This page describes what GlimTok collects, why, how long it is kept and how you can remove it. It is written in plain language on purpose. Where a detail depends on an environment setting, such as whether Google sign-in or payments are enabled, the page says so rather than assuming.

The short version

You can browse public TikTok content without telling GlimTok who you are. GlimTok never asks for a TikTok password, cookie or app permission. If you sign in with Google, GlimTok learns your name, email and profile picture, and nothing else. Your saved profiles, groups and notes are private to your account. Export files are deleted after 72 hours. You can remove saved profiles at any time and delete your account after verifying your identity again.

Your GlimTok identity

Browsing does not require an account. When you choose to sign in, Google provides basic identity information so GlimTok can create and manage your account: your name, email address and profile picture, through the openid, email and profile permissions only. GlimTok does not request Gmail, Contacts, Calendar or Drive access, and Google sign-in has no connection to TikTok.

A signed-in session is kept in a cookie that identifies your GlimTok account. Sessions last up to 30 days and end after 7 days without activity. Sensitive actions, such as deleting your account, require a fresh verification of the same Google identity within the previous ten minutes. An existing session, or returning from a sign-in page, is not treated as proof.

Saved profiles and notes

As a guest, saved profiles are stored in your browser’s local storage on that device. GlimTok cannot see them. Clearing site data, using a private window or switching browsers removes or hides them. Your theme preference is stored the same way.

Once you sign in, saved profiles, groups, pins, default tabs and private notes are stored with your GlimTok account. Local bookmarks are imported only after you select and confirm them. Signing in alone imports nothing. Notes are limited to 200 characters and are readable only by you. Saving a profile does not follow the account on TikTok, does not notify it and does not perform any action through a TikTok account.

Signing out removes access to your cloud list on that device and does not copy it into the browser’s local storage. Different GlimTok users never see each other’s lists, notes or groups.

Public content and service providers

When you look up a profile or video, GlimTok sends a request to its public-data provider and shows you the result. Requests are made only when you act: a lookup, a page load, a reply thread, a refresh you confirmed. Nothing is fetched when a page merely renders, and nothing runs on a schedule.

If a profile picture or other media loads in your browser, the server that hosts it receives a normal web request, which includes your IP address. Google handles authentication. Stripe handles payment flows where they are enabled. Hosting, database and queue providers operate the service infrastructure. When enabled, Cloudflare Turnstile checks browser signals during an explicit public-content request to help prevent abuse; its script is not loaded just by opening the home page or your saved list.

GlimTok makes no claim of invisible or untraceable browsing. It claims something narrower: you are never identified to TikTok, and your query targets stay out of GlimTok’s analytics.

Exports and temporary data

A comment export runs as a private job under your account. The rows it retrieves are stored temporarily so the file can be generated and, within 72 hours, regenerated in the other format. Export files and those temporary rows are deleted after 72 hours. Job status and non-content metadata, such as the options you chose and the counts in the scope report, are kept for 30 days so your history stays legible. Comment text is not retained beyond the 72-hour window.

Retention and deletion

You can remove saved profiles from the Saved page, individually or in bulk, and clear guest bookmarks by clearing site data. You can sign out of one device or all devices from Settings. You can request account deletion from Settings after fresh Google verification. Deletion removes your cloud saved profiles, groups, notes, export data and sessions.

Financial records may be retained where legal and accounting obligations require it. Backups expire on their own schedule, so deletion from the active service is not a promise of immediate physical removal from every backup. If a payment service is unavailable at the moment of deletion, private-data deletion proceeds while any subscription cancellation remains pending, and the account interface reports that distinction rather than claiming success early.

Operational privacy

Product analytics exclude query targets, full URLs, comment text, private notes and authentication tokens. Private saved lists are not captured in any session replay. GlimTok does not sell saved lists, does not share them with third parties for their own purposes, and does not use them to perform actions on TikTok or anywhere else.

Abuse prevention uses request rates, browser challenge results where enabled and account allowances. It does not profile the accounts you look at.

Cookies and local storage

GlimTok uses a session cookie for signed-in accounts and, when enabled, Cloudflare Turnstile’s challenge state during protected requests. Your theme preference and guest saved list live in local storage. Lookup results are briefly kept in your tab’s session storage so opening a result does not repeat the request. None of these are used for advertising.

Children

GlimTok is not directed at children, and Google sign-in is subject to Google’s own age requirements. If you believe a child has created an account, contact us and we will remove it.

Changes and contact

When this page changes in a way that matters, the change will be visible here with its date. Contact details must be configured before public launch; see Contact for current availability. Questions about this page, your data or a deletion request can be sent there.