Privacy Policy
Last updated: August 24, 2026
1. Information we collect
When you connect a TikTok account to Spotly, we receive the following data from TikTok, and nothing else:
- Account identifier (
open_id) — via theuser.info.basicscope. Used to associate your authenticated session with the correct TikTok account. - Display name and avatar URL — via the
user.info.basicscope. Shown inside Spotly so you can confirm which account is connected. - Follower count and video count — via the
user.info.statsscope. Displayed to help you identify and manage multiple connected accounts. - Creator settings — the privacy levels, interaction settings and maximum duration TikTok reports for the account, read immediately before publishing so the interface offers only what TikTok allows.
- OAuth tokens (access token and refresh token) — issued by TikTok when you authorize the app. Used to upload and publish content on your behalf.
- Video files — the videos you choose to publish. Temporarily processed for upload to TikTok, and not stored after publishing.
We do not collect your email address, phone number, password, contacts, or any content from your TikTok account other than the fields listed above.
2. How we use your information
We use your information solely to:
- Authenticate your TikTok account via OAuth 2.0.
- Show you which account is connected before anything is published.
- Upload and publish videos to TikTok as requested by you.
- Check the status of your uploads.
Your data is not used for advertising, profiling, or training any model.
3. Data sharing
We do not sell, share, or disclose your personal information to third parties. Your data is only shared with TikTok as required to provide the publishing service.
4. Data storage and security
OAuth tokens and the profile fields listed in section 1 are stored in local files on the machine running Spotly (one file per connected account). They are never sent to any third-party server. We do not maintain external databases of user information. Video files are read locally and uploaded directly to TikTok.
5. Data retention
OAuth tokens are retained until you revoke access or they expire. Video files are not retained after upload — once TikTok confirms the upload, the file is only kept by TikTok.
You can revoke Spotly's access at any time from the TikTok app: Profile → Settings and privacy → Security & permissions → Apps and services, then remove Spotly. Revoking access immediately invalidates the stored tokens. To have the locally stored data deleted, contact us at the address in section 9.
6. Your rights
- Revoke the Service's access to your TikTok account at any time.
- Request deletion of any stored data.
- Know what data is collected and how it is used.
Requests sent to the address in section 9 are answered within 30 days.
7. Other platforms
Spotly can also publish to Instagram and Facebook accounts you connect. Data from those platforms is handled exactly as described above: only what is needed to publish, stored in local files, never sold or shared, and revocable from the platform's own settings.
8. Children's privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect information from children.
9. Contact
For questions about this Privacy Policy, or to request deletion of your data, contact us at zakharsasu@gmail.com.
10. Changes to this policy
We may update this Privacy Policy at any time. Changes will be reflected on this page with an updated date. This policy forms part of the Terms of Service.