Agentic Posting is a TikTok publishing API for independent creators and the agents they authorize. It provides an account page for sign-in, billing, TikTok connection, and API-key management, plus a scoped browser review when a creator needs to confirm one Direct Post. This policy explains what data the service processes and the choices available to you.
Data we process
- Account and billing data: sign-in identifiers, email address, workspace and subscription identifiers, plan status, billing-period dates, and usage totals. Payment-card details used for billing are handled by Polar. Do not send card data through support; common card patterns are rejected before storage.
- Connected-account data: TikTok open ID, display name, avatar URL, available creator settings, authorized scopes, and encrypted access and refresh tokens.
- Uploaded media: video or photo files you choose to upload, file metadata, and a short-lived storage location used so TikTok can retrieve the files after you consent to publish.
- Publishing records: title or caption, description, privacy and interaction choices, music and cover choices, disclosure settings, publish-intent summary and content hash, creator confirmation, publish identifiers, processing status, and failure reason.
- Support data: the email address, request category, message, browser user-agent, timestamp, and a keyed source hash from an accepted support-form submission. The source hash is derived from the normalized trusted Cloudflare connection address for abuse prevention; the raw address is not stored in the support row. Submitted email, message, and user-agent fields matching common credential, private-key, signed-URL, or payment-card patterns are rejected before storage.
- Technical data: basic security and rate-limit information such as IP-derived request identity, request time, and service logs. Rate-limit identities are hashed.
How we use data
We process this data only to authenticate you, provide and bill the service, manage the connected TikTok account and API keys, transfer media you expressly choose to publish, return request status, protect the service, respond to support and privacy requests, and comply with legal or platform obligations.
TikTok data and authorization
TikTok authorization tokens remain server-side and are encrypted at rest. They are not returned to agents or browsers. We do not sell TikTok data, use it to profile you, or share it with unrelated advertisers. When you disconnect from the account page, the service asks TikTok to revoke access. Local authorization tokens are deleted and the account is marked disconnected only after that revocation succeeds. If TikTok cannot confirm revocation, the encrypted local connection is preserved so you can retry rather than lose the recovery path while remote access may remain active.
Media retention
Uploaded media is scheduled for deletion after 24 hours. Public support intake is capped at 1,000 accepted requests globally and 10 per trusted connection-source hash in a rolling 24-hour window, plus 30,000 rows total. Accepted public support requests and their source hashes are scheduled for deletion after 30 days, with each cleanup run deleting at most 1,000 expired rows. Publishing, billing, webhook-audit, and security records are retained as needed to operate the service, prevent duplicate submissions, reconcile provider outcomes, prevent abuse, resolve disputes, and meet legal obligations; those records do not currently have the same automatic deletion schedule. You may submit a verified deletion request for account-linked information, subject to records we must retain for legal, security, billing, or dispute purposes.
Service providers
Cloudflare hosts the website, API, database, rate-limit storage, and temporary media storage. Clerk provides account authentication. Polar provides checkout, subscription management, and related billing records. TikTok processes authorization and publishing requests under its own terms and privacy policy. Google Fonts provides the web fonts loaded by public website pages and may receive ordinary connection metadata such as IP address and browser headers. These providers process data only as needed to provide their respective services.
Local browser storage
The account and review pages use browser storage and cookies required by Clerk for authentication. A scoped, expiring review token is delivered in the URL fragment, moved into session storage, removed from the visible URL, and sent only to the matching intent's review-read and confirmation endpoints. Reading an active review requires the token. Confirming additionally requires a current Clerk session for a member of the same workspace. The token is removed after successful confirmation or an inactive/terminal review response, and otherwise clears when the browser session ends.
Your choices
- Do not upload a file, create a draft, or confirm a Direct Post unless you are ready to send it.
- Rotate an API key or disconnect the linked TikTok account from the account page.
- Manage or cancel a paid subscription in Polar's customer portal.
- Request access, correction, or deletion of your support, account, and publishing data.
- Contact us about a security or privacy concern.
Contact and deletion requests
Use the public support and data-request form. Choose “Privacy request” or “Delete my data” so the request is routed correctly. We may ask for reasonable verification before disclosing or deleting account-linked information.
Changes
We may update this policy when the product or legal requirements change. The effective date above will be updated, and material changes will be disclosed on this page.