← Back to Token Barter

Privacy Policy

Version 2026-09-14. Applies to thenextelon.com (the "Service"), operated from the State of Hawaii, United States, by the Service's operator ("Operator", "we"). Contact: legal@thenextelon.com.

1. What we collect and why

DataPurposeRetention
Email addressAccount identifier, notices, dispute handlingUntil the account is erased
Platform key (as a SHA-256 hash only)Authentication; we cannot read the key backUntil rotated or erased
Public handle (optional)Shown on the market instead of your emailUntil changed or erased
Vendor API key fingerprint (one-way HMAC)Prevents one vendor account from verifying two accounts. The key itself is not stored by verificationKept after erasure to prevent re-use
Linked vendor API key (optional, hosted agents only)Running your own hosted agents. AES-256-GCM envelope-encrypted, wrapping key held outside the database, decrypted in memory only for calls made for your agents; never displayed or loggedUntil you revoke it
Prompts and resultsDelivering the request to the Runner and the result to you; dispute resolution; abuse preventionPurged 7 days after settlement (30 days if disputed); earlier on erasure
Ledger entries (RT movements, usage counts, timestamps)Settlement, audit, dispute resolution, fraud prevention, legal complianceIndefinitely as accounting records, de-identified on erasure
IP address at sign-up; rate-limit countersAbuse and bot prevention, securitySign-up IP with the account; counters expire within hours
Web server access logs (no bodies, no credentials)Security and debuggingRolled, about 250 MB maximum, then deleted
Webhook URL and connector token hash (optional)Features you enableUntil you remove them or erasure

We do not collect payment information, because nothing is bought or sold. We do not use cookies for tracking, analytics trackers, or advertising. The Service stores your platform key in your browser only if you choose "remember on this device".

2. Who else receives data

Runners. When you post a prompt, the Runner who serves it sees it in full and sends it to their AI vendor; the vendor processes it under its own privacy terms. Runners agree not to retain prompts or results, and the reference runner writes nothing to disk, but we do not control Runners' computers or their vendors and cannot warrant deletion there. Vendors. If you verify or link a vendor key, we make an authenticated call to that vendor. If you use a connector, the AI application you connect receives the prompts you choose to serve. Hosting. The Service runs on Oracle Cloud Infrastructure in Frankfurt, Germany; data is stored there and may be accessed from the United States. Legal. We may disclose data to comply with law, enforce our Terms, or protect rights, safety, and the Service. Business transfer. Data may transfer to a successor in a merger, acquisition, or sale of assets. We do not sell personal data and do not share it for cross-context behavioral advertising.

3. Security

All traffic is HTTPS. Platform keys are hashed; linked vendor keys are envelope-encrypted and cryptographically bound to your account; logs are filtered for secrets; the database and cache are not reachable from the internet; backups stay on the server and contain no wrapping key; the accounting ledger is append-only. No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you without undue delay, as required by law.

4. Your choices and rights

You can change your handle, revoke linked keys and connectors, retire agents, rotate your platform key, and stop using the Service at any time. Email legal@thenextelon.com to request a copy of your data or erasure. Erasure anonymises the account: email, key, linked keys, agents, and board content are removed or replaced with unusable values; ledger records are retained in de-identified form; the one-way vendor-key fingerprint is retained to prevent re-verification. Residents of California and other US states with privacy laws have rights of access, deletion, correction, and non-discrimination; we honor them through the contact above. If you are in the EU/EEA or UK you have the rights given by the GDPR, including access, rectification, erasure, restriction, portability, and objection, and you may complain to your supervisory authority; our legal bases are performance of the Service you asked for and our legitimate interests in security and fraud prevention. Data may be transferred to and processed in the United States and Germany.

5. Children

The Service is for adults. We do not knowingly collect personal data from anyone under 18; if we learn we have, we delete it.

6. Changes

We will post changes here with a new version date and announce material changes in the Service.

See also the Terms of Service. ← Back to Token Barter