Trust center

Know where every boundary sits.

Fleet capture and Router traffic are different data paths. This page states what TokenSpend stores, what downstream providers control, and which facts are pinned to each receipt.

Capture and Router data

Fleet capture

Token counts, timestamps, model names, repository names, branches, and git refs. Never prompts, responses, source code, diffs, transcripts, or tool output.

Router traffic

Requests and responses are stored encrypted for 30 days for workspace request history. Workspace ZDR stops new TokenSpend storage immediately and deletes existing stored bodies.

Route boundary

TokenSpend ZDR governs TokenSpend storage. It does not by itself change a downstream provider's policy, account configuration, or contract.

BYOK

Credential owner
Customer workspace
Recipient
Selected model provider or contracted inference processor
TokenSpend retention
Encrypted 30-day history, or no storage when workspace ZDR is on
Downstream data use
Governed by the customer's provider account, policy, and agreement
Region
Customer provider configuration for direct APIs; US or EU default for open-weight routing
ZDR scope
TokenSpend storage only. Downstream ZDR depends on the customer's provider configuration.

Managed credits

Credential owner
TokenSpend
Recipient
Selected model provider or contracted inference processor
TokenSpend retention
Encrypted 30-day history, or no storage when workspace ZDR is on
Downstream data use
Governed by TokenSpend's provider agreement and service configuration
Region
Provider-controlled for direct APIs; US or EU default for open-weight routing
ZDR scope
TokenSpend storage only unless an Enterprise order explicitly extends the guarantee downstream.

Serving-host mappings stay private for security and routing resilience. Workspace admins can request the current processor list and applicable downstream terms through privacy@tokenspend.dev.

Pricing provenance

Registry 2026-08-08.1

Observed 8/8/2026. New receipts carry this version, their token basis, and six-decimal USD rounding.

Open machine-readable registry

Policies and requests

Current public versions

Read the dated privacy notice and terms. Security reports, deletion requests, DPA requests, and processor questions go to the contacts on those pages.