Legal
Last updated 7 August 2026
Overshot is a research tool for public TikTok posts, run by [[LEGAL_ENTITY_NAME]] — placeholder, not yet filled in. This page says exactly what it stores about you, who else sees it, and how to get rid of it. It is specific rather than generic, because a policy that lists data types we do not collect is a policy nobody can check.
Short version: browsing is anonymous and requires no account. If you make one, we store your email address and roughly nine other columns. There is one cookie for signing in and one counter cookie. We do not run analytics, ad pixels, session recording or a chat widget, and there is no third-party JavaScript on any page of this site.
These are the actual columns on the users row, in full:
Alongside that row: your sessions (see cookies below), any live email confirmation or password reset codes (hashed, single-use, expiring), your saved videos and saved products, and your usage grants.
Tier limits are metered through a table of grants — one row per thing you have been given, never a log of what you looked at. There is a row when you open a full video breakdown, and a row when you run a semantic search.
For a search, the row holds a SHA-256 hash of your normalised query, not the query. That is the whole reason it is a hash: two identical searches have to collide so a page refresh does not spend your quota twice, and that is the only property the meter needs. The table cannot reconstruct what anyone typed, and nobody — including us — can read a search back out of it.
There is no page-view log, no impression table and no read history. Which videos you browsed is not recorded anywhere.
spytok_session — set when you sign in. It holds a random 256-bit token and nothing else: no email, no id, no plan, nothing encoded. Only the SHA-256 of that token is stored on the server, so a database dump is a list of hashes rather than a set of working logins. Marked HttpOnly and SameSite=Lax, and Secure whenever the site is served over HTTPS. Deleting it signs you out.That is the only cookie this site sets. No analytics cookie, no advertising cookie, no third-party cookie of any kind. Nothing on this site loads a script from another domain, which is also why there is no cookie banner: the one above is strictly necessary for the function you asked for.
The index is built from public TikTok posts, read through a third-party API. For each one we store the post's own public metrics, the caption, the creator's public handle, nickname, bio and follower count, and a copy of the video (or its slides) and its cover image, plus the analysis our model writes after watching it.
The copy is not optional. TikTok's CDN links expire in roughly 24 hours — measured: about 24 hours for the video, 23 for the cover — so storing a link instead of the file would leave every thumbnail on this site broken by the next day.
We have no access to anyone's TikTok account and no private data of any kind. Overshot is not affiliated with TikTok or ByteDance. Creators who want a post removed can email overshotapp@gmail.com — placeholder, not yet filled in with the link; we delete the stored media and the analysis.
Everything runs on one server. These are the only third parties involved, and what each one gets:
We do not sell data, we do not share it with advertisers, and we do not train models on anything you write.
Your IP address is visible to the web server on every request, as it is to every website. We use it for two narrow things: rate limiting (so one script cannot hammer the login form or the contact form), and applying the signed-out search allowance. The rate limiter holds counters in memory and forgets everything on restart. Your IP address is also included in the support email when you use the contact form, so an abusive submission can be traced; it is not stored in the database otherwise.
Depending on where you live you may have the right to see what we hold about you, to have it corrected, to have it deleted, to get a copy in a portable format, and to object to particular uses. We honour all of those regardless of where you live, because with this little data there is no reason not to.
To delete your account and everything attached to it, ask through the contact form or email overshotapp@gmail.com — placeholder, not yet filled in from the address on the account. There is no self-service delete button yet — we would rather say that than point you at one that does not exist. Deleting the user row removes, by cascade, every session, every outstanding code, every saved video and product, and every usage grant. Stripe keeps its own invoice records, because tax law requires it to; ask them to erase what they can.
We answer these ourselves and aim to do it within 30 days. If you think we have got something wrong, tell us first — and you can also complain to your local data protection authority.
Overshot is a tool for marketers and is not directed at children. We do not knowingly hold data about anyone under 16. If you believe we do, email us and it will be deleted.
If this policy changes materially, the date at the top changes and — if you have an account — you get an email. The version you are reading is the current one.
See also the terms of service and the refund policy.