Legal

Privacy Policy

Placeholder — not final legal copy. This document is a structured draft pending review by legal counsel before commercial launch. Do not rely on it as ratified terms.

This policy describes what data Toktik processes about account holders and about the public TikTok activity it observes, and the choices available.

1. Account data

When you sign in we process your email, workspace and authentication identifiers to operate your account, meter usage and secure access. API keys are stored hashed; only a prefix is ever displayed.

2. Observed public data

Toktik processes persisted observations of public TikTok LIVE activity within its stated Coverage Set. Public availability does not remove privacy duties: observed creator data may still be personal data under laws such as GDPR or CCPA.

Every result carries provenance (source, observed-at, freshness, coverage status) so its basis is traceable.

3. Retention & suppression

Retained LIVE history is bounded by a hard retention cap, including on enterprise plans — it is not kept indefinitely. A recorded creator opt-out or deletion request triggers durable suppression that removes retained history and prevents re-collection.

There is no public self-service removal endpoint yet; suppression is operator-administered today. A public request channel will be published before commercial launch.

4. Sharing & processors

We use a merchant-of-record for payments (card data never reaches us) and standard infrastructure processors. We do not sell account data.

5. Your choices

You may access, correct or delete your account data. Creators may request suppression of observed data via the channel described in the methodology.

6. Changes

This policy will be finalized by legal counsel before commercial launch. Material changes will be communicated in-product.