Privacy Policy
Our Privacy Policy
This Privacy Policy explains how Octopuce SAS (“Octopuce,” “we,” “our,” or “us”) collects, uses, discloses, and secures information when you install or use the Chrome extension “TikTok & Instagram Sort / Download by Octopuce.io” (the “Extension”). Our sole purpose is to let you sort and download public TikTok and Instagram videos for personal, lawful use. We never collect data that is unrelated to this single purpose.
Last Updated on May, 1st, 2025
What Data We Collect and Why
Current tab URL and media request headers
When collected: only when you click the Extension icon (permissions : activeTab, scripting, tabs, webRequest).
Purpose: detect the TikTok/Instagram video, generate a download link.
Legal basis: performance of a contract (Chrome Web Store Terms).
Download files (video or ZIP)
When collected: after you confirm a download (permission : downloads).
Purpose: deliver the media you requested.
Legal basis: performance of a contract.
Local session token
When collected: if you sign in with Octopuce (permissions : storage, identity).
Purpose: keep you logged in securely and apply your personal settings.
Legal basis: legitimate interest.
Minimal server logs (IP address, timestamp, requested resource)
When collected: whenever the Extension contacts our API https://555924672.xyz.
Purpose: abuse prevention and service diagnostics.
Legal basis: legitimate interest.
Consent and User Control
Just-in-time notices: Chrome shows a native permission prompt the first time any access is required.
Options page: you can disable analytics logging or activate Offline Mode (all processing stays on your device).
Revoking permissions: at any moment you may visit chrome://extensions > Details > Reset permissions or simply uninstall the Extension.
How We Store and Protect Data
Traffic between the Extension and our server is encrypted with TLS 1.3.
Server logs are kept on ISO 27001–certified infrastructure located in the European Union.
Local data (tokens, settings) lives only in Chrome’s chrome.storage.local and is deleted automatically if you remove the Extension.
We apply OWASP and NIST security practices, perform regular audits, and use strict access controls.
Data Sharing
We do not sell, rent, or trade user data. We share information only in these situations:
Service providers that host our infrastructure or process downloads, under confidentiality agreements.
Legal obligations, e.g., a valid court order.
With your explicit direction, such as when you export your personal data.
We never transfer Google, TikTok, or Instagram credentials to any third party.
Data Retention
Server logs: automatically deleted after 14 days.
Local session tokens: removed at logout, after 12 months of inactivity, or when the Extension is uninstalled.
Support correspondence: kept until the request is resolved plus six months (for follow-up and quality control).
You may request earlier deletion at any time (see Section Your Rights).
Security
Where the GDPR or similar laws apply, you can:
Access the personal data we hold about you.
Rectify inaccurate or incomplete data.
Erase data (“right to be forgotten”).
Port data to another service.
Restrict or object to certain processing.
Withdraw consent at any time (without affecting past processing).
To exercise these rights, email contact@octopuce.io. We respond within 30 days.
Cookies and Tracking
The Extension sets no cookies. Our website https://octopuce.io uses essential and analytics cookies; see our separate Website Cookie Notice.
Developer Program Certifications
We do not sell or transfer user data outside approved use cases.
We do not use or transfer data for purposes unrelated to the Extension’s core functionality.
We do not use or transfer data to determine a user’s creditworthiness or for lending purposes.
By installing or using the Extension, you acknowledge that you have read and understood this Privacy Policy.