Privacy notice
This notice explains how Daiko Lab SA processes personal data when you use AI Tokens: the website aitokens.ch, the dashboard (my.aitokens.ch), the chat (chat.aitokens.ch), the documentation (wiki.aitokens.ch) and the API (api.aitokens.ch). It follows the Swiss Federal Act on Data Protection (FADP). If you are in the European Union, the GDPR applies as well.
1. Who is responsible
Daiko Lab SA, Via San Gottardo 86, 6900 Massagno, Switzerland, UID CHE-341.329.982, is the controller of your personal data.
For any question about your data, and to exercise your rights: info@daikolab.ch.
2. What we keep, why, and for how long
| Data | Why | How long |
|---|---|---|
| Account: name, e-mail address, language and display settings. If you enter them: company name, billing address, VAT or UID number. Of your password we keep only a fingerprint (a hash) from which the password cannot be recovered | To run your account and invoice you | While the account exists. This includes an account whose address was never confirmed: to have it deleted, write to us |
| Credit: balance and movements (free credit, top-ups, charges) | To count your credit | While the account exists |
| Invoices | Accounting law | 10 years (art. 958f of the Swiss Code of Obligations) |
Usage records, one per request: date and time, API key, endpoint, model, the machine and zone that computed the answer, input and output tokens, amount charged, response time, outcome, a request reference, and the user field if you send one. No text of requests or answers, and no IP address |
To charge you and to show you your usage | While the account exists |
Automatic model choices (the model auto): API key, the model chosen, the reason, the score, the estimated number of input tokens, whether tools or images were present, the time it took. No text |
To check and improve how the model is chosen | 90 days |
| Request log: endpoint, model, the parameters of the request with every message and input replaced by its length, status, error message, tokens and response time. The texts of requests and answers only for an API key on which you switch on keeping contents (on the API keys page), and then encrypted | To find faults. The texts, to help you debug your program | 30 days |
| Conversations in the chat. Messages are encrypted, titles are not | To show them to you again | Until you delete them, or while the account exists |
| Documents you upload: the file, its text split into pieces and the vectors used to search it | To answer questions about your documents | Until you delete them, or while the account exists |
| Pictures, voices and videos you create | So you can see and download them | Pictures and voices made in the dashboard's Studio: 2 hours. Pictures from the API, when you ask for a link: 24 hours. Pictures returned inside the API answer, and voices from the API, are not kept. Videos: 7 days. The text describing a video is deleted when the video is ready or fails, or after 30 days for a key that keeps contents |
Sign-ins through the API's /api/v1/auth endpoints: IP address and browser or app of each sign-in |
To keep you signed in and protect the account | Up to 90 days after the sign-in expires (it lasts 30 days) or is revoked |
| Page statistics: page, date and time, the domain you came from (never the full address), type of device and a fingerprint that changes every day. No cookie and no IP address | To know which pages are used | 12 months |
| Server logs: IP address, address requested, browser and errors | To protect the service from abuse and to fix faults | 14 days |
| Proof of an account deletion: e-mail address, date and time, IP address and browser of the request | To be able to show that we deleted the account | 12 months after the deletion, or after you cancel it |
| E-mails you write to us | To answer you | As long as we need them to deal with your request. E-mails that are accounting records, for example about a payment: 10 years |
| News by e-mail: your e-mail address, when you subscribed and when you confirmed it | To send you the news you asked for, once you have confirmed the address from the link we e-mail you | Until you unsubscribe, from the link in every e-mail: the address is deleted at once. An address never confirmed is deleted after 7 days |
| Backup copies of the database | To recover data after a fault | One copy every night. The last 7 stay on the AI Tokens machine and the last 30 on a separate store, both in Switzerland. Older copies are deleted, so the oldest is 30 days old |
The user field of the API is stored as you send it. Use an identifier that means something only to you, not a name or an e-mail address.
We do not use your requests, answers, conversations or documents to train models.
3. Where your data are processed
In Switzerland: your account, keys, credit, usage records, request log, conversations, documents, pictures and videos, logs and backup copies. They are on the AI Tokens machine and on a separate store for the copies, both on the GigaKube cloud of Daiko Lab SA in Switzerland. Every API request first reaches that machine, which forwards it to a model.
Automatic model selection. With the model auto, a small model of ours in Switzerland reads the last message of the request to choose the model that answers. It keeps nothing of what it reads.
Models run in Switzerland. The machines that compute the answers are in Switzerland too. Once a request reaches us, not a single packet of it leaves Switzerland.
- The request and the answer travel between the AI Tokens machine and the machine that computes the answer through an encrypted tunnel.
- Answers of the chat, responses and audio endpoints carry an
X-Zonaheader with the code of the zone that computed them (for exampleCH-1), and each usage record keeps it.
4. Who else receives data
| Who | What for | Data |
|---|---|---|
| SMTP2GO | Sends the service's e-mails (address confirmation, password reset) and the news to those who subscribe. We send through its EU endpoint, mail-eu.smtp2go.com | Your e-mail address and the content of those e-mails |
| Google (Google Workspace) | Hosts the mailbox info@daikolab.ch | The e-mails you write to us |
| Stripe (Stripe Payments Europe, Ltd., Ireland) | Processes card payments for top-ups | Your e-mail address and the amount. The card details you type on Stripe's payment page go to Stripe only: we never see them. With the automatic top-up, Stripe keeps the card for the next charges; we keep only Stripe's references to it |
| Cloudflare | DNS for aitokens.ch: it tells browsers the address of our machine. Traffic to aitokens.ch does not pass through Cloudflare | The DNS lookups for aitokens.ch |
Nobody else receives your data, unless the law obliges us.
Google and Cloudflare are companies based in the United States, and Stripe belongs to a group based there. The e-mails you write to us, and the data of a card payment, may therefore be processed outside Switzerland and the European Union.
5. Legal bases
For users in the European Union, under the GDPR:
- your consent (art. 6(1)(a)): the news by e-mail, which you withdraw at any time by unsubscribing;
- the contract you accept when you sign up (art. 6(1)(b)): your account, credit, the requests you send, usage records, service e-mails;
- legal obligations (art. 6(1)(c)): invoices and accounting records;
- our legitimate interest (art. 6(1)(f)): the request log, server logs and page statistics, to protect and fix the service; the proof of an account deletion, to show that it was done.
Under the FADP we process data for the same purposes, in proportion to them.
6. Your rights
You can ask to see your data, to correct them, to delete them and to receive a copy in a machine-readable format. In the European Union you can also ask us to restrict processing and object to processing based on our legitimate interest. Write to info@daikolab.ch. We answer within 30 days.
You delete conversations and documents yourself, in the chat and in the dashboard. You delete the whole account as described in section 7.
If you think we do not respect the law, you can complain to the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch) or, from the European Union, to the supervisory authority of your country.
7. If you delete your account
You delete it yourself, with your password, on the Account page of the dashboard.
- At once the account is switched off. You can no longer sign in, and your API keys stop working.
- For 30 days the data stay, in case you change your mind. To switch the account back on, write to info@daikolab.ch.
- After 30 days we delete your name, e-mail address, password, billing details, conversations, documents, keys, videos, credit and its movements, usage records, the request log and API sign-ins. A row without personal data stays, so invoices remain linked to it.
- What stays: invoices, for the 10 years the law requires, and for 12 months the proof of the deletion.
- Backup copies are overwritten. Within another 30 days your data are gone from them too.
8. Security
- Every address of the service works over HTTPS only (TLS 1.2 and 1.3).
- We keep passwords and API keys only as fingerprints. We cannot read them back.
- Chat messages, and request texts kept for the keys that ask for it, are encrypted by the application before they reach the database.
- The database and the file store accept connections only from the machine itself and from our private network.
- Traffic between our machines goes through encrypted tunnels.
If a breach of your data is likely to put you at high risk, we inform the FDPIC and you, as the law requires.
9. Cookies
Only the cookies the service needs. They are listed on the Cookies page.
10. Minors
The service is not for people under 16.
11. Changes
The date at the top says when this version took effect. Before a change that affects how we use your data, we tell you by e-mail.