Product How Tokani works Pricing Deployment Privacy
Private by design

Three promises. Architecturally, not just legally.

Most AI vendors rely on contractual promises you can't verify. Tokani's privacy is enforced by how the engine is built — the things we say we don't do, we can't do.

Promise 01

We never persist your prompts or responses.

Your prompt and response content does not land in our durable storage. Transient processing happens in-memory and is discarded once the request completes.

What we retain is limited to operational metadata — never content.

Promise 02

We never train on your data.

Your traffic is not used to train, fine-tune, or improve any model. Upstream AI providers are contracted under enterprise data-use terms that explicitly exclude your content from training, and we don't sample or retain anything for that purpose ourselves.

This is a commitment, not an opt-out you have to toggle.

Promise 03

Your data never crosses tenant boundaries.

Every record, request, and retained signal is scoped to your tenant at the data layer. This is a structural property of how the service is built — not a configurable setting.

Enterprise customers can additionally run on a single-tenant deployment for physical isolation.

What we do collect

Aggregate operational metadata that lets us prove savings and keep the service healthy: request volume, latency, estimated cost, estimated savings. None of this contains prompt or response content.

For billing and support we additionally retain your account holder email, company name, and the usage metrics above. That's the complete list.

Read the full Privacy Policy › privacy@tokani.ai