Privacy Policy
How TokToolset handles account data, public TikTok lookup data, downloads, exports, credits, payments, support, analytics, and service usage.
Last updated: 2026-09-07
Introduction
This Privacy Policy explains how TokToolset ("TokToolset", "we", or "our") collects, uses, stores, and shares information when you visit toktoolset.com or use our TikTok viewing, research, download, export, account, credit, payment, and support features (collectively, the "Service").
TokToolset is an independent service and is not endorsed by, sponsored by, operated by, or affiliated with TikTok or ByteDance. Use of the Service is also subject to our Terms of Service.
For privacy questions or requests, contact support@toktoolset.com.
Information We Process
The information we process depends on the features you use.
1. Account and Authentication Data
When you create or use a TokToolset account, we may process:
- your name, email address, avatar, language, and basic profile information;
- email verification status, registration date, and registration or referral source, when available;
- password credentials stored in hashed form, verification or reset tokens, and session identifiers;
- account identifiers and authentication tokens returned by providers such as Google or GitHub when you choose one of those sign-in methods; and
- security and request information such as IP address, browser, device, user agent, and timestamps.
TokToolset does not ask for your TikTok password, TikTok session cookie, or TikTok verification code. You do not connect a personal TikTok account to run a lookup. New lookup requests require a TokToolset sign-in so that credits, recent results, security controls, and background tasks can be associated with your TokToolset account.
2. TikTok Lookup Inputs and Public Results
Depending on the tool, we may process:
- a TikTok username, @handle, public profile URL, post URL, supported share link, post ID, comment ID, or reply ID;
- the tool and result category you select, such as stories, posts, reposts, followers, following, account details, profile pictures, photos, videos, comments, or replies;
- pagination values, export selections, requested row limits, file formats, and similar request settings;
- for AI comment analysis, the analysis goal or question you enter, the requested comment scope, and the selected report format;
- public profile and content information returned by supported providers, including usernames, display names, biographies, avatars, verification status, public account statistics, stories, posts, reposts, media, captions, comments, replies, follower or following profiles, and engagement information; and
- request timestamps, result status, cursors, provider identifiers, errors, and credits deducted, reserved, settled, or returned.
Supported share links may be resolved through TikTok domains before a public post is processed.
The Service processes information made publicly available by TikTok or returned as public profile information by a supported provider. It does not bypass private-account settings or recover private, deleted, expired, hidden, moderated, restricted, or otherwise unavailable content. Results may be incomplete, delayed, cached, unavailable, or different from what currently appears on TikTok.
Public TikTok information may still be personal data. You are responsible for using results lawfully and respecting creators, commenters, and other individuals.
3. Downloads, Exports, and Background Tasks
TokToolset may provide individual media downloads, browser-created ZIP or CSV files, background CSV or XLSX exports, AI-generated comment-analysis reports or ZIP packages, and other generated files expressly offered by the Service.
For a background task, we may process and store the source URL or identifier, selected settings, task status, progress, provider cost, credit status, error information, file metadata, and the resulting file. Completed background files use private task storage. After an authenticated ownership check, the download endpoint issues a short-lived signed storage URL. Anyone who receives that signed URL may be able to use it while it remains valid, so do not share it. Authenticated download access to completed files may remain available for up to 7 days and can end earlier; it never continues beyond the recorded task deadline. At that deadline, TokToolset requests permanent deletion from private storage and retries an unconfirmed request; the storage provider may complete physical deletion asynchronously. Operational task records and related metadata may be retained longer for credit settlement, security, support, failure investigation, or dispute handling.
For an AI comment-analysis task, TokToolset may temporarily store the selected public comments, source-post context, your analysis goal, and intermediate model output while the task runs. When a task succeeds, raw task inputs, comment text, usernames, the analysis goal, and intermediate model output are removed from the task records. The completed private download may be a report or a ZIP package containing the selected report and an XLSX file with the collected public comment text and usernames. That download and a limited audit record may remain available for up to 7 days. The task-record cleanup does not remove the public comment text or usernames from the downloadable XLSX before the package expires. The limited audit record can include evidence and comment identifiers with integrity hashes, plus model, provider, generation, token-usage, cost, and workflow-version metadata; it does not retain comment text, usernames, your analysis goal, or model output. When an analysis task reaches a terminal failure, its raw task input, raw processing state, and task-item data are cleared, and any generated report or package object is scheduled for immediate deletion. A limited, content-free failure audit containing model, provider, generation, token-usage, routing, reason-code, and workflow-version metadata may remain for up to 7 days; it does not retain comment text or identifiers, usernames, your analysis goal, prompts, model output, or raw provider error messages. If file deletion cannot be confirmed at once, the failed report or package remains inaccessible, its existing access deadline is not extended, and deletion is retried or completed asynchronously by the storage provider. Separate security and infrastructure logs may be retained as otherwise described in this policy.
A browser-created download is saved to the location selected by your browser or device. TokToolset does not control a file after it has been downloaded.
Downloading or exporting public content does not transfer ownership, copyright, privacy, publicity, or other rights. Rights in TikTok profiles, media, music, comments, and related content remain with their respective owners.
4. Credits, Payments, and Subscriptions
When you receive or use credits, or purchase a plan or credit pack, we may process:
- your credit balance, grants, expiration dates, reservations, consumption, settlement, returns, and source;
- the selected product, price, currency, billing period, order status, and transaction date;
- order, transaction, subscription, invoice, and payment-provider identifiers;
- the email, transaction response, and limited billing information returned by the payment provider; and
- information you provide about billing questions, cancellations, refunds, disputes, or chargebacks.
Payment credentials are submitted through the payment provider shown at checkout. TokToolset receives and stores the business and technical records needed to create and manage the purchase, including relevant provider responses.
5. Support Requests, Profile Images, and Attachments
If you contact support, open or reply to a ticket, update a profile image, or use another enabled upload feature, we may process your name, email address, subject, messages, replies, and files you choose to provide.
Some profile images, support attachments, or other user uploads may use a public storage URL. Anyone who obtains the exact URL may be able to access the file. Do not upload confidential information, sensitive personal data, or content you are not authorized to share. Background-task files use separate private storage as described above.
6. Usage, Device, Security, and Analytics Data
When you visit or use the Service, we may process:
- IP address, browser, device, operating system, visited URL, referring page, and timestamps;
- pages visited, feature usage, clicks, and session activity;
- request-limit, fraud-prevention, and abuse-prevention signals; and
- errors, response times, logs, and diagnostic information.
How We Use Information
We use information described in this policy to:
- create, authenticate, secure, and manage TokToolset accounts;
- validate inputs and run requested public TikTok lookups;
- return results and support pagination, downloads, and exports;
- organize public comments and generate the AI comment-analysis report you request;
- create, process, store, deliver, and expire background-task files;
- calculate, reserve, deduct, settle, grant, expire, and return credits;
- manage orders, payments, subscriptions, cancellations, refunds, and billing support;
- provide support and respond to requests;
- enforce limits and prevent fraud, misuse, duplicate-account abuse, and security threats;
- diagnose errors and improve reliability, accessibility, performance, and user experience;
- measure Service usage through enabled analytics tools;
- send authentication, security, operational, support, and billing messages; and
- maintain records needed for Service operation, security, accounting, dispute handling, and valid legal requests.
What “Anonymous” Means
TokToolset may describe a viewer as anonymous because a lookup does not require or use your personal TikTok password or TikTok session and is not performed through your personal TikTok profile. You do not need to follow the target account or connect your TikTok identity.
“Anonymous” does not mean that TokToolset processes no information about you. Your TokToolset account, IP address, device information, request details, credit activity, and security logs may still be processed as described in this policy. Providers that operate the Service may also process request information under their own policies.
TokToolset does not provide network anonymity, unlock private information, override platform privacy settings, or make an absolute promise about how TikTok or an external provider records, classifies, or reports activity in its own systems.
Ad-Free Service and Analytics
TokToolset is ad-free, meaning the TokToolset interface does not display third-party advertising. Public TikTok content may still contain creator branding, sponsorships, or platform-provided material.
Ad-free does not mean that the Service operates without necessary storage, security, analytics, or support technologies. TokToolset uses Vercel Analytics and may use configured services such as Google Analytics or Plausible to understand traffic and feature usage. Customer-support tools such as Crisp or Tawk.to may also be enabled. Those providers may process usage or device information according to their settings and privacy notices.
We use Microsoft Clarity to understand how visitors use public pages through session recordings, heatmaps, and interaction measurements. Clarity may process browser and device information, page URLs, clicks, scrolling, and page content subject to the configured masking rules. Authentication, account, administration, and payment pages are excluded from Clarity recording. We do not send email addresses or account identifiers to Clarity as custom identifiers. Clarity may use cookies or similar technologies according to its consent settings; we do not automatically grant consent on your behalf. Learn more in the Microsoft Privacy Statement.
We do not sell personal information.
Cookies, Browser Storage, and Result Caches
TokToolset and enabled service providers may use cookies, local storage, session storage, tags, or similar technologies to:
- maintain and protect your TokToolset session;
- remember language, theme, and interface preferences;
- support authentication and enabled third-party sign-in;
- enforce request limits and prevent abuse;
- measure traffic and feature usage;
- enable configured customer-support tools; and
- avoid unnecessary duplicate public-data requests.
Supported public lookup results may be eligible for reuse from the server cache for 10 minutes. Successful, account-scoped lookup results may also be stored in the current browser tab's sessionStorage for 30 minutes. These are cache-validity periods and do not mean that cached data is physically deleted immediately when validity ends or that related request, credit, task, security, or billing records are deleted on the same schedule.
Closing a tab, clearing site data, private-browsing behavior, or browser controls may remove stored results sooner. Blocking cookies or browser storage may prevent authentication, recent-result restoration, or other features from working correctly.
Service Providers and Other Recipients
We share information only when reasonably necessary to operate, secure, and support the Service. Depending on the features and configuration in use, recipients may include:
- TikHub, for supported public TikTok profiles, posts, reposts, followers, following, post details, media information, comments, and replies;
- Apify and the configured TikTok story actor, for supported public story requests;
- OpenRouter and the approved model-endpoint providers selected through it, when you request AI comment analysis;
- TikTok domains and media-delivery infrastructure when resolving supported links or retrieving available public media;
- storage services such as Cloudflare R2 or other S3-compatible providers for uploads and generated files;
- authentication providers such as Google or GitHub when you choose those sign-in methods;
- the payment provider shown during checkout for purchases, subscriptions, taxes, refunds, disputes, and payment records;
- email providers such as Resend or Cloudflare Email when configured;
- analytics providers such as Vercel Analytics, Google Analytics, Microsoft Clarity, or Plausible;
- customer-support providers such as Crisp or Tawk.to when enabled; and
- hosting, database, logging, security, and content-delivery providers.
TikTok, TikHub, Apify, and other providers operate under their own terms and privacy practices. TokToolset does not control their independent systems, retention periods, availability, or policy decisions. Providers may process information in locations different from your own.
AI comment-analysis requests instruct OpenRouter to route only to approved endpoints that support zero-data-retention handling and to deny provider data collection. These request settings do not replace the independent terms, technical behavior, or legal obligations of OpenRouter or the endpoint provider.
We may also disclose information when reasonably necessary to investigate fraud or abuse, protect rights and security, comply with a valid legal request, complete a business transaction with appropriate safeguards, or follow your instructions.
Retention
Retention varies by record type and by operational, security, billing, support, and legal needs. Current practices include:
- Supported public lookup results are eligible for reuse from the server cache for 10 minutes. Expired entries may remain until they are read, evicted, or the server process ends.
- Successful lookup results stored in the current browser tab are valid for 30 minutes.
- Authenticated download access to completed background-task files may remain available for up to 7 days and can end earlier; storage deletion is requested at the recorded deadline and may complete asynchronously.
- A draft server-side snapshot used for the exact “Loaded comments” analysis scope expires after 30 minutes of inactivity and no later than 24 hours after creation if it is not finalized.
- For a successful AI comment analysis, access to the report or ZIP package, including any packaged XLSX with collected public comment text and usernames, and the limited audit record described above are retained for up to 7 days; access then ends and the audit record is scrubbed independently of asynchronous file-storage deletion.
- For an AI comment analysis that reaches a terminal failure, raw task inputs, raw processing state, task-item data, and any failed report or package are cleared as part of failure handling; the content-free failure audit described above is retained for no more than 7 days and is then scrubbed independently of file-storage deletion.
- Account and session records may be retained while the account is active and for a reasonable period afterward for security, support, fraud prevention, and dispute handling.
- Orders, subscriptions, invoices, payment events, and credit transactions may be retained for accounting, billing, contractual, anti-fraud, and claims-handling purposes.
- Lookup inputs, result status, provider metadata, task records, errors, and technical logs may be retained as reasonably needed to operate and protect the Service, resolve failures, and provide support.
- Tickets, messages, and bound attachments may be retained until a request is resolved and for a reasonable support-history period.
- Analytics information is retained according to the applicable provider settings and our configuration.
When information is no longer needed, we may delete, anonymize, or aggregate it. Some records may be retained when needed for security, payment reconciliation, fraud prevention, dispute handling, or a valid legal obligation. Independent providers may apply their own retention periods.
Security
We use reasonable technical and organizational safeguards intended to protect information against unauthorized access, loss, alteration, or improper disclosure. Background-task files are stored separately from public uploads. An authenticated download endpoint checks account ownership before issuing a short-lived signed storage URL.
No internet-connected service can guarantee complete security. Protect your TokToolset credentials, avoid sharing download or attachment links, and contact us if you suspect unauthorized account access.
Your Rights and Choices
Where provided by applicable law, you may request access to, correction of, deletion of, or a copy of personal data associated with you, or ask us to restrict or stop certain processing.
You can update some profile information through your account and clear cookies or site storage through your browser controls. Clearing browser data may sign you out or remove recent cached results.
To make a privacy request, email support@toktoolset.com from the address associated with your account and describe the request. We may ask for additional information to verify your identity and protect other people. Some records may need to be retained for security, billing, fraud prevention, dispute handling, or other valid obligations.
If your request concerns public TikTok information about you, include the relevant username, post, comment, or result so we can identify the material. TokToolset may not control or be able to remove the original information from TikTok or an independent provider.
Changes to This Policy
We may update this Privacy Policy when the Service, providers, or data practices change. We will publish the revised version on this page and update the date shown above. Additional notice may be provided when appropriate.
Contact
For questions, privacy requests, or concerns about this Privacy Policy, email support@toktoolset.com.
