Legal
Privacy Policy
This Privacy Policy explains how ShortDrama Downloader handles personal information when you visit our websites, use the TikTok ShortDrama Downloader app for Windows, buy a plan, or contact us. It says what we collect, why we collect it, who we share it with, how long we keep it, and what rights you have.
Key points
- No account and no password with us. A paid plan is just a licence key. You sign in to your own TikTok account inside the app; your TikTok password and sign-in stay between your PC and TikTok.
- Your videos stay on your PC. The app saves videos directly from the video platform to your computer. We do not receive your videos, your library, your file names, your searches or your watch history.
- The app does send us some information so that licences and the Free plan work: a device ID for your PC, your computer name (not your Windows user name), the app version, and regular licence checks. On the Free plan, it also sends the ID of each new series you start.
- Stripe handles payments. We never receive your full card number. We receive your email address and the details of your purchase.
- No selling and no ads. We do not sell your personal information or use it for targeted advertising. The app and our websites contain no ads and no analytics or tracking tools.
- A few providers help us run the service: Cloudflare, Stripe, Resend, Telegram, GitHub and Google (Gmail hosts our support mailbox). The app’s sign-in and search windows use Microsoft’s Edge WebView2 browser component.
- You have rights. Email support@shortdramadownloader.com to see, correct or delete your information.
This box is a short summary only. It does not replace the full policy below.
1. Who we are
TikTok ShortDrama Downloader is made by ShortDrama Downloader (“ShortDrama Downloader”, “we”, “us” or “our”). ShortDrama Downloader is operated by a company in the State of Florida, United States.
We are responsible for the personal information described in this policy. Under the EU and UK General Data Protection Regulation (“GDPR”) we are the “controller”. Under the California Consumer Privacy Act we are a “business”, to the extent that law applies to us.
This policy covers:
- our websites shortdramadownloader.com, tiktok.shortdramadownloader.com and pinedrama.shortdramadownloader.com;
- the TikTok ShortDrama Downloader app for Windows (also offered as PineDrama Downloader);
- our licence and payment services, including our checkout pages at pay.shortdramadownloader.com, and the emails they send; and
- our support channels (email and Telegram).
Together, these are the “Services”.
TikTok ShortDrama Downloader is an independent product. It is not affiliated with, endorsed or sponsored by TikTok, PineDrama, ByteDance, or any video platform. Those companies, and other websites the Services link to, have their own privacy policies (see section 17).
This policy is a notice. It is not a contract, and you are not asked to “agree” to it. Our Terms of Service and Refund Policy apply separately. Nothing in this policy, or in our Terms, limits any right you have under data protection law that cannot be limited by contract.
2. Key terms
In this policy, these words have the following meanings:
- App: the TikTok ShortDrama Downloader desktop application for Windows.
- Websites: the websites listed in section 1.
- Personal information: information that identifies you, or that can reasonably be linked to you or to your device, directly or indirectly. It includes “personal data” under the GDPR.
- Device ID: a code the App uses to recognize your PC (see section 3.2).
- Device label: your computer’s name (the name Windows shows for your PC), which the App sends to our licence server. The App does not send your Windows user name.
- Licence key (or “key”): the code you receive when you buy a paid plan. It looks like TSD-XXXXX-XXXXX-XXXXX-XXXXX-XXXXX.
- Platform: a third-party short-drama service or website whose videos the App helps you save, such as TikTok and PineDrama. We do not own or control any Platform.
- Service provider: a company that handles personal information for us, on our instructions. Under the GDPR this is a “processor”.
- Process: anything done with personal information, such as collecting, storing, using, sharing or deleting it.
Words defined in our Terms of Service mean the same things here. In this policy, “Services” means the Service, “Free plan” means the Free Plan, “licence key” means a Licence Key, “Platform” means a Third-Party Platform, and “service provider” means a Service Provider, each as defined in the Terms.
3. Information we collect
We collect only what we need to run the Services. What we collect depends on how you use them.
3.1 When you visit our Websites
- Technical data. Our Websites are hosted and protected by Cloudflare. When you visit, Cloudflare receives your IP address and the technical information your browser sends, such as the browser type and the page you asked for. This is needed to deliver pages to you and to protect the Websites from attacks.
- No visitor tracking. Our Websites do not use analytics, advertising or tracking tools. See section 16.
- Theme choice. If you choose the light or dark theme, your browser remembers it on your own device. It is not sent to us.
The Websites have no sign-up or contact forms. They do not ask for your name or email address.
3.2 When you use the App
The App runs on your PC, and most of what it does never reaches us. To make licences and the Free plan work, the App sends the following to our licence server:
- Device ID. The App creates a code that identifies your Windows installation. It does this by applying a one-way mathematical function (a “hash”) to an identifier that Windows gives your installation, together with the App’s name, so the original identifier is not sent to us. If that identifier is not available, the App creates a random code instead. The device ID does not contain your name, but it is linked to your PC, so we treat it as personal information. The App sends it with every request described in this section.
- Licence checks and activity. When the App starts, and then about every 5 minutes while it runs, the App asks our server for your plan. With each check it sends your device ID, the App version, your device label and, if you have entered one, your licence key and your device security code (see below). We keep an activity record for your device only once it has a licence or has started a free series: when it was first and last seen, whether it has a licence, the App version and the device label. A device that only checks its plan is not recorded. On an unusually busy day, a new device on the Free plan may be recorded from its next day of use instead. For a licensed PC, we also record the network it checks in from (see section 3.9). A licensed PC can keep working offline for up to 72 hours after its last successful check. The Free plan needs an internet connection.
- Free plan download records. On the Free plan, each time you start downloading a series you have not downloaded before on that PC, the App sends our server your device ID, the App version and the ID of that series. We record the series ID and the time, and we keep a running total for your device. We also record the network the request came from (see section 3.9). We use this to apply the limit of 2 new series per device per day (the day resets at 00:00 UTC), and so that a series you already started stays free to finish (while your device keeps using the App; see section 11). Because this is a list of series, it can show what kind of dramas you like. We do not collect these records while your device has an active licence.
- Activation. When you activate a licence key, the App sends the key, your device ID and your device label. The device label is your computer’s name, for example “LIVING-ROOM-PC”. If you gave your PC a name that includes your own name, the device label includes it too. The App does not send your Windows user name. We store the device label with the key so that our support team can see which PC holds a key, for example if you ask us to reset a key for a lost or broken PC. We may also use it to prevent fraud and to respond to a payment dispute about that key (see section 5). We remove the device label from the key’s record when you deactivate that PC (“Deactivate this PC” in the App) or when we reset the key. It remains in your device’s activity record (see section 11).
- Device security code. When a PC is activated, our server gives it a random security code that ties the key to that PC. We keep only a one-way hash of this code, never the code itself. On your PC, the code (and your licence key) are protected with Windows’ built-in data protection for your Windows user account. We delete our copy when you deactivate the PC or when we reset the key.
- Moves and activation limits. A key can be moved to another PC only once every 7 days, and a key can be activated only a limited number of times per PC in 24 hours (currently 6). To apply these rules, we record when a key was activated and when it was last moved.
- Buying in the App. When you buy from inside the App, the App asks our payment server to start a Stripe checkout for your chosen plan and opens it in your web browser. It then asks our payment server, using the checkout’s reference number, whether your key is ready, so that it can activate the key on that PC automatically.
- Managing your subscription. When you choose “Manage subscription” in the App, the App sends your device ID and your licence key to our payment server. If a new key replaced a Monthly or Yearly key on that PC, the App keeps the earlier key (protected like your key), and when you ask for the old subscription’s billing link it sends that key too. Our licence server checks that the key belongs to that PC’s licence, and uses the keys to find the Stripe customer record and the email address of each purchase. Our payment server also asks Stripe for other completed purchases made with the same email address, to find any other active subscription to the App. It then emails secure links to Stripe’s billing portal to the email address used for your purchase, including links for those other subscriptions. If the earlier key was bought with a different email address, that subscription’s link is not included, and nothing is sent to that address; you can cancel that subscription from that purchase’s own emails (for example, its receipt) or by contacting us. We send at most one such email to an address per hour; if you ask again within the hour, no new email is sent. The links are never shown on screen.
What the App keeps on your PC, and what it does not send us, is explained in section 4, section 11 and section 16.
3.3 Your sign-in to TikTok
To search and download, the App asks you to sign in to your own TikTok account, in a sign-in window inside the App. You sign in directly with TikTok: your password goes to TikTok, never to us. The App keeps the resulting sign-in session (cookies and the sign-in window’s browser data) and your TikTok display name, username and profile picture address in its folder on your PC. It uses them only to connect your PC to TikTok, and to show which account is signed in. None of this is sent to us. You can sign out at any time in the App’s Settings (“Log out”).
Microsoft’s browser component. The sign-in window, and the hidden browser window the App uses to search and to open the links you paste, are Microsoft Edge WebView2, a browser component that Microsoft provides for Windows. Like the Microsoft Edge browser, it may check the addresses of the pages it opens with Microsoft Defender SmartScreen, which warns about phishing and malware sites, and it may send diagnostic data to Microsoft according to your Windows settings. Microsoft handles this information under its own privacy statement. We do not receive it.
3.4 When you buy a plan
When you buy on our Websites, you first open our checkout page at pay.shortdramadownloader.com. It runs Cloudflare Turnstile, a security check that helps stop automated abuse; Cloudflare processes information about your browser and connection to do this. You then pay on a checkout page hosted by Stripe, which opens in your own web browser. Stripe collects your payment details (for example card number, expiry date and security code, or the details of another payment method), your billing address where needed, and the cardholder’s name. We never receive your full card number or security code.
After you pay, we receive from Stripe and store:
- your email address;
- Stripe reference numbers for you as a customer and for your checkout session, payment and subscription;
- your plan, the amount and the currency; and
- the payment status (for example active, cancelled or refunded).
We store these together with your licence key. We also save your email address as a label on your key’s record, so that we can find your key if you contact us. After checkout, your key is shown on the success page (for up to 3 hours) and sent to you by email. If you buy from inside the App, the key is activated on that PC automatically.
Stripe’s checkout also records that you ticked the box agreeing to our Terms of Service and Refund Policy. Stripe keeps that record for us, in our Stripe account; we do not copy it into our own database. Our payment server reads it only to repeat, in the email with your licence key, what you agreed to at checkout.
Team alerts. When a payment needs our attention (for example, a refund, a payment dispute, an early warning from a card issuer that a payment may be fraudulent, one email address holding two active subscriptions for the same app, or a key email that could not be sent), our payment system sends an automatic alert to our team, by email or in our private Telegram chat. To check for a second subscription, after each purchase our payment server asks Stripe for other completed purchases made with the same email address. Alert emails are sent through Resend to our support mailbox, which is hosted by Google (Gmail). An alert can include the buyer’s email address, the licence key, the plan and Stripe reference numbers. An alert itself changes nothing. For example, after an early fraud warning, a partial refund or a dispute that is only an inquiry, a person on our team reviews the payment and decides what to do; only a full refund or a chargeback turns a key off automatically (see section 7).
Stripe also emails you, for us, a receipt for each payment (including each renewal) and, for the Yearly plan, a reminder 30 days before each renewal. Stripe’s privacy policy also applies to these emails.
3.5 Emails
- Emails we send. We send service emails through Resend, our email delivery provider, such as the email with your licence key after you buy (which also confirms your order and what you agreed to at checkout) and the email with your billing-portal link when you ask for it. Resend receives your email address and the content of the email, which includes your key or your link. We do not currently send marketing emails.
- Emails you send us. Emails to support@shortdramadownloader.com are delivered through Cloudflare’s email routing service to our support mailbox, which is hosted by Google (Gmail). Google stores these emails for us. We receive your email address, any name shown with it, your message and any attachments.
3.6 Telegram support chat
If you message our support on Telegram (@M4st3r0), we receive from Telegram your name and username (as you set them in Telegram) and your messages, and anything you choose to send, such as screenshots or files. These stay in our Telegram chat history. We do not copy them into our own databases.
3.7 Finding and saving videos
When you search, browse, open a title or save videos, your PC connects directly to the Platform, using your own sign-in. We do not receive that traffic, your searches or the list of what you save. See section 17. (The only exception is the Free plan record in section 3.2: the ID of each new series you start.)
3.8 Open-source tools
The App uses three open-source tools to save videos: yt-dlp, FFmpeg and aria2. They come with the App’s installer. If one of them is missing and you choose “Get tools” in the App, the App downloads yt-dlp and aria2 from the release pages of those projects on GitHub (a Microsoft company), and FFmpeg from the FFmpeg-Builds project on GitHub (builds of FFmpeg made by an independent developer, BtbN, not by the FFmpeg project itself). GitHub then receives your IP address and a general app name in the request. The App does not currently check for updates to itself.
3.9 Security and abuse prevention
Our servers use your IP address for a short time to apply rate limits, which stop abuse. For App, licence and payment requests, our own code does not store your full IP address, and request logging is switched off on our licence and payment servers. To detect abuse, our licence server keeps two kinds of network records. They identify a network only by a shortened IP address (the network part: the first three numbers of an IPv4 address, or the first three groups of an IPv6 address), never by your full address:
- Licensed PCs. For each licence key and PC, each network the PC checks in from, with the time it was first and last seen there. We use these records to detect a key that is shared or copied to other PCs, for example one key used from several networks at the same time. Each record is deleted 90 days after the PC last checked in from that network.
- Free plan. For each network and day (UTC), the device IDs that started a new free series there. We use these records to detect many different device IDs taking free series from one network, for example someone changing their device ID to get more free series. They are deleted after 30 days.
We use these records only to spot abuse; they do not block anyone automatically. Our hosting provider, Cloudflare, may keep limited technical logs under its own policy. If someone fails to sign in to our administration tools, we keep the IP address for 15 minutes to block repeated attempts, and delete it within about a day.
3.10 Information from other sources
- Stripe tells us about your payments, renewals, cancellations, refunds and disputes (see section 3.4).
- Telegram gives us your Telegram profile details when you message us (see section 3.6).
- Banks and card issuers, through Stripe, tell us when a payment is disputed, or warn us early that a payment may be fraudulent.
4. What we do not collect
- We do not ask you to create an account with us or a password.
- We never receive your TikTok password, your TikTok sign-in session or your TikTok account details. They stay on your PC.
- We never receive your full card number or card security code. Stripe handles them.
- We do not receive your videos, your library, your file names, your save folder, your searches or what you watch. These stay on your PC.
- The App does not upload its logs. They stay on your PC unless you choose to send them to us.
- We do not collect your contacts, your other files or programs, or anything from your camera or microphone.
- We do not collect your precise location.
- The App and our Websites contain no advertising and no third-party analytics or tracking tools.
5. How we use information
We use personal information only for the purposes below. For people in the European Economic Area (EEA), the UK and Switzerland, the legal basis is shown in brackets. Section 6 explains each basis.
- To run licences. We issue, deliver and activate keys, keep one key on one PC, allow moves, check that a key is valid, apply the 72-hour offline period, and keep a key working when a subscription renews. We use the key, device ID, device label, device security code (hash), activation records and purchase status. (Contract.)
- To run the Free plan. We apply the daily limit of 2 new series per device and let you finish a series you already started. We use the device ID and the series IDs and times. (Contract; legitimate interests in keeping the Free plan fair.)
- To show the right plan in the App. We use the device ID and licence checks. (Contract.)
- To take payments and manage subscriptions. We handle purchases, renewals, failed payments, cancellations and refunds, and send you a billing-portal link when you ask. We use the purchase record and your email address. (Contract; legal obligation for tax and accounting records.)
- To send service emails. We send your key, your billing-portal link and other service emails about your purchase or subscription. (Contract; legal obligation where the law requires a notice.)
- To give support. We answer emails and Telegram messages, look into problems you report, and reset keys for lost or broken PCs. (Contract; legitimate interests in helping users.)
- To keep the Services secure and to prevent fraud and abuse. For example, we apply rate limits, run a security check before checkout, detect keys that are shared or misused, watch for unusual numbers of new devices from one network, act on reports and early warnings of payments made with stolen cards, and protect our administration tools. (Legitimate interests in security and fraud prevention.)
- To respond to payment disputes and chargebacks. If you dispute a payment with your bank or card issuer, we may share purchase, delivery, activation and usage records, and relevant support messages, with Stripe and, through Stripe, with card issuers and card networks. For example: the purchase record and the email address used; that your key email was sent; when and on which device the key was activated, including the device label; when that device last used the App and whether it was licensed; and relevant support emails or chats. (Legitimate interests in preventing fraud and in establishing, exercising or defending legal claims.)
- To understand how the Services are used. We count installs, active devices (for example, how many devices were active in the last 24 hours or 7 days), App versions in use, and how many free series devices have downloaded. (Legitimate interests in running and improving the Services.)
- To comply with the law and enforce our Terms. (Legal obligation; legitimate interests in protecting our rights and those of others.)
We do not use your personal information for advertising, and we do not build profiles about you. If we want to use personal information for a new purpose that does not fit the purposes above, we will tell you first and, where the law requires it, ask for your consent.
6. Legal bases (EEA, UK, Switzerland)
If you are in the EEA, the UK or Switzerland, we must have a legal basis to process your personal information. We rely on these:
- Contract. The processing is needed to provide the Services you use under our Terms, including the Free plan.
- Legitimate interests. The processing is needed for our legitimate interests, and those interests are not overridden by your rights and interests. Our interests are running a secure, fair and working service, preventing fraud and abuse, defending legal claims, and understanding how the Services are used. You can object to this processing (see section 13).
- Legal obligation. The processing is needed to meet a legal duty, such as keeping tax and accounting records or answering a lawful request from an authority.
- Consent. For example, when you choose to send us log files or screenshots. You can withdraw consent at any time. This does not affect processing that happened before you withdrew it.
The App reads or creates the device ID on your PC because this is strictly necessary to provide the licence and Free plan features you use.
Some information is needed for the Services to work. For example, you cannot activate a key without a device ID, and we cannot send you your key without your email address. If this information is not provided, the feature that needs it will not work.
7. Automatic decisions
The Services apply some rules automatically, without a person reviewing each case. For example:
- the Free plan limit of 2 new series per device per day;
- one key on one PC at a time, the limit on activations, and the 7-day wait between moves;
- a key stops working when it expires, or if the PC cannot reach our server for more than 72 hours; and
- when a purchase is refunded in full, or a chargeback is opened (a payment dispute in which the bank or card issuer takes the payment back), our system automatically turns off the key and cancels any subscription.
When a subscription ends for any other reason (for example, it is cancelled), the key keeps working until the end of the period already paid for. A partial refund, a dispute that is only an inquiry (the bank or card issuer asks questions but does not take the payment back) and an early warning from a card issuer that a payment may be fraudulent do not turn off a key automatically: a person on our team reviews them. The network records described in section 3.9 are used only to detect abuse; they do not block anyone automatically.
These rules are needed to provide the Services under our Terms. They do not use profiling. If you think a rule was applied to you by mistake, contact us. A person will review the decision, and you can explain your point of view.
8. Who we share information with
We share personal information only as described in this section.
8.1 Service providers
These companies help us run the Services. They may use personal information only to provide their services to us, except where they act for their own purposes under their own privacy policies, as noted.
| Provider | What it does for us |
|---|---|
| Cloudflare | Hosts our Websites, our licence and payment servers and our databases. Protects the Services from attacks, and runs the Turnstile security check on our checkout page. |
| Stripe | Processes payments and subscriptions. Hosts the checkout page and the billing portal. Sends payment receipts and yearly renewal reminders by email. Stripe may also use information for its own purposes, such as fraud prevention and meeting its legal duties, under its own privacy policy. |
| Resend | Sends our licence-key and billing-link emails, and alerts about payment problems to our team. |
| Telegram | Runs our support chat. Telegram also processes your use of its app under its own privacy policy. |
| Google (Gmail) | Hosts our support mailbox. It stores the emails you send us and the alerts our payment system sends our team, which can include your email address, name, message, licence key, plan and Stripe reference numbers. Google may also use information under its own privacy policy. |
| GitHub (Microsoft) | Hosts the open-source tools the App downloads when you choose “Get tools”. |
| Microsoft (Edge WebView2, Defender SmartScreen) | Provides the browser component the App uses for your TikTok sign-in, for searching and for opening links you paste. Microsoft Defender SmartScreen may check the addresses of the pages it opens, and the component may send diagnostic data to Microsoft according to your Windows settings (see section 3.3). Microsoft acts under its own privacy statement. |
8.2 Payment disputes and fraud prevention
To prevent fraud and to respond to a payment dispute or chargeback, we may share purchase, delivery, activation and usage records, and relevant support messages, with Stripe and, through Stripe, with card issuers, banks and card networks (see section 5).
8.3 Legal reasons
We may share personal information if we believe in good faith that it is needed to: follow the law, a court order or a lawful request from a public authority; enforce our Terms; or protect the rights, property or safety of our users, the public or us.
8.4 Other cases
- Business changes. If our business, or part of it, is sold, merged or reorganized, personal information may be transferred to the new owner. The new owner must continue to protect it as described in this policy.
- Professional advisers. We may share information with our lawyers, accountants and auditors, who must keep it confidential.
- With your permission. We may share information when you ask us to or agree to it.
We do not share your information with any Platform. The App connects your PC to Platforms directly (see section 17).
9. No selling, no ad sharing
We do not sell your personal information. We do not “share” your personal information for cross-context behavioral advertising. These terms have the meanings given in the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We have not sold or shared personal information in the past 12 months. We do not knowingly sell or share the personal information of anyone under 16.
We do not use your personal information for targeted advertising, and we do not allow advertising networks to track you through our Websites or App.
10. International transfers
We are based in the United States, and our service providers operate around the world. Your personal information may be stored and processed in the United States and in other countries where our providers or their partners work. Our databases are hosted by Cloudflare, which may store and process data in several countries.
These countries may have data protection laws that are different from, and sometimes less protective than, the laws where you live.
When we transfer personal information from the EEA, the UK or Switzerland to a country without an “adequacy” decision, we rely on appropriate safeguards. These include the European Commission’s Standard Contractual Clauses (with the UK Addendum where relevant) in our providers’ data processing terms, or a provider’s certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, where available. Some transfers are necessary to provide the Services you ask for, for example when you contact us through Telegram. You can ask us for more information about these safeguards (see section 19).
11. How long we keep information
We keep personal information only for as long as we need it for the purposes in this policy. We may keep information longer if the law requires it, or if we need it for a legal claim or a dispute that is still open. Some records are deleted automatically, as the table below shows: our licence server runs a clean-up every night, and it removes old unpaid checkouts when new checkouts are made. We delete other information when we no longer need it, or when you ask us to and the law allows it (see section 13). The table below explains how long we keep each kind of information.
| Information | How long we keep it |
|---|---|
| Licence record (key, plan, status, the device ID it is linked to, activation and move dates) | While the key exists, and afterwards for as long as we need it to restore a renewed key, answer support questions, handle payment disputes and meet our legal duties. |
| Device label on a key’s record | Until you deactivate that PC in the App or we reset the key. |
| Device security code (hash only) | Until you deactivate that PC or we reset the key. |
| Device activity record (device ID, first seen, last seen, licensed or not, App version, device label, number of free series downloaded) | Deleted automatically once the device has not contacted our licence server for 60 days, unless it was licensed at its last check or a licence key is still activated on it. The record of such a device is kept for as long as we need it for our install and activity statistics, or until you ask us to delete it. |
| Free plan download records (series IDs, times) | Kept while the device keeps using the App, so that the daily limit works and a series you already started stays free to finish. Deleted automatically, with the device activity record, once the device has not contacted our licence server for 60 days (with the same exceptions), or earlier if you ask us to delete them. |
| Network records for licensed PCs (licence key, device ID, shortened IP address, first and last seen) | Deleted automatically 90 days after the PC last checked in from that network. |
| Free plan network records (shortened IP address, day, device ID) | Deleted automatically after 30 days. |
| Purchase and payment records (email, Stripe reference numbers, plan, amount, status) | For as long as we need them for accounting, tax and legal purposes and to handle refunds and payment disputes. Tax law may require us to keep them for several years, and card networks allow some disputes long after a payment. |
| Checkouts that were started but never paid (Stripe reference number, plan, time; no email or key) | Deleted automatically after about 7 days. |
| Team alerts about payment problems (by email) | Kept in our Google (Gmail) mailbox, for the same purposes as the purchase record. |
| Emails we send through Resend | Resend keeps its sending records under its own retention policy. The details we need (your email address and key) are kept as part of the purchase record. |
| Support emails (in our Google (Gmail) mailbox) and Telegram chats | For as long as we need them to help you and to keep a record of what was agreed. |
| IP addresses | Used briefly for rate limits; our code does not store full IP addresses for App, licence or payment requests. Network records (shortened IP addresses only): see the network record rows above. Failed sign-ins to our administration tools: used for 15 minutes to block repeated attempts, and deleted within about a day. Cloudflare may keep limited technical logs under its own policy. |
| Backups of our licence database | We may keep occasional backups. Information deleted from our live systems may remain in a backup until that backup is deleted. |
| Information on your own PC | Under your control. See below. |
Information on your PC. The App keeps its settings, your download queue, your licence file (with your key and device security code protected by Windows), your TikTok sign-in session and profile details, its logs and the tools it uses in the folder %LOCALAPPDATA%\TikTok ShortDrama Downloader. Your videos are in your save folder (by default Videos\TikTok ShortDrama). “Log out” in the App’s Settings signs you out of TikTok on this PC, and “Reset” clears the App’s sign-in, cache and settings (your downloaded videos are kept). When you uninstall the App, it asks whether to also remove your settings and TikTok sign-in from this PC. Only if you answer Yes does it delete the App’s folder above, and it never deletes your downloaded videos. Otherwise, to remove this information completely, delete these folders yourself. If you want to use your key on another PC later, choose “Deactivate this PC” in the App first.
12. Security
We use technical and organizational measures designed to protect personal information. They include:
- Secure connections. The App talks to our servers only over encrypted connections (HTTPS).
- Verified answers. The App checks a digital signature on every answer about your licence, so it only trusts answers that really come from our server.
- No card data. Card details are handled only by Stripe. We check payment notifications from Stripe, and confirm each payment with Stripe, before we issue a key.
- Limited exposure. Your key is shown on the checkout success page for up to 3 hours only. Billing-portal links are sent only to the purchase email address, never shown on screen.
- Device protection. Our server stores only a hash of each PC’s security code. Your PC protects the code and your key with Windows’ built-in data protection.
- Protected systems. Our databases cannot be reached from the internet; only our own server code can use them. Access to our administration tools is limited to authorized people, protected by an access-control service and strong passwords, and locked after repeated wrong attempts.
- Less logging. Request logging is switched off on our licence and payment servers.
- Rate limits and bot checks on our servers help stop abuse.
- Website protections. Our Websites use modern security settings. For example, they force secure connections, load no third-party scripts or fonts and do not allow their pages to be shown inside other websites.
You also have a part to play: keep your licence key private, and keep your PC and Windows account secure.
If a security incident affects your personal information, we will notify you and the relevant authorities where the law requires it.
No method of sending or storing information is completely secure. We cannot guarantee the security of your information. To the extent permitted by law, we are not responsible for unauthorized access to or use of information that happens despite our reasonable security measures.
This does not limit any right you have under data protection law that cannot be limited.
13. Your rights and choices
13.1 Your choices
- Use the Free plan without giving your name. You can use the Free plan without giving us your email address or payment details. The App still sends us a device ID, your device label and the IDs of the series you start (see section 3.2).
- Remove your device label from your key. Choose “Deactivate this PC” in the App. This removes your device label and device security code from your key’s records. (A key can be moved once every 7 days.) To remove it from your device activity record too, ask us (section 13.3).
- Sign out of TikTok. Choose “Log out” in the App’s Settings.
- Delete information on your PC. See section 11.
13.2 Your rights
Depending on where you live, you may have the right to:
- Access (or “know”): ask whether we hold personal information about you, and get a copy of it and details of how we use it.
- Correction: ask us to correct information that is wrong or incomplete.
- Deletion: ask us to delete your information.
- Restriction: ask us to limit how we use your information.
- Objection: object to processing based on legitimate interests.
- Portability: receive the information you gave us in a common, machine-readable format, or ask us to send it to another company where technically possible.
- Withdraw consent where we rely on consent.
- Human review of an automatic decision (see section 7).
- Non-discrimination: we will not treat you differently for using your rights.
- Complain to a data protection authority (see section 13.6).
These rights have limits and exceptions under the law. For example, we may keep purchase records that tax law requires us to keep, and records we need to respond to a payment dispute or a legal claim. Please note: if you ask us to delete the licence records for an active key, the key will stop working, because the App cannot check it without them.
Wherever you live, you can send us a privacy request, and we will consider it.
13.3 How to make a request
Email support@shortdramadownloader.com with “Privacy request” in the subject line. Tell us what you want us to do. If you bought a plan, please write from the email address you used to buy, or include your licence key. You can also message @M4st3r0 on Telegram, but we may ask you to continue by email so that we can verify the request. Requests are free of charge.
13.4 Verification
To protect you, we check that a request comes from the right person before we act on it. We do this by matching details we already hold. For example, we may ask you to reply from the email address used for your purchase, or to confirm your licence key. We ask only for what we need, and we use it only to verify your request.
If you use only the Free plan, we do not know your email address. Our records are linked only to a device ID and a device label. We may ask for your help to identify your device. If we cannot link records to you with reasonable certainty, we will tell you. We are not required to collect extra information only to identify you.
Authorized agents. Where the law allows, you can ask someone else to make a request for you. We will need written permission from you, and we may still ask you to verify your identity directly with us.
13.5 Response times
- EEA, UK and Switzerland: within one month. If a request is complex, or if we receive many requests, we may extend this by up to two more months. If so, we will tell you within the first month.
- California: we confirm receipt within 10 business days and respond within 45 calendar days. We may extend this once by up to 45 more days if needed, and we will tell you if we do.
- Other US states: within 45 days, extendable by up to 45 more days where the law allows.
- Everywhere else: within 30 days, or sooner if your local law requires it.
If a request is clearly unfounded or excessive, we may refuse it or charge a reasonable fee where the law allows. We will explain why.
13.6 Appeals and complaints
If we refuse your request, we will explain why. If you live in a US state that gives you a right to appeal, reply to our decision with “Appeal” in the subject line. We will answer within 60 days, or sooner if your state’s law requires it. If we deny your appeal, you can contact your state’s Attorney General.
If you are in the EEA, you can complain to the data protection authority in the country where you live or work, or where you think a problem happened. In the UK, you can complain to the Information Commissioner’s Office (ICO). In Switzerland, you can complain to the Federal Data Protection and Information Commissioner (FDPIC). Elsewhere, you can contact your local data protection authority. We would be grateful for the chance to help first, so please contact us before you complain.
13.7 Other US states
Residents of some US states, such as Virginia, Colorado, Connecticut, Utah, Texas and Oregon, have privacy rights similar to those above. These include the rights to access, correct, delete and receive a copy of their personal information, and to opt out of targeted advertising, the sale of personal information, and profiling that has legal or similarly significant effects. We do not sell personal information, do not use it for targeted advertising, and do not use it for that kind of profiling. You can use your other rights as described in sections 13.3 to 13.6.
13.8 Other countries
If you live in another country with a data protection law, for example in Asia (such as Singapore, Malaysia, Thailand or the Philippines), you may have similar rights, including the rights to access and correct your information and to withdraw consent. Where your local law relies on consent, you may withdraw it at any time by contacting us. If you do, we may no longer be able to provide some Services to you, and we will explain the effect before we act.
14. California privacy notice
This section adds to the rest of this policy for residents of California. It is given under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), to the extent the CCPA applies to us. We honor the rights described here for all California residents.
14.1 Notice at collection
In the past 12 months, we have collected the following categories of personal information. We collect them for the purposes in section 5, and we keep them for the periods in section 11.
| Category | What we collect | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Device ID, licence key, email address, IP address (briefly; a shortened IP address for the network records in section 3.9), Telegram username, Stripe reference numbers, device label (computer name). | Cloudflare, Stripe, Resend, Telegram, Google (Gmail); GitHub and Microsoft (IP address and technical data only); card issuers and card networks in a payment dispute. |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name (from your Telegram profile or your email) and email address. Payment card details are collected by Stripe, not by us. | Cloudflare, Stripe, Resend, Telegram, Google (Gmail); card issuers and card networks in a payment dispute. |
| Commercial information | Plans bought, amounts, currency, payment and subscription status, refunds and disputes. | Cloudflare, Stripe, Resend, Google (Gmail); card issuers and card networks in a payment dispute. |
| Internet or other electronic network activity | Licence checks and activity times, App version, Free plan series downloads, network records (shortened IP addresses) of licensed PCs and of free downloads. | Cloudflare; Microsoft (addresses of pages the App’s browser component opens, see section 3.3); Stripe, card issuers and card networks in a payment dispute. |
We do not create inferences or profiles about you. We do not use or disclose sensitive personal information for any purpose that would give you a right to limit it under the CCPA.
Sources. We collect personal information from you, from your device through the App and Websites, from Stripe, and from Telegram (see section 3).
Selling and sharing. We do not sell or share personal information, as explained in section 9.
14.2 Your California rights
You have the right to:
- know what personal information we have collected about you, including the categories, the sources, our purposes, the categories of third parties we disclose it to, and the specific pieces of information;
- delete personal information we collected from you, with some exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information (we do neither);
- limit the use of sensitive personal information (we do not use it in a way that gives this right); and
- not be discriminated against for using these rights.
To use these rights, follow the steps in section 13.3. Verification, authorized agents and response times are covered in sections 13.4 and 13.5.
14.3 Other California notices
- Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.
- Do Not Track. Our Websites do not track visitors across other websites, so they do not change their behavior when a browser sends a “Do Not Track” signal. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of sale and sharing. (We do not sell or share personal information.)
- Reviewing and changing your information. You can ask to review and correct your information as described in section 13.
- Changes. We explain how we tell you about changes in section 18.
15. Children
The Services are for adults. They are not directed to anyone under 18, and our Terms require users to be at least 18, or the age of legal majority where they live. We do not knowingly collect personal information from anyone under 18, including children under 13. If you believe a child has given us personal information, please contact us and we will delete it.
16. Cookies, local storage & analytics
16.1 On our Websites
- No cookies from our own code. Our Websites’ own code does not set cookies. Cloudflare, which delivers and protects our Websites, may set strictly necessary security cookies under its own policy.
- Local storage for your theme. If you choose light or dark mode, your browser saves that choice on your device (under the name
sdd-theme). It is not sent to us. - No analytics. Our Websites do not use analytics tools, and they load no third-party scripts or fonts. Our fonts are served from our own Websites.
- Checkout. The Turnstile security check on pay.shortdramadownloader.com is run by Cloudflare. Stripe’s checkout page and billing portal run on Stripe’s own websites and set Stripe’s own cookies, under Stripe’s privacy and cookie policies.
- No advertising cookies or tracking pixels. Our Websites have no advertising cookies, tracking pixels, or embedded third-party video players.
You can clear local storage and cookies at any time in your browser settings.
16.2 In the App
The App’s TikTok sign-in window uses its own browser profile, stored on your PC in the App’s folder. It holds the cookies and site data that TikTok sets when you sign in, and the App keeps a copy of your TikTok sign-in cookies so that it can download for you. These stay on your PC and are sent only to TikTok. (Microsoft’s browser component may check the addresses of the pages it opens with Microsoft Defender SmartScreen; see section 3.3.) The App’s own preferences (such as your theme, save folder and download queue) are kept in files in the same folder.
None of these items are sent to us. The App contains no analytics, tracking or advertising tools. The only information it sends to us is described in section 3.2.
17. Third-party platforms & links
To find and save videos, the App connects your PC directly to the Platform’s website, servers and content delivery networks, using your own sign-in. These parties receive your IP address, your account’s sign-in session and the details of each request, such as your search words and the titles you open. This traffic does not pass through our servers, and we do not receive it.
Platforms, Stripe, Telegram, GitHub, Microsoft, Google and any other website you reach through a link are run by other companies. Their own privacy policies apply to the information they collect. Please read them.
We do not control, and are not responsible for, the privacy practices, content or security of third-party platforms, websites or services. To the extent permitted by law, we are not liable for how they collect or use your information.
18. Changes to this policy
We may update this policy from time to time, for example when the Services or the law change. When we do, we will change the “Last updated” date at the top of this page. If we make a significant change, we will take reasonable steps to tell you before it takes effect, for example with a notice on our Websites, or by email if we have your email address. Where the law requires your consent to a change, we will ask for it.
Earlier versions of this policy are available on request.
19. Contact us
If you have questions about this policy or about your personal information, or you want to make a request, contact us:
- Email: support@shortdramadownloader.com (please write “Privacy request” in the subject line)
- Telegram: @M4st3r0
For privacy requests, email is best, because it lets us verify requests about purchases.
This Privacy Policy explains how we handle personal information. Please read it together with our Terms of Service and Refund Policy.