Privacy Policy
Last updated
TikPlay is a desktop app for TikTok LIVE streamers, and tikplay.app is the small website that sells a licence for it. This policy covers both. It says what we hold about you, why we are allowed to hold it, who else can see it, how long it stays, and how to make us stop.
The short version: almost nothing about your broadcast reaches us. Chat, gifts, viewer records and translation are all processed on your own computer and are never sent to us. This site runs no analytics of any kind — no Google Analytics, no tag manager, no advertising pixel, no third-party fonts — and sets no cookie at all until you sign in or start a purchase. What we do hold is what a paid licence needs: your email address, a random identifier for the installation the licence runs on, and the check-ins that keep it alive.
It is written to be read. Where something is awkward — a default that keeps more than you might expect, a log that knows roughly where your computer was — it is written down plainly rather than buried in a clause.
Who is responsible for your data
The company below decides what is collected and why, and is the controller for everything described in this policy.
- EGO HERO LLC — a limited liability company registered in Wyoming, United States
- 5830 East 2nd Street, Ste 7000 # 31990, Casper, WY 82609, United States
- privacy@tikplay.app
That address reaches a person, not a queue, and it is the address for every request in this policy: to see what we hold, to correct it, to delete it, to object to something, or to complain. There is no separate privacy form to fill in.
We have not appointed a representative in the EU under Article 27 GDPR, or in the UK under Article 27 UK GDPR. There is no local address to write to instead of ours: write to privacy@tikplay.app and the answer comes from us directly. You can also complain to your own supervisory authority, and the list is further down this page.
What stays on your computer
TikPlay connects to your TikTok LIVE from your own machine. Chat messages, viewer names and ids, gift records, likes, follows and everything the overlays draw are handled there and written to a database file in your own user folder. None of it is sent to us. There is no account for your stream, no server of ours between you and your viewers, and no copy of your broadcast anywhere we can reach.
Translation works the same way. The language packs are downloaded to your machine and the translation runs on your own CPU, so the text of a chat message never leaves your computer — not to us, and not to a translation service.
Please read this one. Recording is ON by default, and by default it keeps everything, forever. Out of the box TikPlay writes every event of every broadcast — each chat message with the viewer name and id behind it, every gift, every join — to a database in your TikPlay user folder, and deletes none of it. The gift tracker additionally keeps per-day totals for named viewers, including how much each one spent, and those tables survive the other clean-ups on purpose. All of it is on your disk and none of it is on ours, which also means the choice, and the responsibility to the people in your chat, is yours.
You can change it. In TikPlay settings, turn "Record live events" off to stop writing the archive, switch retention to "Capped — 30 sessions · 200k events" to keep only the recent window, or press "Delete raw data" to drop the untyped payloads. To remove the rest, delete the files in the TikPlay user folder — they are ordinary files and the app will carry on without them.
One consequence worth naming: that archive is about other people. In many countries, keeping it makes you — not us — the one responsible for your viewers data, with your own duty to have a reason for keeping it and to answer a viewer who asks about it. We cannot answer such a request on your behalf, because we do not have the data. If a viewer asks you to remove their messages, the files are yours to edit or delete.
What we collect, and where it comes from
Nothing here is collected in the background. Each item below belongs to a moment you can point at.
- When you open the site. Our host receives the request the way any web server does: your IP address, your browser identification, the page you asked for and the page you came from. We add nothing to that — no analytics, no tag manager, no advertising or social pixel, no session recording, no A/B tooling, no third-party fonts and no embeds. The front page loads nothing from anybody else at all.
- When you buy. Card details are typed into the checkout page Stripe hosts, and they never reach us — we do not see, receive or store a card number. After a successful payment Stripe tells us the email address you used, the reference of the checkout session, and the Stripe customer and subscription ids. That is where your email address comes from: you gave it to Stripe, and Stripe passed it to us so we could send you a licence code.
- When you create an account on this site. A sign-in link goes to the email address you type, and that address is sent from your browser straight to our authentication provider. If you choose "Continue with Google" instead, Google identifies you to us, and our provider stores what Google returns: your Google account id, email address, whether it is verified, your name as Google holds it, your profile picture and your locale — even though this site only ever reads the id and the email. You can also set a display name and a preferred language; both are optional. Sign-in sessions record the IP address and browser they were started from.
- When you activate a licence in the app. The app sends your licence code once, together with a random identifier it generated for that installation. The identifier is a random value, not a fingerprint of your machine: nothing about your hardware is read — no MAC address, no disk serial, no machine id, no processor id. We store only a one-way hash of the licence code, never the code itself, which is also why a licence email that never arrives can be replaced with a new code but can never be re-sent.
- While a paid licence is running. The app checks in every ten minutes and sends two things: the hash of the licence code and that installation identifier. Our server records more than the app sends — the IP address the check-in arrived from and the two-letter country our host derives from it. The next section explains that in full. Free installs never check in, and neither do founder codes.
- When you write to support from inside the app. We receive the category, the star rating, the title and up to 10,000 characters of whatever you typed, plus your app version, the installation identifier and the licence code hash. It is not an anonymous channel: we look your email address up from that hash so we can reply to you, and your message is forwarded to our support mailbox with that address as the reply-to. Please do not paste passwords or licence codes into it, and remember that anything you quote about a viewer is that viewer personal data too.
And what we do not collect, which is most of it: no crash reports, no usage statistics, no "the app started" ping, no list of the overlays you use, no chat, no viewer data, no screenshots. We genuinely do not know how you use TikPlay, and the app carries no code that would tell us.
Why we hold it, and what allows us to
Each row is a separate purpose with its own basis in law. We do not use data collected for one of these for another one without telling you.
| What we do | What it uses | What allows us to |
|---|---|---|
| Sell a licence and deliver the code | Email address, purchase reference, Stripe customer and subscription ids | Performing our contract with you (GDPR Art. 6(1)(b); PIPA Art. 15(1)4) |
| Keep the licence working on your machine | Licence code hash, installation identifier, seat record, the signed token we issue back | Performing our contract with you (Art. 6(1)(b)) |
| Your account on this site | Email address, sign-in session, display name and language if you set them | Performing our contract with you (Art. 6(1)(b)) |
| Answer support and feedback | Everything in your message, your app version and installation identifier, and the licence email we look up to reply | Performing our contract with you, and our legitimate interest in fixing what is broken (Art. 6(1)(b) and 6(1)(f)) |
| Stop one paid licence being shared or resold | Check-in IP address and country, installation identifiers, the timing of check-ins | Our legitimate interest in preventing licence fraud and keeping the licensing service secure (Art. 6(1)(f)) |
| Keep the site and the licence service standing up | Server logs, and IP addresses held in memory for an hour to count requests against a rate limit | Our legitimate interest in network and information security (Art. 6(1)(f)) |
| Keep the records the law requires | Purchase and payment records | A legal obligation we are under (Art. 6(1)(c); Korea, Act on Consumer Protection in Electronic Commerce Art. 6) |
Where the basis is legitimate interests, the interest is named in the row rather than left as a phrase. We have weighed it against your interests in writing, and we will send you that assessment if you ask. You can object to any of it — see Your rights.
Do you have to give us any of this? An email address is required to buy a licence — without one there is nowhere to send the code. The installation identifier and the ten-minute check-in are required for a paid licence to keep working; without them the app falls back to the free version, which is the whole app minus the Pro features. A display name is optional. Nothing about your broadcast is ever required, because we never ask for it.
The licence check-in, in full
A paid licence checks in with our server every ten minutes for as long as TikPlay is open. The app sends the hash of your licence code and the random installation identifier, and nothing else — not your TikTok handle, not your email address, not your operating system, not a version number, and nothing at all about your broadcast.
Our server records more than the app sends. Every check-in appends a row holding the licence, the installation identifier, the IP address the request came from, the two-letter country code our host derives from that address, and the time. At one row every ten minutes that is roughly 144 rows a day per machine, and read together they are a rough picture of where a machine has been. We would rather write that sentence ourselves than have you work it out.
Why we keep it: it is how one buyer with two computers is told apart from a code posted in a forum. The signals are the number of distinct installations, the range of IP addresses, the countries, and check-ins from two places too far apart to be the same person on the same day. The basis is our legitimate interest in preventing licence fraud and keeping the licensing service secure — not consent, because the check-in is not optional for a paid licence and a consent you cannot refuse would not be a real one.
How long we keep it: 90 days. A job runs every night and deletes every check-in row older than that. This is a real deletion with a real mechanism behind it, not a promise to review — and if that job is ever switched off, this sentence has to change with it. The seat record keeps only the most recent IP address, overwritten on each check-in, for as long as the licence exists.
You can object to this. Because the check-in is also how the app learns that the licence is still valid, we cannot both keep a paid licence running and stop calling home — so the honest answer is not "we will switch it off". What we can do, and will consider seriously if you write to us, is stop storing the IP address and country for your licence while keeping the check-in itself. Ask, and you will get a decision from a person with a reason attached, not a form letter.
Free installs never do any of this. Neither do founder codes, which are verified entirely on your own computer and never touch the network at all.
Decisions made automatically
Some answers from the licence server are automatic, and each one has a fixed rule rather than a score behind it: activating one machine more than your licence allows is refused and the machine already holding the seat keeps it; a subscription Stripe reports as unpaid is suspended; a purchase Stripe reports as fully refunded is revoked. A chargeback has the same result but we apply it by hand. All of them are reversible — fix the payment, or release the old machine from your account page.
There is also a flag for a licence we suspect is being shared. Today that flag is set by a person looking at the check-in trail described above — there is no scoring model in the product. Its effect, however, is automatic: a flagged licence receives a signed token that lasts six hours instead of thirty days, so the app has to re-check far more often, and Pro features can stop within hours of our server declining to renew it.
We spell this out because it can take away something you paid for. If it happens to you, write to support@tikplay.app. You are entitled to have a person look at it, to be told what the check-in record actually showed, to give your side of it, and to contest the outcome. Your app keeps working as the free version throughout, and a suspension never touches your recordings, overlays, boards or settings — those are on your disk and we cannot reach them.
We do not profile you for anything else. Nothing you send us is used to build a picture of you as a person, to score you, or to decide what you are shown.
Who else can see it
These are the companies that handle part of this for us. It is the whole list, by name.
| Who | What they do for us | Where |
|---|---|---|
| Stripe | Takes the payment, holds the card details we never see, and tells us the email and reference behind a completed purchase. Stripe also decides for itself how it uses payment and fraud data, under its own privacy policy. | United States, Ireland |
| Supabase | Runs the database that holds everything described above, the sign-in for the account area, and the sending of the sign-in link emails. | Database in Seoul, South Korea |
| Vercel | Hosts the website and the licence endpoints. Every request passes through its servers, which keep ordinary web-server logs. | United States, global edge |
| Resend | Sends the licence-code email and forwards support messages to our mailbox. | United States |
| Hostinger | Hosts the support@tikplay.app and privacy@tikplay.app mailboxes, where your messages and our replies are stored. | Hostinger own data centres |
| Cloudflare | Serves the installer downloads and the update files from updates.tikplay.app. | Global |
| Only if you choose "Continue with Google": Google identifies you to us and returns your account id, email address and basic profile. Google decides for itself how it uses what it collects, under its own privacy policy. | United States |
We do not sell personal data, we do not rent it, and we do not share it for advertising — there is no advertising or analytics network anywhere in this product. Each company above is bound by a contract that lets it use the data only to do the job we hired it for, except Stripe and Google, which act on their own account for what they collect directly and have their own policies you should read.
A note about logs, since it is the kind of thing that is usually left out. Our host keeps ordinary request logs, including IP addresses, under its own schedule, and we do not copy them into our database. Our own error lines carry identifiers only, with one exception worth naming: when a payment arrives without a usable email address, the line we log includes the address the payment provider sent, because that is how we find the buyer and get them their licence.
What the app on your computer connects to
These connections are made by the app on your machine, not by us, and mostly to services that are not ours. You are entitled to the list.
- TikTok — to find your live and receive its events. TikTok sees your IP address and the handle you are connecting to. This one is unavoidable: it is where the broadcast is. The app identifies itself with a randomly generated device value and a stand-in browser profile rather than your real browser, screen size or timezone. If you paste your own TikTok session cookie into settings, it is encrypted on your disk, sent only to TikTok, and deliberately withheld from every other service.
- Euler Stream — the live socket has to be signed by a third party before TikTok will open it, and there is no route around that. Euler sees your IP address, the room being connected to, and which operating system family you are on. Your TikTok session cookie is not sent to it: the app blocks that path on purpose. If you add your own Euler key for higher limits, the request is attributed to your Euler account instead of being anonymous.
- Google Fonts — when the app starts, it downloads the font library the overlays offer (about sixty families, once, then never again). The requests carry no cookie, no identifier and nothing you typed; Google sees your IP address and which families were fetched. Afterwards the fonts are served from your own machine, so the overlay pages your viewers see never contact Google. The app window also uses the browser engine built-in spellchecker, which on Windows can fetch a dictionary for your system language from Google the first time you type into a text box — what you type stays on your computer either way.
- Our update server — about twenty seconds after launch the app asks updates.tikplay.app whether a newer version exists. It sends nothing about you: no licence, no installation identifier, not even the version you are running — the comparison happens on your computer after the file arrives. Downloading an update is always a button you press, never automatic. You can turn the check off in settings.
- Only when you ask for them: Openverse, when you search for an alert sound (the words you type are the query); Hugging Face, if you download the optional local AI model; Mozilla, when you install a translation language pack (Mozilla learns which pair you installed); and TikTok image servers, which the overlay pages load gift artwork and viewer avatars from directly.
Where in the world your data is
Our database is in Seoul, South Korea. The payment, email and hosting providers are in the United States. Nobody would guess that from a .app domain, so here is each leg and what covers it.
| Route | What covers it |
|---|---|
| From the EU/EEA to our database in South Korea | The European Commission has decided that the Republic of Korea provides an adequate level of protection (Implementing Decision (EU) 2022/254, reviewed and confirmed in 2026). No additional safeguard is needed. For data that reaches us this way we also follow the decision Supplementary Rules: we use it only for the purposes named in this policy, we do not pass it on to a further country without equivalent protection, and you may exercise your rights with us and complain to Korea Personal Information Protection Commission as well as to your own authority. |
| From the United Kingdom to South Korea | The UK adequacy regulations for the Republic of Korea, in force since 19 December 2022. This is a separate instrument from the EU one. |
| To the United States — Stripe, Vercel, Resend, Cloudflare, Google | The EU-US Data Privacy Framework where the company is certified under it, and otherwise the European Commission Standard Contractual Clauses, with the UK Addendum or the International Data Transfer Agreement for transfers from the UK. Ask us and we will send you the clauses. |
| Onward, from our database in South Korea to those US providers | Korea adequacy decision covers Europe to Korea and nothing else, so it does not carry this leg. These transfers rest on the contracts described above, and for our Korean users on the disclosure in this policy under PIPA Art. 28-8 — the items, countries, recipients, purposes and retention are in the tables above and below. |
You can refuse the transfer of your data outside your own country. We would rather say plainly what that means than bury it: payment, licence delivery and email all run through the companies above, so if you refuse we cannot sell you a paid licence or keep an existing one running. The free version is unaffected and stays entirely on your own computer. Write to privacy@tikplay.app to refuse.
How long we keep it
| What | How long |
|---|---|
| Licence record — email address, licence code hash, plan, status, payment references | For as long as the licence exists. A refund does not delete it: a refunded licence has to stay recognisable so it cannot simply be activated again. |
| Purchase and payment records | 5 years, because consumer protection law requires it of a seller. Records of complaints and disputes, 3 years. |
| Seat record — installation identifier, first and last check-in, the most recent IP address | For as long as the licence exists. Releasing a machine marks the seat released rather than deleting it, so that the limit of three transfers in thirty days can be counted honestly. |
| Check-in log — IP address, country, installation, time | 90 days, then deleted by a job that runs every night. |
| Payment events we have already processed (identifier and type only, never the contents) | 30 days, deleted by the same nightly job. |
| Support and feedback messages | For as long as the licence they came from exists — a support conversation is something both sides may need to look back at, and unlike the check-in log it is not on an automatic timer. Ask us to delete a message and we will. |
| Account — email address, display name, language, sign-in sessions | Until you ask us to close the account. A session lasts until you sign out. |
| The language you picked, in your browser | Until you clear your browser storage. It never leaves your browser. |
| Your recordings, overlays, boards and settings | On your own computer, for exactly as long as you keep them. We hold no copy and cannot delete them for you. |
When a period runs out or the purpose is finished, the data is deleted without delay — records from the database, files by overwriting. Anything a law obliges us to keep is kept apart from the live data and used for nothing else.
Your rights, and how to use them
Write to privacy@tikplay.app from the address you bought with, and say what you want. There is no form. We answer within one month and it costs nothing; if a request is genuinely complicated we may take up to two months more, and we will tell you why inside the first month rather than going quiet.
- See what we hold about you, and get a copy of it.
- Correct anything that is wrong.
- Have it deleted, or have us stop using it while a disagreement is sorted out.
- Object to anything we do on the basis of legitimate interests — in this product that means the check-in logging described above.
- Receive the data you gave us in a portable file, or have us send it to somebody else.
- Withdraw a consent you gave. Today we ask for no consent at all — we send no marketing email of any kind, and every purpose in the table above runs on contract, legal obligation or legitimate interests. If we ever add something that needs your consent, we will ask for it plainly, and withdrawing it will be as easy as giving it.
- Have a person review an automated decision, hear the reasoning, and contest it.
What we cannot delete on request: the purchase and payment records the law makes us keep, and the minimum needed to keep a refunded or revoked licence recognisable so it cannot be activated again. If that applies to your request we will tell you exactly what was kept and why, rather than answering with a clause number.
We may ask you to confirm that you control the email address on the licence. That is not an obstacle course — "delete this licence" arriving from a stranger is exactly the message an attacker sends.
You can also complain to a regulator, and you do not have to tell us first — though we would rather you did. In Korea, the Personal Information Protection Commission (privacy.go.kr, 118). In the EU or EEA, your national data protection authority; the list is at edpb.europa.eu. In the UK, the Information Commissioner Office (ico.org.uk). In Japan, the Personal Information Protection Commission (ppc.go.jp).
Cookies and browser storage
There is no cookie banner on this site because there is nothing here for you to accept or reject. We set no cookie at all until you sign in or start a purchase, and we run no analytics or advertising technology of any kind. Here is the complete list.
| What | What it does | How long |
|---|---|---|
| tikplay.notice — browser local storage | Remembers that you have already seen the short storage notice, so it appears once instead of on every page. Written only when you dismiss it; reading this page never writes it. | Until you clear your browser storage |
| tikplay.lang — browser local storage | Remembers the language you picked with the switcher at the bottom of the page. It is written only when you actually choose one, never on a plain visit, and it never leaves your browser. | Until you clear your browser storage |
| sb-<project-ref>-auth-token — the sign-in cookie, set only on the account pages | Keeps you signed in to your account so the page can show your licences. | Refreshed while you are signed in; removed when you sign out |
| sb-<project-ref>-auth-token-code-verifier — the sign-in link cookie | A one-use value that ties the browser which asked for a sign-in link to the browser that opens it, so the link cannot be used from anywhere else. | Removed the moment you finish signing in |
Both cookies are there to sign you in, and the language key is a preference you set yourself, so under the ePrivacy rules none of them needs your consent. You can remove them in your browser settings, and signing out removes the session cookie. If we ever add anything that is not on this list, we will ask you first.
Stripe and Google set their own cookies on their own pages when you are sent there to pay or to sign in with Google. Those are theirs and their policies apply; we cannot set or read them.
How it is protected
Your licence code is stored only as a one-way hash, so a stolen copy of our database yields no working codes. Card details never reach our servers. Everything travels over encrypted connections. The database refuses access by default — the tables are closed to the public key entirely, and only the server functions that need a key hold one.
On your own computer: the TikTok session cookie, if you choose to paste one in, and your licence file are sealed with your operating system key store, and the licence file is written so that only your user account can read it.
One thing worth knowing, because streamers show their screens for a living: the signed licence file stored on your computer contains the email address the licence was bought with. Anyone with access to that machine could read it out. It is not a folder to open on stream.
No system is perfect. If personal data is ever exposed, we will notify the regulators and, where the risk to you is real, notify you — within the deadlines the law sets rather than a shorter one we might not meet.
Age
TikPlay is for adults. TikTok LIVE itself is limited to adults, and we do not offer this service to anyone under 18. We do not knowingly collect personal data from children, and we have no children accounts to speak of because we ask nothing of anyone who is not buying a licence. In Korea, we do not process the data of anyone under 14 in any circumstances.
If you believe a child has given us personal data, write to privacy@tikplay.app and we will destroy it without delay.
For users in Korea
This policy is our privacy policy under Article 30 of the Personal Information Protection Act. The purposes, the items processed, the retention periods, the companies we entrust work to and the overseas transfers are in the sections above; the items below are the ones the Act asks us to state here.
- Privacy officer: the representative of EGO HERO LLC. Contact: privacy@tikplay.app.
- Access, correction, deletion and suspension of processing can be requested at that address, by you or by a legal representative or agent. We answer a request to see your data within 10 days.
- Personal data is destroyed without delay once its purpose is achieved or its period expires — database records deleted, files overwritten. Records a law requires us to keep are stored separately from live data.
- We do not collect sensitive information or resident registration numbers, we create no pseudonymised data sets, and we provide personal data to no third party for its own purposes beyond the companies named above.
- For help beyond us: Personal Information Dispute Mediation Committee 1833-6972, Privacy Infringement Report Centre 118, Supreme Prosecutors Office 1301, National Police Agency 182.
For users in Japan
- The business handling your personal information is EGO HERO LLC, 5830 East 2nd Street, Ste 7000 # 31990, Casper, WY 82609, United States. The purposes of use are the ones listed in the purpose table above, and we use your data for nothing else.
- Requests to disclose, correct, add to, delete, or stop the use of your retained personal data go to privacy@tikplay.app. There is no fee, and we reply within one month.
- Complaints go to the same address. Where you would rather not write to us, the Personal Information Protection Commission is at ppc.go.jp. We belong to no accredited personal information protection organisation.
- Where the data is handled: our database is on servers in the Republic of Korea, and the payment, hosting, email and download providers named above are in the United States. We have taken the personal information protection regime of each of those countries into account in the measures described in "How it is protected", and our contracts with those companies require handling equivalent to what Japanese law asks of us. We will tell you what those measures are if you ask.
When this changes
This policy changes when the product changes, and the date at the top says when it last did. If a change matters to you — a new company handling your data, a new purpose, a different retention period — we will say so here in plain words rather than quietly moving the date, and where the law requires it we will tell you before it takes effect.
This policy is published in English, Korean and Japanese, and the three say the same thing. If they ever differ, the reading most favourable to you is the one that counts.
Questions about any of it: privacy@tikplay.app.