Privacy

Everything we know about you. It's a short list.

Last reviewed 8 October 2026. This covers the TokrPAD site and the bot that reads TikTok mentions.

The short version

  • No account is needed to browse the site or look at coins.
  • The bot reads public TikTok data only: the comment that tagged it, the commenter's @, and the video's public link, author @ and thumbnail.
  • A creator gives us two things: their TikTok @, and a wallet address they link with a signature. That's essentially all the personal data we hold.
  • No analytics, no advertising identifier, no tracking pixel, no cookie banner.
  • Nothing is sold to anyone. We don't know your name.
  • Coins, payouts and burns are on a public blockchain and can't be deleted, by us or anyone.
Who is responsible

A person is responsible. The company is still paperwork.

Controller
The individual who operates TokrPAD
Legal name and address
Not published yet; appears here when the company is set up
Contact
contact@tokrpad.fun

Nothing about how your data is handled changes when the company exists.

What we collect

Read from TikTok, and only what's public

  • The comment that tagged @tokrpad: the text, and the @ of the person who wrote it.
  • The video's public address, the @ of the account that posted it, and the thumbnail frame. We copy that frame to our server and use it as the coin's logo, so it doesn't disappear when TikTok's link expires.

We never see anyone's TikTok password, private messages, or anything behind a login.

What we collect

From a creator who claims

  • Your TikTok @, typed on the Creators page.
  • Whether the account is verified (we read your public bio for a code, and nothing else).
  • The wallet address you link, and the signature that proves it's yours. We never receive your private key or seed phrase.
  • A record of payouts sent to that wallet: amount, transaction and time.

The wallet address and payout history are already public on the chain.

What we don't do

The list that stays empty

  • No account or login to browse. No profile, no password.
  • No tracking cookies and no session tracking. Your browser keeps a few small preferences on your own device (for example a pending bio code while you verify); they never leave it.
  • No analytics provider, no advertising network, no crash reporter, no fingerprinting script.
  • No location, contacts, microphone or photos.
How long it lasts

What's kept, and until when

  • Mentions (the comment, commenter @, video link and author) are kept so the same video isn't launched twice and to enforce the anti-spam limits.
  • Coins (name, ticker, contract, numbers read from the chain) are kept as long as the coin exists.
  • Creators (the @, verification state, linked wallet, payout history) are kept so we can pay you and not pay twice.

Everything we hold off-chain can be removed on request. Server request logs at our host expire on the host's own schedule and aren't used to profile anyone.

Who else touches it

Everyone in the path

DigitalOcean
Hosting. Every request to the site passes through the server there, which sees your IP and headers in the ordinary course of serving the page.
Privy
The wallet connector. When you tap Connect wallet, Privy's code runs in your browser to talk to your wallet app and sees your wallet address.
TikTok
We fetch the public video page and thumbnail from TikTok to resolve a mention. That's our request, not yours.
CoinGecko
We read prices to show dollar figures. That call carries no data about you.
Solana
The RPC and the block explorer are public infrastructure we don't run.
Google Fonts
Serves the fonts on this site.
The wall

The part we can't delete

A public chain is public, forever. Coins, payouts and burns are on Solana: a wallet address, an amount, a time. Anyone can read them, and no request to us removes them. We don't attach your name to any of it, because we don't have it. The right to erasure works on everything we hold off-chain and stops at the chain.

Your rights

And how to use them

Write to contact@tokrpad.fun for any of these, and a person answers:

  • Access: what we hold linked to your @ or wallet.
  • Rectification: fix anything wrong.
  • Erasure: remove your @, verification, linked wallet and payout records from our files (not from the chain).
  • Objection and restriction: ask us to stop or pause using what's in dispute.
  • Complaint: to the data protection authority where you live, without asking us first.
Changes

It changes in public

When something material moves (a new processor, a new field, a longer retention), this page is updated before the change ships, and the date at the top moves with it.