Privacy Policy
Effective date: September 18, 2026
TikTomato ("we") restores old photographs, and also upscales and generates images. This policy describes exactly what we collect, why, who we share it with, and how long we keep it. It covers the website at tiktomato.com and the TikTomato iOS app.
1. What we collect
Account information. Your email address, and a display name and profile picture if your sign-in provider supplies them. You can sign in with Google or Apple; if you use Apple's "Hide My Email", we only ever see the relay address. Accounts created by our staff for testing use an email address and password.
Photos you upload. The photo you want restored or upscaled, any reference photos you add when generating an image, and the results. If you attach a screenshot to a feedback message, we receive that too.
Prompts you write. The text you type to describe the image you want generated.
Purchases. Order records and credit history: what you bought, when, how much, and the credits it added. Card details are handled by Stripe (web) or Apple (in‑app purchases) and never reach our servers.
Support messages. The text of feedback you send us and our replies.
Sign-up context. When your account is created we store a snapshot of how you arrived: which sign-in provider you used, the page you signed up from, the referring site, and campaign parameters in the URL if any were present.
Server logs. Errors and warnings produced while serving your requests, which may include your account identifier and the API path involved.
What we do not collect
TikTomato does not directly request or receive your location, contacts, calendar, health data, browsing history outside our own site, or advertising identifiers. We do not use advertising SDKs and we do not track you across other companies' apps or websites — so the iOS app does not ask for tracking permission.
The Google Sign-In SDK bundled in the iOS app has its own privacy manifest. It declares that it may handle a name, email address, phone number, coarse location, user ID, device ID, other usage data, and other data types for sign-in functionality or analytics. Google marks these data as linked to the user but not used for tracking. TikTomato uses the SDK only for sign-in and does not receive its analytics data.
2. How we use it
- To run the service: authenticate you, process the photos and prompts you submit, and deliver the results.
- To operate credits and billing, including granting purchased credits and handling refunds.
- To answer your support messages.
- To find and fix failures. Server logs are how we notice that a restoration failed and why.
- To meet legal and accounting obligations.
We do not use your photos or prompts to train models.
3. Who we share it with
We share information only with the providers we need in order to operate:
| Provider | What they receive | Why |
|---|---|---|
| Cloudflare | Uploaded photos and restored results | Temporary file storage and content delivery |
| AI processing providers | The photo being processed, and the prompt if you wrote one | To produce the result |
| Stripe | Email address, order amount | Payments made on the website |
| Apple | Purchase receipts | In-app purchases, and Sign in with Apple |
| Sign-in tokens | Sign in with Google |
The AI processing provider may change as the service evolves, so we do not name a single vendor here. Whichever one we use receives only the photos being processed and the prompt you wrote, and returns the result; the iOS app shows you this before your first upload.
We may also disclose information when the law requires it, or as part of a merger or sale of the business. We do not sell personal information.
4. How long we keep it
| Data | Retention |
|---|---|
| Photos you upload for processing | 30 days, then deleted automatically |
| Prompts | 30 days, then deleted automatically |
| Results | 30 days, then deleted automatically |
| Feedback screenshots | Kept until you ask us to remove them |
| Account, credits and order history | Until you delete your account |
| Server logs | About three months |
Save the results you want to keep. They are removed after 30 days and we cannot recover them.
5. Deleting your account
In the iOS app: Account → Delete account. On the website: Dashboard → Billing, or write to us. You can also email hi@tiktomato.com and we will do it for you.
Deletion is permanent and immediate: your photos, tasks and remaining credits are gone and cannot be restored. Records we are legally required to keep — payment and tax records in particular — are retained in a form that is no longer linked to you.
If you signed in with Apple, deleting your account also revokes the token we hold for Apple sign-in.
6. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, or to object to or restrict how we process it. Write to hi@tiktomato.com and we will respond within a reasonable time.
7. Security
Traffic is encrypted in transit. Uploaded files sit behind unguessable URLs and are deleted on the schedule above. Access to production data is limited to people who need it to run the service. No system is completely secure, and we cannot promise absolute security.
8. Children
TikTomato is not directed to children under 13, or under the minimum age of digital consent where you live. We do not knowingly collect personal information from them. If you believe a child has given us personal information, write to us and we will delete it.
9. International transfers
Our servers and providers operate in the United States and other countries, so your information may be processed outside the country where you live. Where the law requires it, we rely on appropriate transfer safeguards.
10. Changes
We will update the effective date above when this policy changes, and give you additional notice when the change is significant.