TokenFab Open Platform Privacy Policy
Latest version effective: September 18, 2026
Shenzhen Xiangyuan Gongfang Technology Co., Ltd. (hereinafter referred to as "Xiangyuan Gongfang" or "TokenFab" or "we") understands the importance of your personal information and regards protecting its security as one of our core operating principles. Accordingly, in accordance with the Personal Information Protection Law of the People's Republic of China, the Data Security Law of the People's Republic of China, the Cybersecurity Law of the People's Republic of China, and other relevant laws and regulations, we have formulated this TokenFab Open Platform Privacy Policy (hereinafter referred to as "this Policy").
This Policy is intended to clearly explain how, when you access the TokenFab Open Platform (domain: tokenfab.cn and its sub-domains, hereinafter referred to as "this Platform") and use our services, we collect, use, store, share, and protect your personal information, as well as the rights you are entitled to under applicable laws.
[Please read carefully] Before using this Platform, please read this Policy in full and carefully. Provisions identified in bold and bold-underlined text are closely related to your rights and interests; Please pay special attention to them. If you disagree with any part of this Policy, please stop using this Platform immediately. By clicking "Agree," completing registration, or otherwise starting to use this Platform's services, you are deemed to have fully understood and accepted all the terms of this Policy.
[Contact] If you have any questions or suggestions about this Policy, you can reach us at service@tokenfab.com.
This Policy covers the following:
I. Definitions and Scope of Application
1.1 Core Definitions
- TokenFab Open Platform: The comprehensive platform operated by Shenzhen Xiangyuan Gongfang Technology Co., Ltd. that provides users with AI model inference, API calls, compute services, model fine-tuning, and other technical services via the internet (domain: tokenfab.cn and its sub-domains).
- Personal Information: Information recorded in electronic or other forms that, alone or combined with other information, can identify a specific natural person or reflect their activities. Anonymized information is not personal information.
- Sensitive Personal Information: Personal information that, once leaked or used illegally, can easily harm a natural person's dignity or safety, including biometric information, religious beliefs, specific identity information, medical health information, financial account information, location tracking information, and personal information of minors under fourteen. This Policy marks sensitive personal information with bold underlines.
- User / You: A natural person, legal entity, or other organization that registers for and uses this Platform's services.
- Anonymization: The technical process of processing personal information so that the subject cannot be identified and the information cannot be restored.
- Child: A minor under the age of fourteen.
Unless otherwise stated in this Policy, the meanings of relevant terms are consistent with the TokenFab Open Platform User Agreement.
1.2 Scope of Application
This Policy applies to all products and services provided by the TokenFab Open Platform. If we have a separate privacy policy for a specific service, that service is governed by its own privacy policy; services without a separate privacy policy are governed by this Policy.
This Policy does not apply to products or services provided by third parties through this Platform. The personal information processing rules of such third-party services are subject to their own published privacy policies.
II. Collection and Use of Personal Information
We collect your personal information only to the minimum extent necessary for service functionality, strictly following the principles of legality, propriety, necessity, and good faith. Specifically:
- Necessary Information: If you refuse to provide information essential for basic service functionality, you will not be able to use the corresponding services;
- Non-essential Information: For information needed for extended features, you may choose whether to provide it. Refusal does not affect your use of basic services.
Special Note: The types of personal information collected by different features of this Platform may vary. When we launch new features or need to change the purpose or method of personal information processing, we will inform you through updated policies, pop-ups, or other prominent means and obtain your consent.
2.1 Account Registration and Login
To create your Platform account, we need to collect your mobile phone number and SMS verification code. If you refuse, you cannot complete registration. For better customer service, you may optionally provide your email address and login password; not providing these does not affect basic usage.
If you choose to log in via a third-party account (WeChat, etc.), we will obtain some information from that third-party account (such as WeChat OpenID) to associate it with your Platform account, enrich your profile, and ensure account security. Refusing authorization means you cannot use third-party login, but you can still register via phone number.
2.2 Identity Verification
To meet legal compliance requirements, if you need to use features such as account recharge, you must complete identity verification (either personal real-name verification or enterprise verification):
- Individual Users: Must provide real name and ID number, and upload front and back photos of the ID and a hand-held ID photo. This information is used solely for identity verification. We entrust qualified third-party verification providers and do not store your ID information.
- Enterprise Users: Must provide legal representative name, ID number, ID photo, and mobile number. If you are not the legal representative, please ensure you have their lawful authorization. Additionally, provide the enterprise name, unified social credit code, business license copy, and corporate bank account information (this information is not personal information).
Not completing identity verification does not affect your use of other Platform features that do not require verification.
2.3 Business Consultation and Customer Support
When you submit a business consultation through this Platform, we need to collect your name, mobile number, email, company name, position, industry, and primary use case to contact you and respond.
When you contact our customer support team, to verify identity and provide effective support, we need to collect your mobile number, account ID, and issue description, and may obtain your device information (brand/model, OS version), network information (IP address, network status, carrier), and browser log information. If contacting via email, we will also collect your email address.
To improve service quality and maintain processing records, we will save your communication records with customer service, with retention periods as required by law.
2.4 Model Trial and Interaction
You may voluntarily try various AI models on this Platform. Depending on your usage, we may receive text conversations, images, audio, documents, and other input content you actively provide, and generate corresponding outputs.
If you use real-time audio/video interaction, we need your camera and microphone permissions to transmit live video and audio. You can disable these permissions at any time in your browser settings. Disabling them makes the corresponding features unavailable but does not affect other Platform features.
We process your model input and output content only to the extent necessary to complete the inference services you request, including generating output results and processing required by laws and regulations or necessary to safeguard service security; we will not use such data for model training, fine-tuning, or any form of model improvement, nor for any purpose beyond those described in this Policy.
Important Reminder: Neither this Platform nor the integrated models require you to input personal information. To avoid personal information security risks, we strongly recommend that you do not input content containing sensitive personal information (such as biometric features, financial account passwords, medical health records, etc.) to the models. Whether you provide personal information in conversations and what kind you provide is entirely your own decision and risk.
2.5 Exceptions Not Requiring Authorization
According to relevant laws and regulations, collecting and using your personal information without your authorization is permitted in the following circumstances:
- Necessary for concluding or performing a contract to which you are a party;
- Necessary for performing statutory duties or obligations;
- Necessary for responding to public health emergencies or protecting natural persons' lives, health, and property in emergencies;
- Processing personal information you have voluntarily made public or that has been lawfully made public, within the reasonable scope permitted by law;
- Other circumstances stipulated by laws and administrative regulations.
2.6 Anonymization
When we anonymize collected information (i.e., take technical measures so that the data recipient cannot re-identify a specific individual and the information cannot be restored), such data no longer constitutes personal information under relevant laws and regulations, and subsequent use does not require your consent. We may use anonymized data for platform optimization, statistical analysis and business decision support. We will not use your model input and output data for model training, model fine-tuning, or model improvement.
2.7 Processing After Service Discontinuation
If we discontinue all or part of this Platform's services, we will notify you in advance via announcements, immediately stop collecting related personal information, and delete or anonymize the personal information we hold. For children's personal information, we will simultaneously notify their guardians.
III. Sharing, Transfer, and Public Disclosure of Personal Information
We do not share, transfer, or publicly disclose your personal information to third parties in principle. If such operations are necessary, we strictly follow this Policy and obtain your consent in advance as required by law.
3.1 Entrusted Processing and Third-Party SDKs
To ensure stable service operation and feature implementation, we may entrust third-party service providers to process some personal information or integrate partners' services via SDKs/APIs. We sign strict confidentiality agreements with such third parties and conduct security assessments and oversight to ensure they protect your information to a standard no lower than this Policy. The main scenarios are:
| Third-Party Service | Purpose | Collection Method | Information Type | Provider |
|---|---|---|---|---|
| Alipay | Enable online payment | Backend API transfer and SDK collection | Payment orders and transaction information | Alipay (Hangzhou) Information Technology Co., Ltd. |
| WeChat Pay | Enable scan-to-pay | Backend API transfer and SDK collection | Payment orders and transaction information | Tenpay Payment Technology Co., Ltd. |
| Identity Verification | Personal identity verification | Backend API transfer and SDK collection | Name, ID number, facial recognition information | Alibaba Cloud Computing Co., Ltd. |
| SMS and Email Service | Send verification codes, notifications, and service messages | Backend API transfer | Mobile number, email | Alibaba Cloud Computing Co., Ltd. |
3.2 Transfer
In the event of merger, division, dissolution, acquisition, or bankruptcy of Xiangyuan Gongfang, if personal information transfer is involved, we will inform you in advance of the recipient's name and contact information. The recipient must continue to fulfill the obligations under this Policy; if the processing purpose or method changes, your consent will be re-obtained.
3.3 Public Disclosure
We only publicly disclose your personal information when required by laws, judicial procedures, or competent government authorities, and only to the necessary extent.
3.4 Exceptions Not Requiring Consent
According to laws and regulations, sharing, transferring, or publicly disclosing personal information without your authorization is permitted in the following circumstances:
- Necessary for concluding or performing a contract to which you are a party;
- Necessary for performing statutory duties or obligations;
- Necessary for responding to public health emergencies or protecting natural persons' lives, health, and property in emergencies;
- Processing personal information you have voluntarily made public or that has been lawfully made public, within the reasonable scope permitted by law;
- Other circumstances stipulated by laws and administrative regulations.
Anonymized information that cannot be re-identified by the recipient and cannot be restored may be shared, transferred, or publicly disclosed without your consent.
IV. Storage, Protection, and Security Assessment of Personal Information
4.1 Storage Location
Personal information collected and generated during our operations within the People's Republic of China is stored on servers located in China. There is currently no cross-border transfer of personal information. If cross-border transfer becomes necessary in the future, we will, in accordance with the law, inform you in advance of the transfer purpose, recipient information, processing method, types of personal information involved, how to exercise your rights, and security safeguards, and obtain your separate consent.
4.2 Storage Period
We retain your personal information only for the minimum period necessary to achieve the purposes described in this Policy, except where laws mandate longer retention. The main factors for determining the storage period include:
- Completing business records related to you to respond to potential inquiries or complaints;
- Ensuring service security and quality;
- Mandatory retention requirements of laws and regulations;
- Other special agreements with you.
If the law mandates a minimum retention period for certain information, we cannot delete or anonymize it before that period expires, even if you cancel your account or request deletion. After the statutory retention period expires, we will immediately complete deletion or anonymization.
For model inference requests, your input and output data are processed on a transient basis only for the time necessary to complete the inference, and are not retained after the service is completed; we support Zero Data Retention and do not retain any input or output data.
4.3 Security Technical Measures
We have established a multi-layered security protection system, including but not limited to: data classification and grading protection, transmission encryption (SSL/TLS), storage encryption, access control and identity authentication, network firewalls, intrusion detection, and malware protection, to prevent unauthorized access, use, tampering, or leakage.
4.4 Security Management Measures
We have established a data security-focused management system covering system design, personnel management, and process control:
- Formulating and strictly enforcing personal information protection management systems;
- Establishing a dedicated personal information protection officer position;
- Conducting regular security and privacy protection training for employees;
- Following the principle of least privilege, strictly limiting personnel access to personal information.
4.5 Security Incident Emergency Response
If a personal information security incident occurs or may occur, we will immediately activate our emergency plan, take effective measures to reduce impact, and inform you in accordance with legal requirements: the basic situation and possible impact, remedial measures taken or to be taken, measures you can take to reduce risk, and our contact information. We will notify you via email, phone, in-platform notifications, or other methods. If individual notification is not required by law, we will publish an announcement. We will also report the incident handling to regulatory authorities.
4.6 Your Responsibility for Self-Protection
Please safeguard your account and password, use complex passwords different from other platforms, and avoid logging in on public networks. If you find your account has been compromised or information leaked, please contact our customer support immediately. Note: Any information you actively provide when using services (including others' personal information) is your own responsibility to carefully evaluate.
4.7 Personal Information Protection Impact Assessment
When processing sensitive personal information, using personal information for automated decision-making, entrusting personal information processing, providing personal information to third parties, publicly disclosing personal information, or transferring personal information overseas, we will conduct a personal information protection impact assessment in advance in accordance with Article 55 of the Personal Information Protection Law and record the processing. Assessment reports and processing records will be kept for at least three years.
V. Your Rights Regarding Personal Information
Under relevant laws and regulations, you have the following rights regarding your personal information, which we will respond to and protect in accordance with the law:
5.1 Access, Copy, and Correct
You can access, copy, and correct your personal information at any time by logging into this Platform and navigating to "Personal Center." If some information cannot be operated on online, you can contact us through customer support.
5.2 Delete Personal Information
You may request deletion of your personal information under any of the following circumstances:
- The processing purpose has been achieved, cannot be achieved, or is no longer necessary;
- We stop providing the product/service, or the retention period has expired;
- You withdraw consent;
- We process your personal information in violation of laws, regulations, or agreements;
- Other circumstances stipulated by laws and administrative regulations.
You can submit a deletion request through this Platform's ticket system or email service@tokenfab.com. After deletion, due to technical limitations, corresponding information in backup systems may not be immediately cleared; We will securely isolate it and stop all processing except storage until it can be thoroughly cleared or anonymized. If a statutory minimum retention period applies, processing will be completed immediately after expiration.
5.3 Withdraw Authorization
You may withdraw your previous authorization for our collection and processing of personal information. After withdrawal, we will stop processing the corresponding personal information. Withdrawal does not affect the legality of processing activities previously conducted based on your consent.
5.4 Cancel Account
You can submit a cancellation request at "Personal Center — Account Settings — Cancel Account." After cancellation, we will stop providing services and delete or anonymize your personal information in accordance with legal requirements. If a statutory minimum retention period applies, processing will be completed immediately after expiration.
5.5 Request Response
To ensure account security, we may need to verify your identity before processing the above requests (e.g., requiring written applications, verification codes, etc.). We will respond within 15 business days of receiving your request.
For reasonable requests, we process them free of charge; for repeated or unreasonable requests, we may charge reasonable fees or decline to respond under the following statutory circumstances:
- Directly related to national security or defense;
- Directly related to public safety, public health, or major public interest;
- Directly related to criminal investigation, prosecution, trial, or judgment execution;
- There is sufficient evidence that you have subjective malice or are abusing rights;
- Response would seriously harm the legitimate rights of you or other individuals/organizations;
- Involves trade secrets;
- Other circumstances stipulated by laws and administrative regulations.
VI. Protection of Minors' Information
This Platform primarily provides AI technology services to adult users. We attach great importance to protecting minors' personal information.
If you are a minor under 18, please read this Policy accompanied by a parent or legal guardian, and use this Platform only with their explicit consent. If you are a child under 14, please complete registration and use services under your guardian's guidance.
We do not actively collect minors' personal information. If we discover that we have collected a minor's information without guardian consent, we will immediately stop processing and delete it. If you are a minor's guardian and believe we may hold your ward's information, please contact us promptly.
VII. Cookies and Similar Technologies
To ensure this Platform's normal operation and continuously optimize user experience, we store small data files such as cookies on your device. Cookies are mainly used to identify session state, record preference settings, and collect visit statistics.
We do not use cookies for any purpose other than those described in this Policy. You can manage or clear cookies through your browser settings. Note that disabling cookies may cause some service features to not function properly.
VIII. Updates and Notifications to this Policy
As our business develops and laws change, we may revise this Policy periodically. Without your explicit consent, we will not reduce the rights you enjoy under this Policy.
For the following major changes, we will notify you through in-platform announcements, pop-ups, or other prominent means:
- Significant changes to the service model (e.g., changes to processing purposes, personal information types, or usage methods);
- Significant changes to ownership structure or control (e.g., mergers, reorganizations);
- Changes to the main parties with whom personal information is shared, transferred, or publicly disclosed;
- Significant changes to how you exercise your personal information rights;
- Changes to the department, contact information, or complaint channels responsible for personal information protection.
IX. Contact Us
If you have any questions, opinions, or suggestions about this Policy, or encounter any issues related to personal information processing that require complaints or reports, please contact us through the following methods. We will respond within 15 business days:
- Online Channel: Log into this Platform and submit your issue at "Personal Center — Tickets — Create Ticket."
- Email: Send an email to the personal information protection officer's dedicated mailbox service@tokenfab.com. Please note that we may not respond to emails unrelated to this Policy or personal information protection.
If you are not satisfied with our handling results, particularly if you believe our personal information processing has infringed your legitimate rights, both parties should first attempt to resolve the matter through friendly negotiation. If negotiation fails, either party may file a lawsuit with the people's court with jurisdiction over the domicile of Shenzhen Xiangyuan Gongfang Technology Co., Ltd. (Shenzhen, Guangdong Province).
The conclusion, effectiveness, performance, interpretation, and dispute resolution of this Policy are governed by the laws of the mainland of the People's Republic of China (excluding the laws of the Hong Kong Special Administrative Region, the Macao Special Administrative Region, and Taiwan, for the purposes of this Policy).
Shenzhen Xiangyuan Gongfang Technology Co., Ltd.
Personal Information Protection Contact Email: service@tokenfab.com
This Policy was last updated on September 18, 2026