This policy covers Attrados Publisher, a self-hosted content scheduling dashboard operated by Attrados ("we"). It applies to the TikTok accounts a creator connects to the dashboard and to the data TikTok provides about them through the TikTok for Developers APIs.
Information we collect
When a creator authorizes the dashboard through TikTok Login Kit we receive and store:
- the OAuth access token and refresh token TikTok issues for that account, and the scopes granted;
- the account's TikTok open ID, display name, @username and avatar URL;
- the account's posting constraints returned by TikTok (available privacy levels, whether comments, duets or stitches are disabled, maximum video duration), fetched each time the composer opens and not retained;
- the videos, captions and settings the creator chooses to publish through the dashboard, and the publish status TikTok reports for them;
- if the creator opens the analytics tab, the follower, like and per-video view counts for their own account.
We do not collect data about other TikTok users, and we do not collect anything from the TikTok app on the creator's device.
How we use it
Only to operate the dashboard for that creator: to publish the videos they submit to the account they chose, with the audience and permissions they selected; to keep the connection alive by refreshing tokens; and to show them the outcome and performance of their own posts. We do not use TikTok data for advertising, profiling or model training.
Sharing
We do not sell, rent or share TikTok account data or tokens with any third party. Data leaves our systems only to TikTok itself, over the TikTok APIs, to carry out the creator's request, or where required by law.
Storage and security
Tokens and account data are stored in a database on servers Attrados controls, reachable only over an encrypted private network, with tokens encrypted at rest. Media files awaiting publication are held on the same infrastructure and served over HTTPS only for TikTok to retrieve them.
Retention and deletion
Tokens and account data are kept while the account remains connected. Disconnecting the account in the dashboard deletes its tokens immediately. Media and post records are removed on request. A creator may also revoke the dashboard's access at any time from TikTok's own Settings → Security → Manage app permissions. To request deletion of anything we hold, email karsten@attrados.com; requests are completed within 30 days.
Children
The dashboard is not offered to anyone under 18.
Changes
Material changes to this policy are posted here with a new date.
Contact
Attrados · karsten@attrados.com