AGENT NETWORK / TOKEN SERVICE
Privacy Policy
Effective date: 12 June 2026 · Applies to the Agent Network Token Service portal and API at agentnetwork.org.cn.
In short: we store the minimum needed to run a metered LLM gateway — your account,
wallet/credit ledger, API usage records, and (for providers) your encrypted endpoint
credentials. We don't sell data. Prompts pass through to upstream model vendors to serve
your request and are not used by us for training.
1. What we collect
| Category | Examples | Why |
| Account data | Username or email, hashed password, display name, role | Authentication, invite-only access control |
| Financial ledger | TBC wallet balances, transactions, top-ups, loans, credit/reputation state, marketplace earnings and payouts | Metering, billing, the TB002 credit system |
| API usage | Model called, token counts, request ids, timestamps, charge amounts | Billing, abuse prevention, service statistics |
| Provider endpoint data | Base URL, served models, availability window, API key (encrypted at rest), probe/benchmark results | Operating the compute marketplace |
| Technical logs | IP address, user agent, rate-limit counters | Security, rate limiting, debugging |
2. Prompts and completions
- Request and response bodies are relayed to the upstream model serving your call
(which may be a platform channel or a community-contributed endpoint) and are subject to
that upstream's own terms.
- We persist token counts and metadata for billing, not full prompt text, except in
transient service logs kept for debugging and abuse investigation.
- We do not use your prompts to train models, and we do not sell them.
3. Provider credentials
- Contributed API keys are encrypted (Fernet) before storage and installed only into the
internal gateway. They are never shown back in plaintext and never exposed to consumers.
- Keys are used exclusively for relaying consumer traffic, liveness probes, and periodic
TPM/RPM benchmarks. Deleting your endpoint removes the gateway channel.
4. Sharing
- Upstream model vendors receive the request content needed to serve each call.
- No sale of personal data. No advertising use. No third-party analytics trackers —
the portal loads no external scripts.
- We may disclose records if required by law or to investigate fraud or abuse.
5. Retention
- Financial ledger entries (wallet, usage, earnings, payouts) are retained for the life of
the service as required for accounting integrity — the credit system depends on an
append-only history.
- Technical logs and probe/benchmark records are pruned on a rolling basis.
- Account deletion: contact us (below); we will deactivate the account and remove personal
identifiers where the ledger's integrity allows.
6. Security
Passwords are stored hashed; provider keys encrypted at rest; internal gateway and database
listen on loopback/private networks only; admin actions are audit-logged. No system is perfectly
secure — report vulnerabilities to the contact below.
7. Your rights
You may access and export your own records via the console and API (balances, usage,
endpoints, earnings), correct your account data, and request deletion as described above.
Depending on your jurisdiction you may have additional statutory rights.
8. Changes
We may update this policy; the effective date above changes accordingly. Material changes
will be announced on the portal.
9. Contact
ink@chatchat.space