding.

Open machine-readable registry

Policies and requests

Current public versions

Current public versions

Read the dated privacy notice and terms. Security reports, deletion requests, DPA requests, and processor questions go to the contacts on those pages.

Changelog

  • Registry 2026-09-17.3

    New receipts carry this version, their token basis, and six-decimal USD rounding.

  • Boundary 2026-09-14.2

    Request logging governs TokenSpend storage only. Downstream retention follows the applicable provider account, configuration, policy, and contract.