FindMyTok Privacy Policy

Plain-language summary — not part of the Policy

FindMyTok helps you search your own published TikTok videos by words you remember saying and, when enabled, text visible in video frames. It builds and searches a local index on your device.

The important privacy distinction is that on-device processing is not the same as no network traffic. The app uses the network to connect to TikTok through the session you establish, and it also uses RevenueCat for purchase reporting and the self-hosted Aptabase service for the limited analytics described below. Your TikTok password is entered into TikTok’s own login page, not into an FindMyTok-owned password field.

This summary is for convenience only. The sections below are the Privacy Policy.

Effective date and updates

Effective date: September 10, 2026
Last updated: September 10, 2026

We will update the “Last updated” date whenever this Policy changes. If a change materially affects how personal data is handled, we will provide any additional notice required by applicable law.

1. Who is responsible for this Policy

The controller and publisher is the Brazilian company identified in Section 19 (Contact and legal identity) below. We place the complete corporate details there so they remain easy to find without interrupting the explanation of the app’s privacy model.

Privacy and data-rights requests may be sent to [email protected].

In this Policy, “we,” “us,” and “our” refer to that controller/publisher.

2. Scope

This Policy covers the FindMyTok iOS app and the product website findmytok.app.

The website uses basic Google Analytics and no contact form or additional website analytics provider. In its standard web implementation, Google Analytics may process page/session activity, browser and device information, approximate location, and a pseudonymous website client identifier commonly stored in a first-party cookie such as _ga. Google states that Google Analytics 4 does not log or store raw IP addresses.

Google Analytics is used only to understand aggregate website usage and improve the product site. We do not intentionally send TikTok account data, transcripts, search queries, purchase details, or other app content to Google Analytics.

Google Analytics is delivered through a Google Tag Manager container. We use that container to load the analytics measurement described here, not advertising or remarketing tags.

Neither the container nor Google Analytics loads until you accept it. That applies on every visit and in every country, not only where prior consent is legally required: until you accept the analytics notice, no Google script, cookie, or identifier is created. Declining is a single action in that same notice, and you can change or withdraw your choice at any time through the analytics control in the site footer, in the same number of steps it took to accept. Withdrawing also deletes the Google Analytics cookies already stored in that browser.

Development diagnostics are debug-only and are removed from the production release. The production app does not provide a developer-diagnostics export or silently upload debug diagnostic logs to us.

3. How FindMyTok connects to TikTok

The user signs in through TikTok’s own login page rendered inside a WKWebView. The app does not ask for or store the user’s TikTok password. After TikTok establishes an authenticated web session, the app detects the session cookie TikTok sets and uses the authenticated session to perform the app’s functions on the user’s own account.

For media needed for indexing, FindMyTok may copy the TikTok session cookies to URLSession so it can retrieve the user’s own media through that session. The app does not implement an official TikTok API integration.

TikTok receives network requests made through its own website/session and processes information under TikTok’s own terms and privacy practices. TikTok and ByteDance are not affiliated with, sponsors of, or endorsers of FindMyTok. FindMyTok is an independent app.

4. Data processed on your device

FindMyTok stores on your device post metadata, processing status and issues, transcripts, recognized frame text, thumbnails, and SQLite FTS5 search indexes. It temporarily downloads video media through your TikTok session, extracts audio, and performs speech recognition and frame-text recognition on the device using Apple frameworks. Downloaded video and extracted audio are temporary; the app attempts to delete them after processing and clears leftover temporary media when the app launches. Transcription reads audio files and does not use the microphone. There is no implemented cloud transcript store and no cross-device library sync.

Photo posts are outside the current video-processing scope and recognized photo entries are filtered or excluded.

FindMyTok also requests local notification permission for match notices and can display progress through a Live Activity. These operating-system features do not change the fact that the transcript/search library described above remains local unless another data flow is expressly described in this Policy.

Because these data are designed to remain on the device, we do not treat the local copy as a cloud account held by us. Data-protection law may nevertheless regulate the processing performed by software whose purposes and means we determine. Where applicable, we therefore describe our role and legal bases in this Policy rather than claiming that local processing is automatically outside privacy law.

5. Data sent off the device

5.1 TikTok session traffic

The app sends requests to TikTok through the authenticated session you establish. TikTok can receive information inherent in web traffic and the requests necessary to provide its service. The exact categories TikTok collects through the embedded login and account pages depend on TikTok’s own pages and the login method you choose.

We have audited this traffic. The requests the app makes are those TikTok’s own pages require, plus those needed for the operations you request on your own account. The app changes content only on the items you select and confirm. We do not add tracking of our own to that traffic, and no app content is sent to a third party through it.

5.2 Aptabase analytics

FindMyTok uses a self-hosted Aptabase instance at data.rafacst.me. The app sends the events app_started, screen_view, search_run, and index_run. The app-defined event properties are limited to screen names, flags, and bucketed counts. The app does not put search query text, transcript text, captions, post identifiers, or TikTok account names into those event properties.

The stored Aptabase events are configured without account identifiers, device identifiers, advertising identifiers, query/content text, or additional technical fields. The analytics record is intended to be anonymous and cannot be used by us to identify an individual user. Analytics is optional, and the user can disable it at any time in Settings.

No Aptabase usage event is sent before the user affirmatively consents to analytics. The user may later withdraw that consent at any time in Settings, without losing paid or core functionality.

Aptabase analytics events are retained for 90 days and then deleted or aged out from the analytics store. Any infrastructure logging used to operate that service must not be used to create user profiles or cross-service tracking.

5.3 Purchases and RevenueCat

Apple processes payments and subscription renewals through StoreKit. StoreKit is the source of truth for entitlement in the app. RevenueCat is integrated to report verified purchases and successful restores.

RevenueCat necessarily receives purchase/transaction information required for that reporting and may receive technical information through its SDK. We do not receive your payment-card number from Apple.

RevenueCat uses an anonymous App User ID rather than a custom user identity. We do not configure RevenueCat customer attributes, integrations, or webhooks. RevenueCat is used only for purchase/restoration reporting around the StoreKit flow. Vendor-side retention, processing locations, and international-transfer safeguards are governed by RevenueCat’s applicable service terms and data-processing documentation.

6. Important data we do not send in the described analytics

Based on the current app implementation described above, Aptabase event properties do not contain search queries, transcripts, captions, TikTok post identifiers, or TikTok account names. We do not describe the local TikTok library as “never using the network,” because the app must communicate with TikTok to provide its functions.

Nothing in this section changes information that TikTok itself receives when its pages and authenticated session are used, or information RevenueCat receives for purchase reporting.

Where the LGPD, GDPR, UK GDPR, or a comparable law requires a legal basis, we rely on the following bases to the extent applicable:

Processing Purpose Brazil (LGPD) EEA/UK
TikTok session and app-requested account operations Provide the function you requested Performance of a contract / procedures relating to a contract (LGPD Art. 7(V)) Performance of a contract (GDPR/UK GDPR Art. 6(1)(b))
Local indexing/catalogue and related device processing Provide search or cleanup functionality Performance of a contract (Art. 7(V)) Performance of a contract (Art. 6(1)(b))
Purchase verification/reporting Provide paid entitlement, restore purchases, prevent purchase abuse Contract (Art. 7(V)); legitimate interests where necessary (Art. 7(IX)); legal obligation where applicable Contract (Art. 6(1)(b)); legitimate interests where necessary (Art. 6(1)(f)); legal obligation where applicable
Optional Aptabase usage analytics Understand aggregate product usage and improve the app Consent (Art. 7(I)) once the required opt-in is implemented Consent (Art. 6(1)(a)) once the required opt-in is implemented
Security and abuse prevention Protect the app, users, and transactions Legitimate interests (Art. 7(IX)), subject to applicable balancing and rights Legitimate interests (Art. 6(1)(f)), subject to balancing and rights

If we rely on consent, you may withdraw it prospectively without affecting processing already lawfully carried out. If we rely on legitimate interests, you may have a right to object depending on the jurisdiction and circumstances.

8. Who receives data

The current product architecture involves these recipients or independent services:

Apart from those recipients, no other processor receives data derived from your use of the app. We do not pass it to a separate support provider, analytics vendor, CDN, or reverse proxy, and the analytics records we hold cannot be linked by us to you, your device, or your TikTok account.

We do not sell personal information and, on the supplied facts, do not disclose personal information for cross-context behavioral advertising.

9. International transfers

Apple, RevenueCat, and TikTok are established outside Brazil and may process data outside the country where you use the app. The analytics instance is operated by us.

We do not rely on an adequacy decision for those flows. Where a transfer mechanism is required, it is the standard contractual clauses incorporated into each provider’s own data-processing terms, including RevenueCat’s terms of service and Apple’s applicable terms:

Brazil: the standard contractual clauses (cláusulas-padrão contratuais) under LGPD Arts. 33–36 and ANPD Resolution CD/ANPD No. 19/2024.

EEA: the European Commission’s standard contractual clauses under GDPR Art. 46(2)(c).

United Kingdom: the UK International Data Transfer Addendum to those clauses, or the UK IDTA.

10. Retention and deletion

We apply the following product-specific rules:

We may retain information longer where required to comply with law, resolve disputes, or establish legal claims, but only if such retention actually applies to data we hold.

11. Your controls

You can control data and permissions in several ways:

Removing app-local data does not delete content or an account held by TikTok unless you separately instruct TikTok to perform such an action.

12. Brazil — LGPD rights

If the LGPD applies to your personal data, you may have rights including confirmation of processing, access, correction, anonymization/blocking/deletion of unnecessary, excessive or unlawfully processed data, portability subject to regulation, information about sharing, information about consequences of refusing consent, consent withdrawal, deletion of data processed on consent subject to legal exceptions, and objection to unlawful processing. You may also petition the ANPD and other competent consumer authorities.

Requests: [email protected].

Some app data is stored only on your device and is not readable from our servers. In that case, we may direct you to the applicable in-app/device control because we cannot retrieve data we do not possess.

13. EEA and UK rights

If the GDPR or UK GDPR applies, you may have rights to access, rectify, erase, restrict processing, object, receive portable data, withdraw consent, and lodge a complaint with your local supervisory authority. Rights depend on the legal basis and circumstances.

EEA representative under GDPR Art. 27: We do not currently appoint a representative in the EEA. We have assessed that the exception in Article 27(2)(a) applies to our relevant processing because it is occasional, does not involve large-scale processing of special-category or criminal-offence data, and is unlikely to result in a risk to the rights and freedoms of natural persons. We will reassess this position if the nature, scale, regularity, or risk of the processing changes.

UK representative: We do not currently appoint a UK representative. We have assessed that the corresponding UK GDPR exception for occasional, low-risk processing applies. We will reassess this position if the nature, scale, regularity, or risk of the processing changes.

14. California privacy

On the supplied facts, we do not sell personal information and do not “share” personal information for cross-context behavioral advertising as those terms are used in the CCPA/CPRA.

If we are a “business” subject to the CCPA/CPRA, California residents may have applicable rights to know/access, delete, correct, and opt out of sale/sharing, and the right not to receive discriminatory treatment for exercising covered rights. Because the applicability thresholds depend on facts not established in the product record, this section does not represent that we currently meet the statutory definition of a CCPA “business.”

Request channel: [email protected].

15. Children and teenagers

FindMyTok is not intended for use by anyone under 18 years of age. By using the app, you confirm that you are at least 18.

An existing TikTok account is not treated by us as proof of age. If we learn that a person under 18 has used the app in circumstances that require action under applicable law, we will take reasonable steps appropriate to the data we actually control. Because the app does not create a first-party user account, we may not be able to identify a particular device user unless that person contacts us.

16. Security

We use the architecture described in this Policy to reduce data exposure, including device-local storage for the TikTok library and not collecting TikTok passwords into an app-owned credential system. No method of storage or transmission is completely secure.

Development builds may contain diagnostic logging for engineering purposes, but that debug-only facility is removed from the production release. The production app does not provide a developer-diagnostics export or silently upload diagnostic logs to us.

17. Third-party services and TikTok independence

FindMyTok is an independent app and is not affiliated with, endorsed by, sponsored by, or connected to TikTok or ByteDance. TikTok, Apple, RevenueCat, and other third-party services apply their own terms and privacy notices to processing they independently control.

This Policy does not state that TikTok has authorized FindMyTok’s integration method. The Terms of Service separately explain the platform dependency, the user’s responsibilities, and the risk that TikTok may change, restrict, or discontinue relevant functionality.

18. Changes to this Policy

We may revise this Policy as the app, law, or vendor configuration changes. We will post the revised version with an updated “Last updated” date and provide additional notice where required.

Privacy requests and support: [email protected]

Controller / publisher: R Castro Silva Consultoria em Tecnologia LTDA, trading as Rafacst Consultoria, registered in Brazil under CNPJ 66.424.919/0001-10
Business address: Rua Guaicurus 635, Apt. 202, Tower A, Água Branca, São Paulo, SP, 05033-001, Brazil

This company operates the app worldwide, subject to mandatory local consumer and data-protection law where applicable.

20. Language

The English and Brazilian Portuguese versions are intended to impose equivalent privacy commitments. If a discrepancy arises, the text must be interpreted consistently with the mandatory consumer and data-protection rights that apply to the user.