01Scope of this policy
This Privacy Policy explains what DiscTok collects when you invite the bot, sign in with Discord, or link a TikTok account, and what happens to that data afterwards.
It covers the bot, the website, and the dashboard. It does not cover TikTok, Discord, or Stripe, each of which handles your data under its own privacy policy.
02Data we collect from Discord
When you sign in with Discord, we receive your Discord user ID, username, and avatar, and the list of servers you can manage where the bot is present. We use a session cookie to keep you signed in.
When a member links an account, we store the Discord user ID and the server ID the link belongs to, so roles and profile cards can be applied in the right place.
03Data we collect from TikTok
When a member authorizes a link, TikTok returns an open ID, an access token, a refresh token, and their expiry times. We store these so the link keeps working without asking the member to log in again.
With the approved scopes, we also read the member's display name, username, bio, follower count, total likes, and video count. For announcements, we read the metadata of the member's own public videos: video ID, title, cover image, share link, and creation time.
We do not collect data about accounts a member does not own, and we do not access private messages, watch history, or non-public analytics.
04How we use this data
To verify that a Discord member owns a TikTok account, and to grant the roles the server configured.
To render profile cards and role rules with current statistics, refreshed on the server's plan interval.
To post announcements for a member's own new public videos, only when that member has opted in and the server's plan includes announcements.
To show server administrators usage, billing status, and an audit log of actions such as links, unlinks, and role changes.
05What we never do
We do not scrape TikTok. All TikTok data comes through the official Login Kit and Display API.
We do not sell personal data, and we do not use it for advertising or to build cross-server profiles of members.
We do not post to TikTok, change anything on a member's account, or announce a video they did not opt into.
We do not store payment card details, because payments are handled entirely by Stripe.
06Why we are allowed to process it
For members, processing is based on consent: a member chooses to link an account, chooses which scopes to approve, and chooses whether to opt into announcements. Consent can be withdrawn at any time by unlinking or by revoking access in TikTok's settings.
For server administrators, processing is based on the contract between us (providing the dashboard and the subscription) and on our legitimate interest in operating and securing the service.
For security, fraud prevention, and legal compliance, we process limited data based on our legitimate interests and legal obligations.
08Retention and deletion
TikTok profile data, statistics, and tokens are kept only while a link is active. When a member unlinks, or when we detect that they revoked DiscTok's access on TikTok (via TikTok's authorization-removed webhook, with a token-refresh check as a fallback), the stored TikTok data for that link is deleted.
Announcement metadata for a member's videos is deleted with the link. Audit log entries are kept without TikTok profile data so server administrators retain a record of actions.
Some records, such as billing records held by Stripe, are retained as long as required for tax and accounting purposes.
10Your choices and rights
You can unlink a TikTok account at any time with /unlink or from the dashboard, which deletes the associated TikTok data. You can also revoke DiscTok's access from your TikTok account settings.
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to certain processing, or to withdraw consent. Requests can be sent to support@disctok.therealalexv.com.
Server administrators can remove a server's data by removing the bot and contacting us to delete the server's records.
11Age
DiscTok is not intended for anyone below the minimum age required by Discord or TikTok in their country, and never for children under 13. If we learn that a child below that age has linked an account, we will delete the data.
12Security
Tokens are stored server-side and never exposed to the browser or to other members. The website never receives secrets, and only public configuration is sent to the frontend.
Sessions are signed and set with standard protections. Access to the dashboard requires authenticating with Discord and, for a given server, holding the permission to manage it.
13Changes and contact
If this policy changes in a meaningful way, we will update the date on this page. Continued use after an update means you accept the revised policy.
Questions or requests can be sent to support@disctok.therealalexv.com.