Privacy Policy
Last updated: January 2025
This service is operated by an independent developer based in the United States.
This service is operated from the United States.
Overview
toran is designed with privacy in mind. We collect the minimum data necessary to provide the Service and give you visibility into your outbound API requests.
toran is read-only by design: we do not retry, cache, block, or modify requests or responses. toran only inspects raw HTTP requests and responses and does not see application-level context such as prompts, model internals, or agent reasoning.
What We Don’t Do
- We do not sell your data or use it for advertising.
- We do not use your requests logs to train models.
- We do not intentionally collect sensitive personal data; you control what you route through toran.
What We Collect
Account Information
When you sign in, we collect your email address. This is used for authentication, account administration, and account-related communications.
Requests Logs
When you route requests through toran, we may log:
- Request method, path, and query parameter names (values are redacted by default)
- Request and response headers
- Response status code
- Request timing and duration
- Request and response body sizes
By default, sensitive headers (Authorization, Cookie, API keys), client identity headers, and query parameter values are excluded or redacted from logs. Body logging is disabled by default. When enabled, toran stores request and response bodies only when they can be decoded as UTF-8 text (best-effort). If a body cannot be decoded as text, toran does not store it and instead stores the body size and a SHA-256 fingerprint.
Some logging controls, including enabling sensitive fields, are only available on paid plans.
On paid plans, you may explicitly opt in to logging certain excluded fields if required for debugging. Use these controls carefully and route only what you intend to inspect.
If you choose to log additional fields (for example, client IP headers such as cf-connecting-ip or x-real-ip), you are responsible for ensuring you have the right to collect and process that data.
Usage Data
We collect basic usage data to operate, secure, and improve the Service, such as request counts, feature usage, and service metrics.
Data Retention
Request logs are retained on a rolling basis according to your subscription plan.
As new requests arrive, older requests may be automatically deleted to remain within applicable limits. toran does not guarantee retention of request data for any specific duration or quantity.
Unclaimed anonymous torans may be deleted after a period of inactivity.
How We Use Your Data
- To provide and operate the Service
- To display your requests logs in the dashboard
- To send account-related emails (magic links, claim emails)
- To improve and develop the Service
- To enforce our Terms of Service
Data Sharing
We do not sell your data. We may share data with:
- Service providers who help operate toran (for example, hosting and email delivery)
- Professional advisors (for example, legal, accounting) when necessary
- Law enforcement or regulators when required by law
Security
We use industry-standard security measures to protect your data, including encryption in transit (HTTPS) and secure infrastructure. However, no system is completely secure, and we cannot guarantee absolute security.
Your Rights
You can delete your torans and associated logs at any time through the dashboard. To request access to, correction of, or deletion of your account information, contact us at support@toran.sh.
Children
toran is not directed to children under the age of 13, and we do not knowingly collect personal information from children.
Cookies
We use cookies for authentication (session tokens) and basic functionality. We do not use tracking or advertising cookies.
Third-Party Services
toran proxies requests to upstream APIs you configure. The data you send through toran is transmitted to those third-party services according to their own privacy policies.
International Data Transfers
If you access toran from outside the United States, your information may be processed in the United States or other locations where our service providers operate.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page with an updated date.
Contact
For questions about this Privacy Policy or privacy-related concerns, contact us at support@toran.sh. Legal notices or formal requests may be sent to legal@toran.sh. Our handling of disputes is described in the Terms of Service.