Skip to main content
TikTomato

Privacy Policy

Effective date: September 18, 2026

TikTomato ("we") restores old photographs, and also upscales and generates images. This policy describes exactly what we collect, why, who we share it with, and how long we keep it. It covers the website at tiktomato.com and the TikTomato iOS app.

1. What we collect

Account information. Your email address, and a display name and profile picture if your sign-in provider supplies them. You can sign in with Google or Apple; if you use Apple's "Hide My Email", we only ever see the relay address. Accounts created by our staff for testing use an email address and password.

Photos you upload. The photo you want restored or upscaled, any reference photos you add when generating an image, and the results. If you attach a screenshot to a feedback message, we receive that too.

Prompts you write. The text you type to describe the image you want generated.

Purchases. Order records and credit history: what you bought, when, how much, and the credits it added. Card details are handled by Stripe (web) or Apple (in‑app purchases) and never reach our servers.

Support messages. The text of feedback you send us and our replies.

Sign-up context. When your account is created we store a snapshot of how you arrived: which sign-in provider you used, the page you signed up from, the referring site, and campaign parameters in the URL if any were present.

Server logs. Errors and warnings produced while serving your requests, which may include your account identifier and the API path involved.

What we do not collect

TikTomato does not directly request or receive your location, contacts, calendar, health data, browsing history outside our own site, or advertising identifiers. We do not use advertising SDKs and we do not track you across other companies' apps or websites — so the iOS app does not ask for tracking permission.

The Google Sign-In SDK bundled in the iOS app has its own privacy manifest. It declares that it may handle a name, email address, phone number, coarse location, user ID, device ID, other usage data, and other data types for sign-in functionality or analytics. Google marks these data as linked to the user but not used for tracking. TikTomato uses the SDK only for sign-in and does not receive its analytics data.

2. How we use it

  • To run the service: authenticate you, process the photos and prompts you submit, and deliver the results.
  • To operate credits and billing, including granting purchased credits and handling refunds.
  • To answer your support messages.
  • To find and fix failures. Server logs are how we notice that a restoration failed and why.
  • To meet legal and accounting obligations.

We do not use your photos or prompts to train models.

3. Who we share it with

We share information only with the providers we need in order to operate:

ProviderWhat they receiveWhy
CloudflareUploaded photos and restored resultsTemporary file storage and content delivery
AI processing providersThe photo being processed, and the prompt if you wrote oneTo produce the result
StripeEmail address, order amountPayments made on the website
ApplePurchase receiptsIn-app purchases, and Sign in with Apple
GoogleSign-in tokensSign in with Google

The AI processing provider may change as the service evolves, so we do not name a single vendor here. Whichever one we use receives only the photos being processed and the prompt you wrote, and returns the result; the iOS app shows you this before your first upload.

We may also disclose information when the law requires it, or as part of a merger or sale of the business. We do not sell personal information.

4. How long we keep it

DataRetention
Photos you upload for processing30 days, then deleted automatically
Prompts30 days, then deleted automatically
Results30 days, then deleted automatically
Feedback screenshotsKept until you ask us to remove them
Account, credits and order historyUntil you delete your account
Server logsAbout three months

Save the results you want to keep. They are removed after 30 days and we cannot recover them.

5. Deleting your account

In the iOS app: Account → Delete account. On the website: Dashboard → Billing, or write to us. You can also email hi@tiktomato.com and we will do it for you.

Deletion is permanent and immediate: your photos, tasks and remaining credits are gone and cannot be restored. Records we are legally required to keep — payment and tax records in particular — are retained in a form that is no longer linked to you.

If you signed in with Apple, deleting your account also revokes the token we hold for Apple sign-in.

6. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, or to object to or restrict how we process it. Write to hi@tiktomato.com and we will respond within a reasonable time.

7. Security

Traffic is encrypted in transit. Uploaded files sit behind unguessable URLs and are deleted on the schedule above. Access to production data is limited to people who need it to run the service. No system is completely secure, and we cannot promise absolute security.

8. Children

TikTomato is not directed to children under 13, or under the minimum age of digital consent where you live. We do not knowingly collect personal information from them. If you believe a child has given us personal information, write to us and we will delete it.

9. International transfers

Our servers and providers operate in the United States and other countries, so your information may be processed outside the country where you live. Where the law requires it, we rely on appropriate transfer safeguards.

10. Changes

We will update the effective date above when this policy changes, and give you additional notice when the change is significant.

11. Contact

hi@tiktomato.com