Connecting an account is always your choice, always done through the platform's own official login screen, and always revocable. We never ask for or store your password to any third-party platform. We request the narrowest set of permissions each feature needs.
TikTok: Creator Platform is registered with TikTok as the application "Content HQ". With your authorization it uses TikTok's Login Kit and Content Posting API, holding three permissions and no others. user.info.basic returns your display name, username, and avatar, so you can see which TikTok account is linked. video.publish publishes the videos you compose and schedule in the content calendar. video.upload sends a video to your TikTok drafts instead, for you to finish in the TikTok app. Before each publish we ask TikTok which privacy levels your account allows and never exceed them. We do not request user.info.stats or video.list, so we do not read your follower counts, your video list, or their metrics. We use TikTok data only to run the posting you asked for, on your own account. We do not sell it, share it with other users, use it for advertising, or combine it with another creator's TikTok data. Our use of TikTok data follows the TikTok Developer Terms of Service and TikTok's own Privacy Policy.
Instagram and Facebook: with your authorization we use the Instagram and Facebook Graph APIs to read your profile and media, read account and post insights, publish posts you schedule, and, if you turn it on, send automated replies to people who message your account first. Our use of Meta platform data follows the Meta Platform Terms and Developer Policies.
YouTube and Google: we use the YouTube Data API for public video statistics and comments, and, if you authorize it, YouTube Analytics for your private channel stats. Our use of YouTube data follows the YouTube Terms of Service and the Google Privacy Policy. You can revoke our access at any time at myaccount.google.com/permissions.
Platform data is stored only as long as your connection is active. Disconnect an account inside the app and the stored tokens and cached platform data for it are deleted.