1. Definitions
For purposes of this Data Processing Addendum, the following terms apply. Capitalized terms not defined here have the meanings given in the Tokokino Terms of Service or other written agreement that incorporates this Addendum.
- Affiliate
- Any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where control means ownership of more than 50% of the voting interests or equivalent authority.
- Customer Personal Data
- Personal Data that Customer provides to Tokokino, or that Tokokino processes on Customer's behalf, through hosted account, sharing, draft, support, or related service features.
- Data Protection Laws
- Applicable privacy and data protection laws, including the GDPR, UK GDPR, CCPA/CPRA, the Swiss Federal Act on Data Protection, and similar laws that apply to the processing.
- EU Area
- The European Union, European Economic Area, United Kingdom, and Switzerland.
- Personal Data
- Information relating to an identified or identifiable natural person, as defined by applicable Data Protection Laws.
- Processing
- Any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, deletion, or destruction.
- Security Incident
- A confirmed unauthorized or unlawful disclosure of, access to, loss of, or destruction of Customer Personal Data.
- Sub-processor
- A third party engaged by Tokokino to process Customer Personal Data on behalf of Customer.
- Standard Contractual Clauses or SCCs
- The contractual clauses adopted by the European Commission for transfers of Personal Data to third countries, as amended or replaced from time to time.
2. Scope
This Addendum applies to Tokokino's Processing of Customer Personal Data in connection with the hosted Tokokino services, including account authentication, public sharing, saved drafts, support communications, and related operational systems, to the extent such Processing is subject to Data Protection Laws.
Tokokino's editor is local-first by default. Screenshots and styling work remain in the user's browser unless the user chooses to sign in, save, upload, share, or otherwise use a server-backed feature.
Except as modified by this Addendum, the Agreement remains in effect. If this Addendum conflicts with the Agreement on data protection matters, this Addendum controls for those matters.
3. Party Roles
Customer acts as the Controller, or Business where applicable under the CCPA/CPRA, for Customer Personal Data.
Tokokino acts as the Processor, or Service Provider where applicable under the CCPA/CPRA, when it processes Customer Personal Data on Customer's behalf to provide hosted service features.
Customer is responsible for providing required notices, obtaining required consents, and ensuring that Customer Personal Data, including Personal Data contained in screenshots, uploads, filenames, text layers, or shared images, may lawfully be processed through the Services.
4. Data Processing Obligations
With respect to Customer Personal Data, Tokokino will:
- Process Customer Personal Data only on Customer's documented instructions, including as necessary to provide, secure, maintain, support, and improve the Services, unless applicable law requires otherwise.
- Ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
- Implement and maintain reasonable technical and organizational security measures designed to protect Customer Personal Data against unauthorized Processing and accidental loss, destruction, or damage.
- Engage Sub-processors only as described in this Addendum and remain responsible for their performance to the extent required by Data Protection Laws.
- Promptly notify Customer of any legally binding request for disclosure of Customer Personal Data by a public authority unless legally prohibited from doing so.
- Notify Customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data.
- Provide reasonable assistance with data subject rights requests to the extent Tokokino can do so based on the hosted Services and Customer's use of them.
- Upon termination or expiry of the Agreement, delete or return Customer Personal Data in Tokokino's possession upon Customer's reasonable request, unless retention is required by law or needed for legitimate security, dispute, or backup lifecycle purposes.
- Make available information reasonably necessary to demonstrate compliance with this Addendum, subject to confidentiality, security, and reasonable scope limitations.
5. International Data Transfers
Tokokino and its Sub-processors may process Customer Personal Data in the United States, India, and other countries where infrastructure or service providers operate. Where Customer Personal Data from the EU Area is transferred to a country that has not been deemed adequate, the parties agree to use appropriate safeguards required by Data Protection Laws.
- GDPR Transfers: the European Commission's Standard Contractual Clauses, Module Two for controller-to-processor transfers, are incorporated by reference where applicable.
- UK Transfers: the UK International Data Transfer Addendum to the EU SCCs applies where required for Personal Data subject to the UK GDPR.
- Swiss Transfers: the SCCs apply with modifications required by the Swiss Federal Act on Data Protection, including references to the competent Swiss supervisory authority where needed.
- AI/ML Processing: Tokokino is a screenshot editing and sharing tool. As of the Last Updated date, Tokokino does not use Customer Personal Data to train external AI or machine learning models.
6. Security Measures
Tokokino maintains reasonable technical and organizational measures appropriate for the nature of the hosted Services and the open-source project. These measures include:
6.1 Information Security Management
- Security-conscious project maintenance, dependency review, and issue response processes.
- Use of managed infrastructure providers for hosting, database, object storage, message queues, CDN delivery, and platform security controls.
- Periodic review of security-sensitive code paths, including authentication, sharing, storage, account deletion, and export proxy behavior.
6.2 Personnel Security
- Access to production data and service administration is limited to people with a legitimate operational need.
- Private support, account, or legal requests are handled through restricted communication channels when possible.
6.3 Access Controls
- Authentication is required for account-backed features such as share history, drafts, and other user-specific hosted features.
- Administrative access is restricted and protected by provider-level authentication controls.
- Tokokino follows the principle of least privilege for infrastructure and data access where supported by service providers.
6.4 Infrastructure & Network Security
- Hosted traffic is served over HTTPS/TLS through managed edge infrastructure.
- Share images and draft data are stored in Cloudflare R2, while share, draft, preset, and account metadata are stored in Cloudflare D1.
- Background jobs such as account deletion are processed asynchronously through Cloudflare Queues.
- Public share links are accessible to anyone with the URL; users should avoid sharing content that they do not want made public.
- Server routes validate request types and size limits for upload and sharing workflows.
- External image export requests are proxied through a controlled API route to support browser rendering while reducing direct client-side CORS exposure.
7. Sub-processors
Customer gives Tokokino general authorization to use Sub-processors for the purposes described in this Addendum. Tokokino will impose data protection obligations on Sub-processors where required by applicable Data Protection Laws and remains responsible for Sub-processor performance to the extent required by law.
Tokokino will provide notice of material new Sub-processors by updating this page or another reasonably accessible notice. If Customer objects on reasonable data protection grounds, Customer may stop using the affected hosted Services or contact Tokokino to discuss the concern.
8. Security Incident Notification
Tokokino will notify Customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data, and where feasible within 72 hours. Notice may be provided by email, in-product notice, repository notice, or another reasonable communication channel depending on the nature of the incident and available contact information.
The notice will include available information about the nature of the Security Incident, affected data categories, likely consequences, mitigation steps, and a point of contact for follow-up. Tokokino will take reasonable steps to investigate, mitigate, and remediate confirmed Security Incidents.
9. Data Subject Rights
Tokokino will provide reasonable assistance to Customer in responding to data subject rights requests, including access, correction, deletion, restriction, portability, objection, and withdrawal requests, to the extent such requests relate to Customer Personal Data processed through hosted Services.
Privacy requests may be sent to hello@theshiva.xyz. Requests should include enough detail to identify the relevant account, public share URL, draft, or support communication.
10. Indemnification
Customer will indemnify and hold harmless Tokokino, its maintainer, contributors, service providers, and agents from third-party claims, damages, losses, costs, and expenses arising from Customer's breach of this Addendum, unlawful Customer instructions, or Customer's failure to comply with applicable Data Protection Laws.
11. Compliance Standards
Tokokino will comply with Data Protection Laws that apply to its Processing of Customer Personal Data. Tokokino does not currently claim certification under ISO 27001, SOC 2, HIPAA, PCI DSS, or similar compliance frameworks unless a separate written notice expressly says so.
12. Term and Termination
This Addendum remains in effect for the duration of the Agreement and terminates automatically when the Agreement terminates or expires. Provisions that by their nature should survive termination, including confidentiality, security, deletion, indemnification, and liability provisions, will survive.
Annex 1: Details of Processing
- Data Exporter (Controller)
- Customer, as defined in the Agreement, including users or organizations that choose to use hosted Tokokino features.
- Data Importer (Processor)
- Tokokino, the open-source screenshot beautifier project and any official hosted service operated for Tokokino.
- Categories of Data Subjects
- Customer's users, team members, end users, and other people whose Personal Data appears in account data, support requests, screenshots, uploads, drafts, shared images, or related metadata.
- Categories of Personal Data
- Names, email addresses, authentication identifiers, avatars where supplied by an identity provider, share and draft metadata, rendered shared images, screenshots or text uploaded by Customer, support messages, operational logs, and technical diagnostics.
- Purpose of Processing
- Providing authentication, editor-related hosted features, public sharing, draft storage, export support, account deletion and related cleanup, abuse prevention, security, debugging, support, and service improvement.
- Duration of Processing
- For the duration of the Agreement, unless deleted earlier by Customer, removed through normal lifecycle management, or retained where required by law or legitimate security, backup, or dispute needs.
- CCPA Business Purposes
- Performing services on behalf of Customer, maintaining account and share functionality, detecting security incidents, debugging, protecting against fraud and abuse, improving service quality, and preserving service integrity.
Annex 2: Sub-processors
The following Sub-processors are authorized to process Customer Personal Data for Tokokino hosted Services. Customer-enabled providers are used only when a user chooses the relevant feature or support channel.
Cloud Infrastructure & Hosting
| Sub-processor | Purpose | Entity | Location |
|---|---|---|---|
| Cloudflare Workers & CDN | Application hosting, request routing, CDN delivery, edge security controls, and operational logging for hosted service traffic. | Cloudflare, Inc. | United States / Global |
| Cloudflare D1 | Managed relational database used for account, share, draft metadata, and other application records. | Cloudflare, Inc. | United States / Global |
| Cloudflare R2 | Object storage used for hosted share images, draft state files, thumbnails, and related uploaded assets. | Cloudflare, Inc. | United States / Global |
| Cloudflare Queues | Managed message queue used for asynchronous background jobs such as account deletion and related cleanup workflows. | Cloudflare, Inc. | United States / Global |
| Cloudflare Browser Rendering | Optional remote browser automation and rendering infrastructure used for browser-based capture features when enabled. | Cloudflare, Inc. | United States / Global |
| PostHog | Optional product analytics and exception reporting used to understand feature usage and to detect, investigate, and remediate service issues. | PostHog, Inc. | United States / Global |
Authentication & Account Access
| Sub-processor | Purpose | Entity | Location |
|---|---|---|---|
| Google OAuth | Optional sign-in provider when a user chooses Google authentication. | Google LLC | United States / Global |
Customer-Enabled Content Sources
| Sub-processor | Purpose | Entity | Location |
|---|---|---|---|
| Unsplash | Optional image search and download flow when a user chooses Unsplash backgrounds or image assets. | Unsplash Inc. | United States |
| GitHub | Public repository hosting, issue discussion, security reports, and support communications submitted through the project repository. | GitHub, Inc. | United States |
Contact
For questions about this Data Processing Addendum, contact Tokokino at hello@theshiva.xyz.