Legal

Privacy Policy

Effective August 9, 2026

Agentic Posting is a TikTok publishing API for independent creators and the agents they authorize. It provides an account page for sign-in, billing, TikTok connection, and API-key management, plus a scoped browser review when a creator needs to confirm one Direct Post. This policy explains what data the service processes and the choices available to you.

Data we process

How we use data

We process this data only to authenticate you, provide and bill the service, manage the connected TikTok account and API keys, transfer media you expressly choose to publish, return request status, protect the service, respond to support and privacy requests, and comply with legal or platform obligations.

TikTok data and authorization

TikTok authorization tokens remain server-side and are encrypted at rest. They are not returned to agents or browsers. We do not sell TikTok data, use it to profile you, or share it with unrelated advertisers. When you disconnect from the account page, the service asks TikTok to revoke access. Local authorization tokens are deleted and the account is marked disconnected only after that revocation succeeds. If TikTok cannot confirm revocation, the encrypted local connection is preserved so you can retry rather than lose the recovery path while remote access may remain active.

Media retention

Uploaded media is scheduled for deletion after 24 hours. Public support intake is capped at 1,000 accepted requests globally and 10 per trusted connection-source hash in a rolling 24-hour window, plus 30,000 rows total. Accepted public support requests and their source hashes are scheduled for deletion after 30 days, with each cleanup run deleting at most 1,000 expired rows. Publishing, billing, webhook-audit, and security records are retained as needed to operate the service, prevent duplicate submissions, reconcile provider outcomes, prevent abuse, resolve disputes, and meet legal obligations; those records do not currently have the same automatic deletion schedule. You may submit a verified deletion request for account-linked information, subject to records we must retain for legal, security, billing, or dispute purposes.

Service providers

Cloudflare hosts the website, API, database, rate-limit storage, and temporary media storage. Clerk provides account authentication. Polar provides checkout, subscription management, and related billing records. TikTok processes authorization and publishing requests under its own terms and privacy policy. Google Fonts provides the web fonts loaded by public website pages and may receive ordinary connection metadata such as IP address and browser headers. These providers process data only as needed to provide their respective services.

Local browser storage

The account and review pages use browser storage and cookies required by Clerk for authentication. A scoped, expiring review token is delivered in the URL fragment, moved into session storage, removed from the visible URL, and sent only to the matching intent's review-read and confirmation endpoints. Reading an active review requires the token. Confirming additionally requires a current Clerk session for a member of the same workspace. The token is removed after successful confirmation or an inactive/terminal review response, and otherwise clears when the browser session ends.

Your choices

Contact and deletion requests

Use the public support and data-request form. Choose “Privacy request” or “Delete my data” so the request is routed correctly. We may ask for reasonable verification before disclosing or deleting account-linked information.

Changes

We may update this policy when the product or legal requirements change. The effective date above will be updated, and material changes will be disclosed on this page.