{"schemaVersion":"1.0","boundaryVersion":"2026-08-18.1","reviewedAt":"2026-08-18T00:00:00.000Z","servingHostDisclosure":"Serving-host identities and route mappings are not public. Provider-specific terms are available to workspace admins during security review.","policyFieldRule":"A null provider policy URL or effective date means the route can use more than one private serving path. It does not mean no downstream policy applies.","routes":[{"route":"BYOK","credentialOwner":"Customer workspace","recipient":"Selected model provider or contracted inference processor","tokenSpendRetention":"Encrypted 30-day history, or no storage when workspace ZDR is on","downstreamDataUse":"Governed by the customer's provider account, policy, and agreement","providerPolicyUrl":null,"providerPolicyEffectiveAt":null,"providerRetention":"Set by the customer's provider account, configuration, policy, and agreement","trainingBoundary":"Set by the customer's provider terms and configuration. TokenSpend makes no training-use claim.","region":"Customer provider configuration for direct APIs; US or EU default for open-weight routing","zdrScope":"TokenSpend storage only. Downstream ZDR depends on the customer's provider configuration.","contractualZdr":"TokenSpend only, unless a signed Enterprise order expressly extends the guarantee","escalationContact":"privacy@tokenspend.dev"},{"route":"Managed credits","credentialOwner":"TokenSpend","recipient":"Selected model provider or contracted inference processor","tokenSpendRetention":"Encrypted 30-day history, or no storage when workspace ZDR is on","downstreamDataUse":"Governed by TokenSpend's provider agreement and service configuration","providerPolicyUrl":null,"providerPolicyEffectiveAt":null,"providerRetention":"Provider-specific and not changed by the TokenSpend ZDR toggle","trainingBoundary":"Governed by the applicable provider agreement and configuration. TokenSpend makes no training-use claim.","region":"Provider-controlled for direct APIs; US or EU default for open-weight routing","zdrScope":"TokenSpend storage only unless an Enterprise order explicitly extends the guarantee downstream.","contractualZdr":"TokenSpend only, unless a signed Enterprise order expressly extends the guarantee","escalationContact":"privacy@tokenspend.dev"}]}