Privacy
Everything we know about you.
It's a short list.
Last reviewed 14 September 2026. This covers the TokrBot site and the bot that reads TikTok mentions.
A person is responsible. The company is still paperwork.
The law calls whoever decides what happens to your data the controller. Somebody is deciding today, so there's a controller today.
- Controller
- The individual who operates TokrBot
- Legal name & address
- Not published yet - appears here when the company is set up
- Contact
- contact@tokrbot.fun
Nothing about how your data is handled changes when the company exists; the rows below are the answer either way.
The short version
Six lines, then the detail.
- There are no accounts to browse the site, and no login to look at tokens. There is nothing to track and we don't try.
- The bot reads public TikTok data only: the comment that tagged it, the commenter's @, and the video's public link, author @ and thumbnail. The same things anyone sees when they tap share.
- A creator gives us two things: their TikTok @, and a wallet address they link with a signature. That's essentially all the personal data we hold.
- No analytics SDK, no advertising identifier, no tracking pixel, and no cookie banner - because there's nothing to put in one.
- Nothing is sold to anyone. There'd be almost nothing to sell: we don't know your name.
- Tokens and payouts are on a public blockchain. Those can't be deleted, by us or anyone - it has its own card below.
Read from TikTok, and only what's public
- The comment that tagged @tokrbot - the text, and the @ of the person who wrote it.
- The video's public address, the @ of the account that posted it, and the thumbnail frame. We mirror that frame to our server and use it as the token's logo, so it doesn't disappear when TikTok's link expires.
All of it is public. We never see anyone's TikTok password, private messages, or anything behind a login - we read videos the same way any viewer can.
From a creator who claims a fee
- Your TikTok @, typed on the creator page.
- Whether the account is verified (we read your public bio for a code - that read touches nothing else).
- The wallet address you link, and the signature that proves it's yours. We never receive your private key or seed.
- A record of payouts sent to that wallet - amount, transaction, and time.
That's the whole of the personal data behind a creator: an @, a wallet address, and a payout history. All three of the last two are already public on the chain.
The list that stays empty
- No account or login to browse. No profile, no password, nothing stored about a visitor.
- No cookies of our own, no local storage we write, no session tracking. Your wallet extension keeps its own state; that's the wallet's, not ours.
- No analytics provider, no advertising network, no advertising identifier, no crash reporter, no fingerprinting script.
- No location, no contacts, no microphone, no photos beyond the video thumbnail that is already public.
What's kept, and until when
Our data lives in plain files on the server, not a tracking database:
- Mentions (the comment, commenter @, video link and author) are kept so the same video isn't minted twice and to enforce the anti-spam limits.
- Tokens (name, ticker, contract, the numbers read from the chain) are kept as long as the token exists.
- Creators (the @, verification state, linked wallet, payout history) are kept so we can pay you and not pay twice.
Everything we hold off-chain can be removed on request (next card is the exception). Server request logs at our host expire on the host's own schedule and aren't used to build a profile of anyone.
Everyone in the path
- DigitalOcean
- Hosting. Every request to the site passes through the server there, which sees IP and headers in the ordinary course of serving the page.
- TikTok
- We fetch the public video page and thumbnail from TikTok's own servers to resolve a mention. That's our request, not yours.
- CoinGecko
- We read the SOL/USD price to show dollar figures. That call carries no data about you.
- Solana
- The RPC and the block explorer are public infrastructure we don't run. Reading a token or a payout there is a request to them.
- Your wallet
- When you connect and sign, that happens in your own wallet software. We receive an address and a signature, never a key.
There is no analytics provider and no ad network in that list because there isn't one. The fonts are served from Google Fonts.
The part we can't delete
A public chain is public, forever, by design. A token and every payout are on Solana: a wallet address, an amount, a token, a time. Anyone can read them. They'll still be readable after the company exists and after it stops existing. No request to us removes them - not because we'd refuse, but because they were never ours to remove.
What's on the chain: addresses, amounts, transactions. What isn't: nothing extra - we don't attach your name to any of it, because we don't have it. The right to erasure works on everything we hold off-chain and stops at the chain.
And how to use them
Write to contact@tokrbot.fun for any of these, and a person answers:
- Access - what we hold linked to your @ or wallet.
- Rectification - fix anything wrong.
- Erasure - remove your @, verification, linked wallet and payout records from our files. It can't touch the chain (see the card above).
- Objection & restriction - ask us to stop or pause using what's in dispute.
- Complain - to the data protection authority where you live, without asking us first.
It changes in public
When something material moves - a new processor, a new field, a longer retention - this page is updated before the change ships, and the date under the headline moves with it.