Last updated: 2026-08-14
Website downloader: the TikTok link you submit, and standard request logs (IP address, timestamp, user agent) used only for rate limiting and abuse prevention. Using the website downloader does not create an account or a stored profile.
Website account: your email address, password hash, account settings, creators you choose to monitor, subscription tier and usage counters, password-reset records, and metadata for saved Stories shown in your library. Private LIVE testers may also have LIVE recording metadata.
Payments: if you upgrade, payment is handled entirely by Stripe. We receive your subscription status and tier, not your card details.
To fulfill download requests, run the Story monitoring jobs you enable, enforce plan limits, provide account and password-recovery features, apply rate limits and detect abuse, process billing, and keep the service reliable. Private testers may separately enable LIVE recording jobs. We also keep aggregate daily product counts for a small allowlist of events and outcomes. With your permission, TikVault additionally records a limited first-party funnel using a random identifier so we can understand first landing page, broad source, signup, activation, and payment. We do not use fingerprinting or advertising trackers.
Cloudflare provides the application, network, database, object storage, and recording-container infrastructure. Google processes Google sign-in and provides a verified email address, a stable account identifier, and basic profile information when you choose that sign-in method. TikVault does not store Google access tokens. Stripe processes subscriptions and plan changes. Resend sends password-reset email. Sentry receives sanitized application error and reliability events. External font providers receive ordinary network request information when your browser loads their fonts. We do not sell personal data.
The website uses essential cookies for account sessions and to remember your analytics preference. If you allow analytics, an HttpOnly first-party visitor cookie lasts up to 90 days; only its one-way hash is stored. First touch stores the landing path without its query string, referrer hostname, bounded UTM values, and broad source category. You can change your choice using “Analytics choices” in the footer. Withdrawing expires the visitor cookie and deletes the current unlinked visitor record when it can be identified. IP addresses are used transiently for rate limiting and abuse prevention. Web-font providers may see your IP address as an ordinary side effect of serving those resources.
Your access to a saved Story lasts for your current plan's window — 3 days on Free, 7 days on Starter, 30 days on Pro, and 90 days on Plus — measured from when the Story was captured, and updates automatically if you change plans. Because a Story posted by a creator you track may also be saved on behalf of other customers tracking the same creator, the underlying file may remain in shared storage for up to 90 days (the longest window any current plan allows) even after your own access to it has ended; your ability to view or download it is always governed by your own plan's window, never by how long the file happens to physically exist. Successfully delivered LIVE artifacts are normally retained for 14 days; failed recovery material for 72 hours; and validation-failed or incomplete output is quarantined without customer download access for seven days unless an operator applies a legal or diagnostic hold. Password-reset links expire after 45 minutes; consumed and expired token records are cleaned up. Rate-limit counters are rolling. Watchlists, billing records, and account settings remain while the account exists, subject to legal accounting or dispute-retention duties.
You can ask what account data we hold, correct it, export it, or have it deleted — including your watched-creator list, usage counters, and stored recordings. Use your account settings or contact us. If you're in the EU/UK, this includes rights to access, rectification, erasure, restriction, and data portability under GDPR; you also have the right to lodge a complaint with your local data protection authority.
We process account data to perform the service contract and for legitimate interests such as abuse prevention and service reliability; billing data is processed to administer a paid subscription. Cloudflare, Stripe, Resend, Sentry, and the external font providers operate infrastructure that may process data outside your country of residence and maintain their own transfer safeguards.
TikVault is not directed at children and isn't intended for use by anyone below the minimum age required to use TikTok in their country. We don't knowingly collect data from children.
If this policy changes materially, we'll update the date at the top of this page and provide any notice required by law.
TikVault, operated from Denmark, is the data controller for personal data processed through this website. For privacy questions, data requests, or to exercise your rights, contact support@tiktokvault.com.
Questions about this policy? Contact TikVault.