Legal

Privacy Policy

DiscTok works with a small, specific set of data: the Discord identity of a member and the TikTok profile they chose to link. This page explains exactly what that means, and how to get it removed.

Last updated October 2, 2026

01Scope of this policy

This Privacy Policy explains what DiscTok collects when you invite the bot, sign in with Discord, or link a TikTok account, and what happens to that data afterwards.

It covers the bot, the website, and the dashboard. It does not cover TikTok, Discord, or Stripe, each of which handles your data under its own privacy policy.

02Data we collect from Discord

When you sign in with Discord, we receive your Discord user ID, username, and avatar, and the list of servers you can manage where the bot is present. We use a session cookie to keep you signed in.

When a member links an account, we store the Discord user ID and the server ID the link belongs to, so roles and profile cards can be applied in the right place.

03Data we collect from TikTok

When a member authorizes a link, TikTok returns an open ID, an access token, a refresh token, and their expiry times. We store these so the link keeps working without asking the member to log in again.

With the approved scopes, we also read the member's display name, username, bio, follower count, total likes, and video count. For announcements, we read the metadata of the member's own public videos: video ID, title, cover image, share link, and creation time.

We do not collect data about accounts a member does not own, and we do not access private messages, watch history, or non-public analytics.

04How we use this data

To verify that a Discord member owns a TikTok account, and to grant the roles the server configured.

To render profile cards and role rules with current statistics, refreshed on the server's plan interval.

To post announcements for a member's own new public videos, only when that member has opted in and the server's plan includes announcements.

To show server administrators usage, billing status, and an audit log of actions such as links, unlinks, and role changes.

05What we never do

We do not scrape TikTok. All TikTok data comes through the official Login Kit and Display API.

We do not sell personal data, and we do not use it for advertising or to build cross-server profiles of members.

We do not post to TikTok, change anything on a member's account, or announce a video they did not opt into.

We do not store payment card details, because payments are handled entirely by Stripe.

06Why we are allowed to process it

For members, processing is based on consent: a member chooses to link an account, chooses which scopes to approve, and chooses whether to opt into announcements. Consent can be withdrawn at any time by unlinking or by revoking access in TikTok's settings.

For server administrators, processing is based on the contract between us (providing the dashboard and the subscription) and on our legitimate interest in operating and securing the service.

For security, fraud prevention, and legal compliance, we process limited data based on our legitimate interests and legal obligations.

07Sharing and service providers

We share data with the platforms needed to run DiscTok: Discord (to grant roles and post announcements), TikTok (to read approved profile and video data), and Stripe (to process subscriptions). Each provider processes data under its own terms.

We may share data if required by law, to protect the service from abuse, or as part of a transfer of the service, in which case this policy continues to apply.

08Retention and deletion

TikTok profile data, statistics, and tokens are kept only while a link is active. When a member unlinks, or when we detect that they revoked DiscTok's access on TikTok (via TikTok's authorization-removed webhook, with a token-refresh check as a fallback), the stored TikTok data for that link is deleted.

Announcement metadata for a member's videos is deleted with the link. Audit log entries are kept without TikTok profile data so server administrators retain a record of actions.

Some records, such as billing records held by Stripe, are retained as long as required for tax and accounting purposes.

09Cookies and sessions

DiscTok sets a session cookie when you sign in with Discord. It is necessary for the dashboard to work, it is not used for advertising, and it is not shared with third parties.

No analytics or advertising cookies are set on the website.

10Your choices and rights

You can unlink a TikTok account at any time with /unlink or from the dashboard, which deletes the associated TikTok data. You can also revoke DiscTok's access from your TikTok account settings.

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to certain processing, or to withdraw consent. Requests can be sent to support@disctok.therealalexv.com.

Server administrators can remove a server's data by removing the bot and contacting us to delete the server's records.

11Age

DiscTok is not intended for anyone below the minimum age required by Discord or TikTok in their country, and never for children under 13. If we learn that a child below that age has linked an account, we will delete the data.

12Security

Tokens are stored server-side and never exposed to the browser or to other members. The website never receives secrets, and only public configuration is sent to the frontend.

Sessions are signed and set with standard protections. Access to the dashboard requires authenticating with Discord and, for a given server, holding the permission to manage it.

13Changes and contact

If this policy changes in a meaningful way, we will update the date on this page. Continued use after an update means you accept the revised policy.

Questions or requests can be sent to support@disctok.therealalexv.com.