TokPad

Privacy

Everything we know about you.
It's a short list.

Last reviewed 14 September 2026. This covers the TokPad site and the bot that reads TikTok mentions.

Who is responsible

A person is responsible. The company is still paperwork.

The law calls whoever decides what happens to your data the controller. Somebody is deciding today, so there's a controller today.

Controller
The individual who operates TokPad
Legal name & address
Not published yet - appears here when the company is set up
Contact
contact@tokpad.tools

Nothing about how your data is handled changes when the company exists; the rows below are the answer either way.

The short version

Six lines, then the detail.

  • There are no accounts to browse the site, and no login to look at tokens. There is nothing to track and we don't try.
  • The bot reads public TikTok data only: the comment that tagged it, the commenter's @, and the video's public link, author @ and thumbnail. The same things anyone sees when they tap share.
  • A creator gives us two things: their TikTok @, and a wallet address they link with a signature. That's essentially all the personal data we hold.
  • No analytics SDK, no advertising identifier, no tracking pixel, and no cookie banner - because there's nothing to put in one.
  • Nothing is sold to anyone. There'd be almost nothing to sell: we don't know your name.
  • Tokens and payouts are on a public blockchain. Those can't be deleted, by us or anyone - it has its own card below.
What we collect

Read from TikTok, and only what's public

  • The comment that tagged @trytokpad - the text, and the @ of the person who wrote it.
  • The video's public address, the @ of the account that posted it, and the thumbnail frame. We mirror that frame to our server and use it as the token's logo, so it doesn't disappear when TikTok's link expires.

All of it is public. We never see anyone's TikTok password, private messages, or anything behind a login - we read videos the same way any viewer can.

What we collect

From a creator who claims a fee

  • Your TikTok @, typed on the creator page.
  • Whether the account is verified (we read your public bio for a code - that read touches nothing else).
  • The wallet address you link, and the signature that proves it's yours. We never receive your private key or seed.
  • A record of payouts sent to that wallet - amount, transaction, and time.

That's the whole of the personal data behind a creator: an @, a wallet address, and a payout history. All three of the last two are already public on the chain.

What we don't do

The list that stays empty

  • No account or login to browse. No profile, no password, nothing stored about a visitor.
  • No cookies of our own, no local storage we write, no session tracking. Your wallet extension keeps its own state; that's the wallet's, not ours.
  • No analytics provider, no advertising network, no advertising identifier, no crash reporter, no fingerprinting script.
  • No location, no contacts, no microphone, no photos beyond the video thumbnail that is already public.
How long it lasts

What's kept, and until when

Our data lives in plain files on the server, not a tracking database:

  • Mentions (the comment, commenter @, video link and author) are kept so the same video isn't minted twice and to enforce the anti-spam limits.
  • Tokens (name, ticker, contract, the numbers read from the chain) are kept as long as the token exists.
  • Creators (the @, verification state, linked wallet, payout history) are kept so we can pay you and not pay twice.

Everything we hold off-chain can be removed on request (next card is the exception). Server request logs at our host expire on the host's own schedule and aren't used to build a profile of anyone.

Who else touches it

Everyone in the path

DigitalOcean
Hosting. Every request to the site passes through the server there, which sees IP and headers in the ordinary course of serving the page.
TikTok
We fetch the public video page and thumbnail from TikTok's own servers to resolve a mention. That's our request, not yours.
CoinGecko
We read the SOL/USD price to show dollar figures. That call carries no data about you.
Solana
The RPC and the block explorer are public infrastructure we don't run. Reading a token or a payout there is a request to them.
Your wallet
When you connect and sign, that happens in your own wallet software. We receive an address and a signature, never a key.

There is no analytics provider and no ad network in that list because there isn't one. The fonts are served from Google Fonts.

The wall

The part we can't delete

A public chain is public, forever, by design. A token and every payout are on Solana: a wallet address, an amount, a token, a time. Anyone can read them. They'll still be readable after the company exists and after it stops existing. No request to us removes them - not because we'd refuse, but because they were never ours to remove.

What's on the chain: addresses, amounts, transactions. What isn't: nothing extra - we don't attach your name to any of it, because we don't have it. The right to erasure works on everything we hold off-chain and stops at the chain.

Your rights

And how to use them

Write to contact@tokpad.tools for any of these, and a person answers:

  • Access - what we hold linked to your @ or wallet.
  • Rectification - fix anything wrong.
  • Erasure - remove your @, verification, linked wallet and payout records from our files. It can't touch the chain (see the card above).
  • Objection & restriction - ask us to stop or pause using what's in dispute.
  • Complain - to the data protection authority where you live, without asking us first.
Changes

It changes in public

When something material moves - a new processor, a new field, a longer retention - this page is updated before the change ships, and the date under the headline moves with it.