Browser Extension Privacy Policy

Applies to the TikTap browser extension · Last updated: August 18, 2026

This policy covers the TikTap browser extension only. The tiktap.app website is covered by a separate policy; unlike the website, the extension shows no ads and loads no advertising or analytics SDKs of any kind.

No Account, No Credentials

The extension has no sign-up and no login. It never reads, stores, or transmits your TikTok password, session cookies, or any other credential. Everything it does on a TikTok page runs locally in your own browser, under your own already-signed-in session — the same as if you clicked through the pages yourself.

What We Collect

On first install the extension generates a random identifier (for example x8f2k9d1m4) and stores it in your browser. It is not derived from your device, your browser, your IP address, or any TikTok account — it is a random string, and it is the only thing that ties one install's events together.

Alongside that identifier we record anonymous usage events: which feature was used and how it went. Concretely, these are event names such as backup_start or export_done, plus non-identifying counters like how many items a job contained, how many failed, and how long it took. We use them to find broken features and to see which parts of the product are worth improving.

The same random identifier is attached to the uninstall URL, so we can count uninstalls. No other data is sent at that point.

What We Never Collect

  • Your browsing history, or any page you visit outside of tiktok.com.
  • The content of the videos, photos, or audio you back up — those are written directly to your own Downloads folder and never pass through our servers as stored files.
  • Your TikTok username, profile, follower list, messages, or the identity of anyone whose posts you interact with.
  • Keystrokes, form input, page text, or screenshots.
  • Anything at all on non-TikTok sites — the extension is not injected there.

We do not sell your data, do not share it with data brokers, and do not use it for advertising, credit assessment, or lending. We do not use it for any purpose unrelated to the extension's single purpose of backing up and exporting your own TikTok content.

Why Each Permission Is Needed

  • downloads — to write the videos, audio, and images you choose to back up into your local Downloads folder. It is used for nothing else; the extension does not read or search your existing download history for its own purposes.
  • storage — to keep local state inside your browser: your preferences, the progress of a running backup job so it can resume after an interruption, and the random identifier described above.
  • Access to tiktok.com — to detect posts on the page and add the backup controls to TikTok's interface. The extension requests no access to any other site.

Servers We Contact

  • Our own API (Cloudflare Workers) — receives the anonymous events above, checks how much backup quota an install has left, and issues checkout links. It also relays media requests that TikTok's servers refuse to answer directly from a browser extension; those requests carry the media address only, never your identity.
  • Creem — our payment processor, used only if you choose to buy a credit pack. Payment is completed on Creem's own hosted checkout page. We never see or store your card number; we receive only the confirmation needed to add credits to your install.
  • Cloudflare — hosting and content delivery for the above.

The extension loads no remote code. It contains no third-party analytics SDK, no advertising library, and no externally hosted script — in line with Chrome's Manifest V3 requirements.

Retention and Deletion

Usage events are retained for up to 24 months and then deleted. Because everything is keyed to a random identifier, the fastest way to erase your own trail is to uninstall the extension or clear its browser storage — the identifier is gone at that point and cannot be regenerated.

If you want the events already recorded for your identifier removed, email support@tiktap.app with the identifier shown in the extension popup and we'll delete them within 30 days.

Your Rights (GDPR / CCPA)

If you're in the European Economic Area or the UK, you have the right to access, correct, or delete data associated with you, and to object to processing. If you're a California resident, you have rights under the CCPA/CPRA — note that we do not "sell" or "share" personal information as those terms are defined there. To exercise any of these rights, email support@tiktap.app.

Children

The extension is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes materially, we'll update the date at the top of this page and, where the change affects what we collect, note it in the extension's release notes.