legal
Privacy Policy
Effective July 18, 2026
1. What this covers
This policy explains what data RoastMyTok collects when you use the Service, why, and who else sees it. We built this to actually reflect what the app does, not a generic template.
2. Data we collect
- Account data: email address, if you create an account (Firebase Authentication). Guest sessions get an anonymous identifier and no email until you choose to save your roast.
- TikTok content you provide: post captions, view/like/comment/share counts, post dates, and thumbnails, either pasted by you, pulled via TikTok’s official Login Kit/Display API after you connect your account, or read from your public TikTok profile page. We never collect your TikTok password.
- Payment data: handled entirely by Stripe. We store only your Stripe customer ID and subscription status, never your card number.
- Usage data: page views and in-app events (for example: a roast started, a plan generated, an upgrade clicked) via Vercel Analytics and Google Analytics for Firebase. Vercel Analytics is cookieless and does no cross-site tracking. Google Analytics for Firebase sets a first-party analytics identifier and, where you are signed in, ties events to your account id so we can tell whether features are actually used. We do not use either for advertising.
3. How we use it
Your posts and profile data are sent to an AI model (Google Gemini, via Google Cloud Vertex AI) to generate your analysis, virality score, and any scripts or content ideas you request. We use your account data to enforce free-tier limits, gate paid features, and process billing. We do not sell your data, and we do not use your content to train AI models.
4. Who we share it with
We use a small number of infrastructure providers to run the Service, each of whom processes data only on our behalf:
- Google Firebase, authentication and database (Firestore)
- Google Cloud / Vertex AI, runs the Gemini model that generates your analysis
- Stripe, payment processing
- Vercel, hosting and cookieless page-view analytics
- Google Analytics for Firebase, product analytics (which features get used, where people drop off)
- TikTok, only if you connect your account via Login Kit, to read your own posts
We do not otherwise sell, rent, or share your personal data with third parties for their own marketing purposes.
5. Data retention & deletion
We keep your data for as long as your account is active. Guest (anonymous) session data that is never claimed may be periodically cleared. You can delete your account yourself at any time from Settings. This cancels any active subscription and erases your account, posts, roasts, and scripts. If you’d rather we handle it, email tchindaphilippe@gmail.com and we’ll confirm once it’s done.
6. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Contact us at the email above to exercise any of these rights.
7. Security
Data is stored in Firestore behind security rules that restrict client access to your own data; all writes from AI-generated content go through our authenticated server, not directly from the browser. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your information.
8. Children’s privacy
The Service is not directed at children under 13, and we do not knowingly collect data from them.
9. Changes to this policy
We may update this policy as the Service changes. Material changes will be reflected by updating the effective date above.
10. Contact
Questions about this policy or your data: tchindaphilippe@gmail.com