Legal / Privacy
Privacy Policy
This policy explains how SignalPost processes information when a creator connects a TikTok account, reviews an original video, publishes it with explicit consent, asks for status, or requests support. SignalPost is operated by Michael Costea in Victoria, Australia. Contact: costea.michael@gmail.com.
1. Information we process
TikTok connection information
- OAuth authorization state, connected account identifier, granted scopes, and token expiry information.
- The TikTok access token and refresh credential required to query creator choices and submit a creator-approved post.
- Creator nickname, username, avatar URL, available privacy levels, interaction restrictions, and maximum video duration returned by TikTok.
Post information
- The MP4 selected by the user, its size and media type, caption/title, chosen privacy, interaction controls, commercial-content settings, Music Usage Confirmation, and explicit publishing consent.
- Provider publish identifier, processing state, sanitized error code, and operational receipt. Provider upload URLs and secret credentials are not placed in browser-visible receipts.
Technical and support information
- Security and request metadata such as time, route, coarse provider result, and abuse/rate-limit events.
- Information the user voluntarily includes in support or data-deletion email.
2. Why we use it
- Connect the account the user selected.
- Display accurate creator identity and account-specific posting choices.
- Upload only the exact media and settings the user reviewed and explicitly approved.
- Return provider processing status, prevent duplicate/abusive requests, secure the service, answer support requests, and meet legal obligations.
3. Legal basis and user control
We process connection and post data to provide the service the user requests and on the basis of the user’s explicit actions and consent. The user chooses whether to connect, what media to select, what caption to use, every privacy and interaction setting, and whether to publish. Consent can be withdrawn by disconnecting.
4. Storage, processors, and international handling
Server-side credentials, sessions, and operational records are processed through Google Cloud and Firebase infrastructure. TikTok receives the account queries and posting payload required for its Content Posting API. These providers may process information outside Australia under their own terms and safeguards. SignalPost does not put provider credentials in public page code or browser local storage.
5. Retention
- Unused OAuth state expires after approximately 10 minutes.
- SignalPost browser sessions expire after approximately seven days unless disconnected earlier.
- TikTok credentials remain only while the creator keeps the connection active or until the provider credential expires.
- Sanitized publish and security receipts may be retained for up to 30 days for troubleshooting, fraud prevention, and audit evidence, then deleted or de-identified unless a longer period is legally required.
- Selected video bytes are relayed for the requested upload and are not intentionally retained by SignalPost after the request completes.
6. Sharing and sale
We share information only with TikTok as required to perform the requested connection and post, Google Cloud/Firebase as infrastructure processors, and professional or legal advisers where reasonably necessary. We do not sell personal information. We do not share creator information for targeted advertising.
7. Security
SignalPost keeps provider credentials server-side, hashes browser-session identifiers before storage, limits accepted origins, checks account capability before publishing, rate-limits publish attempts, strips secrets from receipts, and requires fresh per-post confirmations. No internet service can guarantee absolute security.
8. Disconnect, access, correction, and deletion
Use Disconnect and delete data inside SignalPost to revoke the active connection where possible and delete stored TikTok credentials and SignalPost sessions. For access, correction, a copy of data, deletion of retained receipts, or privacy questions, email costea.michael@gmail.com with “SignalPost privacy” in the subject. We may need limited information to verify the request without asking for a password or token.
9. Children
SignalPost is not directed to children. Users must meet TikTok’s age requirements and be legally able to accept these terms.
10. Changes
Material changes will be dated on this page. If a change materially affects an active connection, we will require renewed agreement where appropriate.