Legal information
Privacy Policy
This policy explains what information Auto Publisher processes, why it is needed, how it is protected, and how users can revoke authorization or request deletion.
1. Scope and responsible entity
This Privacy Policy applies to the Auto Publisher desktop application, related support interactions, and the public website at [DOMAIN_NAME] (together, the “Service”). The Service is operated by [LEGAL_ENTITY_NAME] (“we,” “us,” or “our”), located at [BUSINESS_ADDRESS].
Auto Publisher is intended for creators and account managers who own an account or have authorization to manage it. TikTok, Google, and YouTube operate independently and process information under their own privacy policies.
2. Data we process
The data processed depends on the accounts you connect and the functions you choose to use.
| Category | Examples | Source |
|---|---|---|
| Account identification | TikTok open_id, TikTok display name, and supported profile or account metadata; Google/YouTube account or channel identifiers and display names. | Provided by TikTok or Google/YouTube after you authorize access. |
| Authorization data | OAuth access tokens, refresh tokens where provided, authorization scope, token status, and expiration information. | Issued by the platform after official OAuth authorization. |
| Video and publishing content | Selected video files or references, titles, descriptions, captions, destination account, grouping information, and chosen schedule. | Provided or selected by the user in the desktop application. |
| Publishing records | Draft, ready, scheduled, in-progress, successful, or failed status; requested publishing time; platform response identifiers; and error information needed to explain a failed attempt. | Created as the user operates the Service and as platforms return publishing results. |
| Support data | Email address, message contents, troubleshooting details, and information included in a privacy or deletion request. | Provided directly by the user. |
| Website technical data | Standard hosting logs such as IP address, browser type, requested page, timestamp, and security events. The public website does not intentionally use advertising trackers or account sign-in cookies. | Processed automatically by the website hosting and security provider. |
3. How we use data
We process data only as reasonably necessary to provide, secure, and support the Service, including to:
- identify the TikTok or YouTube account that the user has authorized;
- display the connected account, including the TikTok open_id and display name where made available;
- use OAuth tokens to perform authorized account and publishing functions requested by the user;
- organize video materials and user-created groups;
- save publishing content, schedules, and the user’s active confirmation;
- create publishing records so the user can review pending, successful, or failed activity;
- diagnose errors, protect the Service, prevent unauthorized use, and provide support;
- comply with legal obligations and enforce our Terms of Service.
OAuth tokens are used to call platform functions within the permissions granted by the user. They are not used to obtain a user’s platform password, and they are not used for artificial engagement, automated social interaction, unsolicited messaging, or avoidance of platform safeguards.
4. Platform passwords and verification codes
We do not collect or store TikTok passwords, Google passwords, or one-time verification codes. Platform authentication takes place on the official TikTok or Google authorization page. You should never send a platform password, verification code, client secret, access token, or refresh token to our support address.
5. Data retention
We retain information only for the period needed for the purposes described in this policy:
- OAuth tokens: retained while the account remains connected and the authorization is active. They are removed from active use or invalidated after disconnection or revocation, subject to short-lived protected backups that are overwritten through the normal backup cycle.
- Account identifiers and display names: retained while the connected account is used in the Service, or until the user removes the account or requests deletion, unless retention is required by law.
- Publishing content and records: retained while the user keeps them in the Service for workflow history, or until the user deletes them or requests deletion, subject to legal, security, dispute-resolution, and backup requirements.
- Support correspondence: retained only as long as reasonably necessary to resolve the request, document the resolution, maintain security, and meet legal obligations.
- Hosting and security logs: retained according to the website hosting provider’s standard security and logging cycle.
When a retention purpose ends, data is deleted, de-identified, or allowed to expire. If applicable law requires a longer period, we retain only the information required for that period and limit its use accordingly.
6. Data storage and security measures
We use reasonable administrative and technical measures appropriate to the nature of the information. These measures include restricting access to authorized functions, protecting OAuth tokens from display in the public website or ordinary user interfaces, limiting data access to operational need, using encrypted transport such as HTTPS for supported network communications, and maintaining software and access controls.
No storage or transmission method can be guaranteed to be completely secure. Users should protect the device running Auto Publisher, apply operating-system security updates, restrict access to local user accounts, and promptly revoke platform access if a device or authorization may be compromised.
7. Data sharing and disclosure
We do not sell personal information. We may disclose limited data only in the following circumstances:
- Platforms at your direction: to TikTok or Google/YouTube when you request an account or publishing function.
- Service providers: to infrastructure, security, hosting, or support providers that process data for us under appropriate restrictions.
- Legal and safety reasons: when reasonably necessary to comply with law, legal process, protect rights or safety, investigate misuse, or secure the Service.
- Business transfer: as part of a merger, acquisition, reorganization, or transfer of assets, subject to applicable law and continued protection of the information.
- With your instruction or consent: when you clearly direct us to share information.
We do not share OAuth tokens with advertisers, data brokers, or unrelated third parties.
8. How to revoke account authorization
You can stop Auto Publisher’s future platform access at any time:
- Open the account management area in Auto Publisher.
- Select the connected TikTok or YouTube account.
- Choose the available disconnect or revoke action and confirm.
You may also revoke access from the connected apps or security settings provided by TikTok or your Google Account. Revocation stops future authorized API access, but it does not automatically remove publishing records or content already stored in the Service. Use the deletion process below if you also want those records deleted.
9. How to request data deletion
To request deletion, email [SUPPORT_EMAIL] with the subject “Auto Publisher Data Deletion Request.” Include enough information to identify the connected account, such as the platform and display name, but do not include passwords, verification codes, OAuth tokens, client secrets, or other sensitive credentials.
We may ask for reasonable verification that you control the relevant account before acting on the request. After verification, we will delete or de-identify data within the scope of the request unless it must be retained for legal, security, fraud-prevention, or dispute-resolution reasons. Protected backup copies may remain inaccessible until they are overwritten through the normal backup cycle.
Revoking platform authorization and requesting deletion are separate actions. For the most complete result, revoke the account connection and submit a deletion request.
10. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding personal information, and to appeal or complain to a data protection authority. We will respond to verified requests as required by applicable law.
You can also choose not to connect a platform account, disconnect a connected account, remove content and publishing records using available product controls, or stop using the Service.
11. Policy changes
We may update this policy when the Service, legal requirements, or data practices change. The “Last updated” date above identifies the current version. Material changes will be communicated through the Service or another reasonable method where required.
12. Contact us
For privacy questions, revocation assistance, or data requests, contact:
[LEGAL_ENTITY_NAME]
[BUSINESS_ADDRESS]
Email: [SUPPORT_EMAIL]
Website: [DOMAIN_NAME]