1. Scope
This policy covers paritok.com, the Paritok dashboard, and the hosted compression API (together, the “Service”), operated by Paritok (“we”, “us”).
The open-source Paritok gateway and model run on your own machine. When you self-host them, nothing you process is sent to us. The gateway only contacts the Service if you configure it with a Paritok API key to use hosted compression; the sections below then apply to what it sends.
2. What we collect
Account information
When you sign in with Google or Microsoft, we receive and store your email address, name and profile picture, which provider you used, and the time and IP address of each sign-in. When you come back while still signed in, we also record the time and IP address of that visit, at most once a day per IP address.
API keys
We store a one-way hash of each API key and a short display prefix. The full key is shown to you once and is not stored.
Content you send to the hosted API
When your gateway uses hosted compression, it sends us segments of your agent’s context — for example file contents, command output and tool results — along with request details: the query or intent text, the content kind, the compression level, and the name of the model your agent uses. We return a compressed version. We store the submitted content and the compressed result, with those request details, for 90 days (longer only if you turn on “Help improve Paritok”; see Sections 3 and 6). Your code can contain personal data or secrets, so please also read Section 8.
Usage data
For each hosted request we record token counts, compression ratio, which tokens are billable, processing time, a request ID, the API key used and a timestamp. If your gateway uses an API key, it also reports token counts for tool-schema filtering, which runs locally; those reports contain numbers only, never content.
Billing information
Credit top-ups are paid through Stripe. Stripe collects your card or other payment details directly; we never see or store card numbers. We store your Stripe customer ID, your credit balance and its expiry, the amount and time of each top-up and credit grant, when you accepted our Terms, and your usage totals.
Technical data
We record the IP address of each sign-in (see above) to keep accounts secure and to prevent abuse, such as one person claiming the welcome credit through many accounts. For rate limiting we also use the IP address or API key of API requests; that is held briefly in server memory and not written to our database. Like most websites, our hosting infrastructure may keep standard server logs (such as IP address, user agent and request time) for security and operations.
3. How we use it
- To run the Service: sign you in, compress your requests, and show your usage.
- To meter usage and bill you, and to answer billing questions.
- To keep the Service secure: rate limiting, preventing abuse, investigating incidents.
- To debug problems and measure compression quality.
- Training is off by default. We do not use content you submit to the hosted API to train or improve our models. Only if you turn on “Help improve Paritok” in your dashboard may we use content you submit while it is on, and the compressed results, to evaluate and train our compression models. You can turn it off at any time.
- To tell you about changes to the Service, pricing or these policies.
- To comply with the law.
We do not sell your personal information, and we don’t use it for advertising.
4. Who processes it
We use these providers to run the Service. They process data on our behalf:
- RunPod — GPU servers that run the compression model. Content you send to the hosted API is processed there.
- Amazon Web Services — hosts the website and API.
- MongoDB Atlas — our database, which holds the account, usage and content data described above.
- Stripe — payment processing and invoicing.
- Google and Microsoft — sign-in, under their own privacy policies.
We may also disclose information if the law requires it, to protect the rights and safety of Paritok or others, or as part of a merger, acquisition or sale of assets (in which case this policy continues to apply to your information).
5. Cookies
We set one cookie, paritok_token, which keeps you signed in. It is strictly necessary, HTTP-only, and lasts up to 90 days. We don’t use analytics or advertising cookies. Signing in with Google or Microsoft loads their scripts, which may set their own cookies. The Product Hunt badge on our homepage is loaded from Product Hunt’s servers.
6. Retention
- Account information: while your account exists. Sign-in times and IP addresses: your most recent 1,000 sign-ins.
- Content submitted to the hosted API and compressed results: 90 days. We keep them for security, abuse prevention and debugging, then delete them automatically.
- If you turned on “Help improve Paritok”: content submitted while it was on is kept for training until you turn the setting off or ask us to delete it. Turning it off puts that content back on the 90-day schedule, so anything older than 90 days is deleted. Models already trained with it are not changed.
- Usage and billing records: as long as needed for billing, tax, accounting and legal purposes, even after you close your account.
7. Security
Traffic to the Service is encrypted in transit (HTTPS), API keys are stored only as hashes, and access to our database is restricted. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you as the law requires.
8. Your choices and rights
- Use the self-hosted gateway if you don’t want your code to leave your machine. Hosted compression is optional.
- Revoke API keys at any time in the dashboard.
- Turn “Help improve Paritok” (training use of your content) on or off at any time in the dashboard. It is off unless you turn it on.
- Ask us to access, correct, export or delete your information, including content you submitted, by emailing [email protected]. We respond within 30 days.
- Depending on where you live (for example the EEA, the UK or California), you may have additional rights, including to object to or restrict processing and to complain to a data protection authority.
9. International transfers
We and our providers process data in the United States and other countries where they operate. Where the law requires, we rely on appropriate safeguards for these transfers.
10. Children
The Service is for developers and is not directed to children under 16. We don’t knowingly collect their information; if you believe a child has given us information, contact us and we will delete it.
11. Changes
We will post updates here with a new “Last updated” date and notify you by email or in the dashboard of material changes.
12. Contact
Privacy questions and requests: [email protected].
