Privacy Policy
Effective date: 22 August 2026 · Last updated: 22 August 2026
Mastros ("we", "us", or "our") operates the mastros.online website and provides browser-based tools, including the TikTok Scraper & Export Chrome extension, that let you export data your own logged-in TikTok session can already see.
This Privacy Policy explains what the extension reads, what stays on your device, and the small amount of information that reaches us. Contact: admin@mastros.online
1. The short version
- The extension runs inside your browser on
www.tiktok.com. It reads what your own session already renders — it does not log in for you, and it cannot see anything your account cannot see. - The data you extract never reaches our servers. Profiles, videos, comments, followers, Shop listings, your own analytics and any downloaded media are assembled in the page and saved straight to your computer.
- What we do receive is limited to what is needed to run a licence and to keep the tool working: an account identifier, your plan, usage counts, and anonymous product analytics.
2. What stays on your device
Everything you extract. Rows are collected in the page, held in the browser while a run is in progress, and written to a CSV, XLSX or ZIP file using the downloads permission. Extracted rows are never transmitted to Mastros, and there is no endpoint on our side that would accept them.
This includes the more sensitive surfaces. If you export DM contacts or chat history, those messages are read from your own inbox, written to your own file, and never sent to us or to anyone else.
Settings and the state of an interrupted run are kept in Chrome's local extension storage (storage) so a long export can be resumed. Removing the extension removes that storage.
3. What we receive
Licence and billing
Our licence service at ttexport-api.mastros.workers.dev (Cloudflare Workers) stores one row per user containing:
- An account identifier. If you are signed in to Chrome, this is the email address of your Chrome profile, read through Chrome's
identity.emailpermission. If you are not signed in, a randomly generated install ID is used instead and we never learn an email address. - A browser fingerprint (a canvas hash), used solely to stop one person claiming an unlimited number of free quotas. It is never used for analytics, profiling or advertising.
- Your plan and subscription status, and — if you subscribe — the Stripe customer and subscription identifiers and your billing cycle dates.
Usage counters (how many rows you have exported in the current cycle) are held separately in Cloudflare KV. They are counts, not content.
Product analytics
We use PostHog, hosted in the EU (eu.i.posthog.com), to see whether the tool works. Events are restricted by a strict allow-list in the extension itself: anything not on the list is dropped before the request is built, so a future change cannot leak content by accident.
What is sent: the event name, and only these kinds of properties —
- product, plan, extension version, interface locale;
- which surface was used (for example "followers" or "video comments"), how many rows were gathered, how long the run took, whether it was resumed, and why it stopped;
- failure and self-healing causes when something breaks.
What is never sent: usernames, handles, display names, bios, captions, comment text, email addresses, video identifiers, search queries, or any third party's follower counts. Row counts and failure causes only.
4. Permissions, and why each one exists
www.tiktok.com— the only site the extension runs on.*.tiktokcdn.com,*.tiktokcdn-us.com,*.tiktokv.com— TikTok's own media servers. These are requested for one reason: when you choose to download a video or image, the file has to be fetched from where TikTok serves it. Nothing is sent to these hosts beyond the request for the file.storage— settings and resumable run state, kept locally.downloads— writing your export and any media to your computer.identity/identity.email— identifying your licence across devices. Optional in practice: without it you fall back to an anonymous install ID.alarms— pacing long runs and refreshing licence state.ttexport-api.mastros.workers.dev— the licence service.eu.i.posthog.com— the analytics described above.
5. Processors
- Cloudflare — hosting for this site and the licence service (Workers, D1, KV).
- Stripe — payments. Card details go to Stripe directly; we never see or store them.
- PostHog (EU region) — product analytics, as scoped above.
- SplitForms — the contact and uninstall-feedback forms on this website. It retains submissions in its own dashboard.
- Google — distribution through the Chrome Web Store and the Chrome identity API.
6. Data you extract about other people
This matters and we would rather be blunt about it. When you export followers, commenters or a chat history, you are collecting personal data about people who are not party to this policy. For that data you are the controller, not us — we never receive it and cannot act on it for you.
You are responsible for having a lawful basis to collect and use it, for honouring access and deletion requests from those people, and for complying with TikTok's own terms and with the data-protection law that applies to you. Message content deserves particular care: the other participants in a conversation did not choose to have it exported.
7. Retention and your rights
Your licence row is kept while your account exists, and billing records for as long as tax and accounting rules require. Analytics events are retained by PostHog under its own retention settings and cannot be tied back to you by name, because no name is ever sent.
If the GDPR or a comparable law applies to you, you may request access to, correction of, or deletion of the data we hold about you, and you may object to processing or ask for a portable copy. Write to admin@mastros.online and we will action it. Deleting your licence also removes the email address or install ID associated with it.
8. Children
The Service is not directed at children under 16, and we do not knowingly create accounts for them.
9. Changes
If what the extension collects changes, this page changes with it and the "last updated" date above moves. Material changes will be called out in the extension or on this site rather than made quietly.
Questions: admin@mastros.online