| STONK account and authentication data |
Username, password submitted for login or password change, session token, license status, extension version. |
Sign in, license validation, account status, version updates, support, and security. |
Password is transmitted over HTTPS to STONK authentication services and is not saved by the extension in Chrome storage. Session tokens may be stored locally to keep the user signed in. |
| TikTok authentication/session data |
TikTok Shop or TikTok Ads cookies, CSRF values, active session state, seller identifiers, advertiser identifiers. |
Read or submit TikTok Shop/TikTok Ads workflows requested by the user, such as reports, campaign operations, shop/account mapping, and automation within the user's authorized account. |
Stored locally when needed for the user's workflow. Sent to STONK cloud only if the user enables cloud sync, backup, multi-device access, or a related user-requested automation feature. |
| Website content and business resources |
Shop names, seller IDs, product IDs, product names, campaign names, campaign IDs, video IDs, creator names, live room IDs, promotion information, page tables, and visible operational page state. |
Show dashboards, detect shop context, build reports, analyze Ads/Content/LIVE status, and perform user-requested shop, campaign, video, and product workflows. |
Usually stored locally as cache or operational state. Selected data may be sent to configured report destinations or STONK sync services when the user enables those features. |
| Shop, Ads, LIVE, content, and report metrics |
Revenue, GMV, ad spend, ROI, CPO, order count, clicks, impressions, views, CTR, CVR, budgets, balances, product performance, LIVE metrics, video performance, and report date ranges. |
Generate dashboards, reports, quick recap messages, business alerts, campaign recommendations, and operational task queues. |
Stored locally and optionally transmitted to STONK services, Telegram, Zalo, Google Sheets, Apps Script, or Gemini only when the user enables or starts those features. |
| User settings and configuration |
Selected shops, privacy-consent record, feature toggles, report schedules, timezone, currency settings, manual exchange rates, profit margin settings, sync server URL, local relay URL, and automation settings. |
Remember user preferences, run scheduled reports, prevent duplicate sends, and keep workflows consistent across sessions. |
Stored in Chrome local storage; limited video-tool preferences may use Chrome Sync so the user's own Chrome profile can synchronize them. Selected settings may be backed up to STONK cloud only if the user enables cloud sync or account backup. |
| Optional integration credentials |
Telegram bot token, Telegram chat IDs/topic IDs, Zalo group/user IDs, Zalo relay host, Google Apps Script or Google Sheets URLs, Gemini API key, local relay secret. |
Send reports or alerts, export to Sheets, request AI analysis, or connect to user-configured local/third-party workflows. |
Stored locally unless the user enables sync/backup. Transmitted only to the configured destination or STONK service required to provide the enabled feature. |
| Downloaded media metadata |
TikTok video URLs or IDs, creator names, product labels, download status, and generated filenames. |
Support user-requested TikTok video viewing or download features. |
Stored locally as operational state. Sent to Tikwm only when the user starts a video download or video retrieval action. |
| Diagnostics and logs |
Scheduler state, sync status, send status, request status, error messages, queue status, retry status, and duplicate-send prevention keys. |
Operate scheduled workflows, troubleshoot failures, prevent duplicate sends, maintain reliability, and support security investigations. |
Stored locally. Relevant diagnostics may be transmitted to STONK support/services only for support, reliability, security, abuse prevention, or user-requested troubleshooting. |
| Authorized organization and role data |
Assigned username, role, organization/shop ownership, permitted child shops, and operator-to-shop mappings. |
Restrict each user to authorized shops, allow an authorized organization administrator to manage assigned users/shops, and support scheduled reporting for those shops. |
Stored locally and on STONK servers as required for account authorization, cloud synchronization and organization administration. |