Privacy Policy
Last updated 15 August 2026
Social Publisher (“the Service”) is operated by Ryan Evans Dev. This policy explains what the Service collects, why, how it is stored, and how to have it deleted.
The Service does one thing: it publishes videos to social media accounts that you have connected and explicitly authorized. It does not read your feed, message anyone on your behalf, or post anything you have not asked it to post.
What we collect
Account information
Your email address, and a cryptographic hash of your password. Passwords are hashed with scrypt and are never stored in a readable form; nobody, including us, can recover your password from what is stored.
Connected social accounts
When you connect a TikTok account, TikTok returns an account identifier (your open_id), your display name, the permissions you granted, and OAuth access and refresh tokens. We store these so the Service can publish on your behalf without asking you to sign in to TikTok every time.
We never receive or store your TikTok password. Authorization happens on TikTok’s own site.
Content you upload
Video files you upload for publishing, the captions you write, and the status of each publishing attempt, including any error returned by the platform.
Technical information
Ordinary server logs, including IP addresses, used to operate the Service and to rate-limit sign-in and publishing so the Service is not abused. We do not use analytics, advertising, or third-party tracking cookies. The only cookies set are the session cookie that keeps you signed in and a short-lived cookie that protects the account-connection flow against cross-site request forgery.
How your information is used
- To authenticate you and keep you signed in.
- To publish the videos and captions you submit, to the accounts you select, at your instruction.
- To keep your connection to TikTok working by refreshing access tokens before they expire, and to tell you when an account needs reconnecting.
- To show you the status and any errors for each publishing attempt.
- To protect the Service against abuse.
We do not sell your information, share it with advertisers, or use your content to train machine-learning models.
Who your information is shared with
TikTok.The video, caption and publishing settings you submit are sent to TikTok’s Content Posting API in order to create the post you asked for. TikTok’s own privacy policy governs what it does with that content once posted.
Infrastructure providers. The Service runs on Railway, which hosts the application, its database and its file storage on our behalf. They process data only to provide that hosting.
We may disclose information if legally required to do so, or where necessary to investigate abuse of the Service.
How your information is stored
- OAuth access and refresh tokens are encrypted at rest using AES-256-GCM. The encryption key is held only in the server environment and is never stored in the database or in our source code.
- Tokens are never sent to your browser and never written to logs.
- All traffic to the Service is encrypted in transit over HTTPS.
- The Service uses its own dedicated database, isolated from any other site we operate.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data we will notify you at the email address on your account.
How long it is kept
- Account information is kept until you ask for your account to be deleted.
- Tokens for a connected account are deleted immediately when you disconnect that account in the dashboard.
- Uploaded videos and post records are kept until the account is deleted, so you can see the history of what was published.
Your choices
Disconnect an account at any time.Use Disconnect on the dashboard. This deletes the stored tokens for that account. You can also revoke the Service’s access from within TikTok’s own security settings, which we will honour.
Delete your account and data. Email ryanbob10@yahoo.com from the address on your account and we will delete your account, connected-account records, tokens, uploaded videos and post history. Self-service deletion from the dashboard is not yet available; until it is, email is the way to do it.
Depending on where you live you may also have rights to access, correct, export or restrict the processing of your personal data. Use the same address and we will respond.
Children
The Service is not intended for anyone under 13, and we do not knowingly collect information from children. Connected platforms have their own minimum-age requirements which also apply.
Changes to this policy
If this policy changes materially we will update the date at the top of this page and, where the change affects how your data is used, notify you by email.
Contact
Questions about this policy, or about your data, go to ryanbob10@yahoo.com.