Privacy Policy

Last updated : 2/18/2026

1. Introduction

This Privacy Policy explains how Islandium collects, uses, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). By using Islandium, you accept the practices described below.

2. Data Collected - Complete Inventory

For complete transparency, here is all the data we collect and store:

2.1. User Account Data

DataPurposeRetention
EmailAuthentication, communicationAccount duration
UsernameIdentificationAccount duration
Password (bcrypt hashed)Secure authenticationAccount duration
Name, surname (optional)BillingAccount duration
Postal address (optional)BillingAccount duration
Google ID (if Google login)OAuth authenticationAccount duration
Google profile photo (if OAuth)Profile displayAccount duration

2.2. Technical and Security Data

DataPurposeRetention
IP AddressSecurity, fraud prevention30 days (logs)
User-Agent (browser)Compatibility, debug30 days (logs)
Session tokens (JWT)Session maintenance7 days then deleted
Audit logs (actions)Security, traceability90 days
Timezone (browser)Automatic region detection for TikTok giftsAccount duration

2.3. Payment and Billing Data

DataPurposeRetention
Stripe customer IDSubscription managementAccount duration
Transaction historyAccounting10 years (legal obligation)
PDF invoicesProof of purchase10 years (legal obligation)
Credit card numbersNOT STORED - processed by Stripe-

2.4. Configurations and Preferences

DataPurposeRetention
Overlay profiles (JSON)Tool customizationAccount duration
Trigger configurationsTikTok automationsAccount duration
Custom webhooksExternal integrationsAccount duration
Notification preferencesPersonalized communicationAccount duration

3. TikTok LIVE Data - Detailed Storage

Unlike some services that don't record anything, Islandium stores TikTok data to enable the functioning of leaderboards, statistics, and history. This data is publicly accessible during TikTok lives.

3.1. Stored Viewer Data

DataExampleRetention
TikTok username (@username)@viewer_exampleStreamer account duration
TikTok user ID123456789Streamer account duration
Profile picture URLExternal TikTok URLStreamer account duration
First visit date01/01/2025Streamer account duration
Last activity date01/15/2025Streamer account duration
Counters (follows, likes, shares)5, 120, 3Streamer account duration
Total gifts sent15Streamer account duration
Calculated points1250Streamer account duration

3.2. Gift History

DataPurpose
Gift type (Rose, Lion, etc.)Statistics, leaderboards
Quantity per typeTop donors leaderboards
Value in diamondsTotal calculations

3.3. Trigger Execution Logs

DataRetention
Username of viewer who triggered the action30 days
Event data (JSON)30 days
Success/failure of action30 days

What we do NOT collect from TikTok viewers

  • Viewer email addresses
  • Phone numbers
  • Private TikTok account data
  • TikTok browsing history
  • Viewer geolocation
  • Private messages

Legal basis: This data is publicly accessible during TikTok lives. Processing is based on the streamer's legitimate interest in managing their activity and the fact that the viewer, by participating publicly in the live, makes this information visible to everyone.

4. Subcontractors and Third-Party Services

Hosting - OVH / Hostinger

  • Data : All stored data
  • Location : Europe (France)
  • Guarantees : GDPR compliant, ISO 27001 certified

Database - MySQL

  • Data : Accounts, configurations, statistics
  • Location : Europe
  • Encryption : At rest and in transit

Payments - Stripe

  • Transmitted : Email, amount, customer ID
  • NOT transmitted : Card numbers (processed directly by Stripe)
  • Certification : PCI-DSS Level 1
  • Policy : stripe.com/privacy

AI - OpenAI (GPT-4)

AI - Google Gemini

TTS - Google Cloud Text-to-Speech

  • Data sent : Texts to convert to audio
  • Purpose : Voice synthesis for alerts
  • Cache : Audio files cached for 24h

Authentication - Google OAuth

5. Cookies

Islandium uses minimal cookies

No marketing or advertising tracking cookies are used.

CookieTypeDurationPurpose
access_tokenEssential15 minAuthentication
refresh_tokenEssential7 daysSession maintenance
themePreference1 yearDark/light mode
i18nPreference1 yearLanguage

6. Data Retention Periods

Data TypeDurationJustification
Account dataUntil account deletionContract execution
TikTok viewer dataUntil streamer account deletionLegitimate interest
Technical logs30 daysSecurity
Audit logs90 daysSecurity, traceability
Invoices and transactions10 yearsLegal accounting obligation
TTS audio cache24 hoursPerformance

7. Minimum Age

The Islandium service is reserved for users aged at least 18 years, in accordance with TikTok LIVE terms of service. No data concerning minors is intentionally collected. If you are a parent and believe your child has provided us with data, contact us immediately.

8. Data Deletion

You may request the deletion of your account and all your data at any time.

Deletion delays:

  • Account data : Within 72 hours
  • TikTok viewer data : Within 72 hours (cascade deletion)
  • Configurations and profiles : Within 72 hours
  • Technical logs : Within 30 days
  • Invoices : Retained 10 years (legal obligation)

Deletion request: privacy@islandium.com

9. Your Rights (GDPR)

In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

  • Right of access: view the data we hold about you
  • Right to rectification: correct your inaccurate data
  • Right to erasure: request deletion of your data
  • Right to data portability: retrieve your data in a readable format (JSON)
  • Right to object: refuse certain data processing
  • Right to restriction: limit the processing of your data

To exercise these rights: privacy@islandium.com
Response within 30 days maximum.

10. Data Security

Islandium implements appropriate technical and organizational measures:

  • Encrypted communications (HTTPS/TLS)
  • Hashed passwords (bcrypt)
  • JWT tokens with short expiration
  • Internal access limitations
  • Regular encrypted backups
  • Security monitoring and alerts

11. International Transfers

Islandium aims to keep data within the European Union. However, some providers (OpenAI, Google, Stripe) may have global infrastructure. In this case, transfers are governed by Standard Contractual Clauses (SCC) and subcontractor contractual commitments.

12. Policy Modifications

Islandium may update this policy at any time. Any significant changes will be communicated by email or platform notification. The last update date is indicated at the top of this page.

13. Contact

For any questions regarding data protection or your rights: