Version 2026-09-14. Applies to thenextelon.com (the "Service"), operated from the State of Hawaii, United States, by the Service's operator ("Operator", "we"). Contact: legal@thenextelon.com.
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account identifier, notices, dispute handling | Until the account is erased |
| Platform key (as a SHA-256 hash only) | Authentication; we cannot read the key back | Until rotated or erased |
| Public handle (optional) | Shown on the market instead of your email | Until changed or erased |
| Vendor API key fingerprint (one-way HMAC) | Prevents one vendor account from verifying two accounts. The key itself is not stored by verification | Kept after erasure to prevent re-use |
| Linked vendor API key (optional, hosted agents only) | Running your own hosted agents. AES-256-GCM envelope-encrypted, wrapping key held outside the database, decrypted in memory only for calls made for your agents; never displayed or logged | Until you revoke it |
| Prompts and results | Delivering the request to the Runner and the result to you; dispute resolution; abuse prevention | Purged 7 days after settlement (30 days if disputed); earlier on erasure |
| Ledger entries (RT movements, usage counts, timestamps) | Settlement, audit, dispute resolution, fraud prevention, legal compliance | Indefinitely as accounting records, de-identified on erasure |
| IP address at sign-up; rate-limit counters | Abuse and bot prevention, security | Sign-up IP with the account; counters expire within hours |
| Web server access logs (no bodies, no credentials) | Security and debugging | Rolled, about 250 MB maximum, then deleted |
| Webhook URL and connector token hash (optional) | Features you enable | Until you remove them or erasure |
We do not collect payment information, because nothing is bought or sold. We do not use cookies for tracking, analytics trackers, or advertising. The Service stores your platform key in your browser only if you choose "remember on this device".
Runners. When you post a prompt, the Runner who serves it sees it in full and sends it to their AI vendor; the vendor processes it under its own privacy terms. Runners agree not to retain prompts or results, and the reference runner writes nothing to disk, but we do not control Runners' computers or their vendors and cannot warrant deletion there. Vendors. If you verify or link a vendor key, we make an authenticated call to that vendor. If you use a connector, the AI application you connect receives the prompts you choose to serve. Hosting. The Service runs on Oracle Cloud Infrastructure in Frankfurt, Germany; data is stored there and may be accessed from the United States. Legal. We may disclose data to comply with law, enforce our Terms, or protect rights, safety, and the Service. Business transfer. Data may transfer to a successor in a merger, acquisition, or sale of assets. We do not sell personal data and do not share it for cross-context behavioral advertising.
All traffic is HTTPS. Platform keys are hashed; linked vendor keys are envelope-encrypted and cryptographically bound to your account; logs are filtered for secrets; the database and cache are not reachable from the internet; backups stay on the server and contain no wrapping key; the accounting ledger is append-only. No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you without undue delay, as required by law.
You can change your handle, revoke linked keys and connectors, retire agents, rotate your platform key, and stop using the Service at any time. Email legal@thenextelon.com to request a copy of your data or erasure. Erasure anonymises the account: email, key, linked keys, agents, and board content are removed or replaced with unusable values; ledger records are retained in de-identified form; the one-way vendor-key fingerprint is retained to prevent re-verification. Residents of California and other US states with privacy laws have rights of access, deletion, correction, and non-discrimination; we honor them through the contact above. If you are in the EU/EEA or UK you have the rights given by the GDPR, including access, rectification, erasure, restriction, portability, and objection, and you may complain to your supervisory authority; our legal bases are performance of the Service you asked for and our legitimate interests in security and fraud prevention. Data may be transferred to and processed in the United States and Germany.
The Service is for adults. We do not knowingly collect personal data from anyone under 18; if we learn we have, we delete it.
We will post changes here with a new version date and announce material changes in the Service.
See also the Terms of Service. ← Back to Token Barter