Privacy Policy
1. Scope
This policy covers gloritoken.ai, api.gloritoken.ai and the gloritoken API service, operated by Gloritoken (HK) Limited from Hong Kong with serving infrastructure in Singapore.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Username, email, hashed password | Account creation, login, key delivery |
| Billing data | Top-up records, per-request token counts and cost | Metering, invoicing, fraud prevention |
| Request metadata | Timestamps, model name, token counts, status codes, IP address | Operations, abuse prevention, itemized billing |
| Support data | Emails you send us, key-application form entries | Responding to you |
3. Your prompts and outputs
- We do not use your prompts or outputs to train models.
- We do not persistently store request or response bodies in the normal course of operation; we store token counts and metadata for billing. Limited, short-lived technical logs may exist for debugging and abuse investigation.
- Your content is transmitted to the upstream model vendor you select, and is handled by that vendor under its own terms and privacy policy.
4. Where your data goes (routing tiers)
- Global tier (default): inference runs on international endpoints (Singapore region). Your request content does not enter mainland China.
- China-Direct tier (“-cn” model names): your request content is relayed to the model vendor's API in mainland China. This tier is clearly labeled and used only when you explicitly select a “-cn” model.
5. Sharing
We share data only with: (a) the upstream model vendor needed to serve your request; (b) infrastructure providers (e.g. Cloudflare, cloud hosting) under standard data-processing terms; (c) authorities where legally required. We do not sell personal data.
6. Retention
Account and billing records are kept for as long as your account is active and as required by Hong Kong accounting and tax law. Technical logs are rotated on a short cycle. You may request account deletion at any time; we will delete personal data not subject to statutory retention.
7. Security
TLS in transit end to end, hashed credentials, least-privilege access to production systems, and audit logging on administrative actions.
8. Your rights
You may request access to, correction of, or deletion of your personal data under Hong Kong's Personal Data (Privacy) Ordinance by contacting hello@gloritoken.ai. We respond within 30 days.
9. Changes
We will post updates on this page with a new effective date; material changes will be announced on the website.
10. Contact
Gloritoken (HK) Limited · Rooms A-B, 9/F, Easey Commercial Building, 288 Des Voeux Road Central, Sheung Wan, Hong Kong · hello@gloritoken.ai