1. Introduction
ss-content ("the Service") is operated by SystemSculpt ("we," "us," or "our"). This policy explains the information handled when a creator uses ss-content to compose content, connect TikTok, and start a posting flow.
2. Information We Handle
- ss-content account: Email address, authentication data managed by our authentication provider, and session data.
- TikTok connection: TikTok account identifier, granted scopes, access and refresh tokens, token expiration and refresh state, and available profile or creator information returned by TikTok.
- Creator content: Media placed in the workspace, slideshow compositions, text overlays, captions, descriptions, and rendered slide images.
- Posting choices: The posting mode, privacy choice, comments and music choices, commercial-content disclosures, and consent acknowledgement associated with a request.
- Publishing records: Request and status payloads, publish and post identifiers when returned, timestamps, terminal status, and error details.
- Operational data: Request and server logs that may include IP address, browser or device information, requested URL, and timestamp.
3. How We Use Information
- Authenticate the creator and operate their ss-content workspace.
- Complete TikTok Login Kit authorization and maintain the connection the creator approved.
- Fetch creator info to present TikTok-supported posting choices.
- Render and host creator-directed media so TikTok can retrieve it for the selected posting flow.
- Submit only the media, metadata, disclosures, and settings the creator reviews and confirms.
- Check TikTok processing status and show completion or failure.
- Secure, troubleshoot, and improve the Service and comply with legal obligations.
4. Sharing and Public Media Access
We do not sell personal information. Information is disclosed only as needed to operate the Service:
- TikTok: After the creator starts a posting flow, we send the selected metadata and provide TikTok with HTTPS URLs for the rendered media.
- Source uploads: Uploaded source images are tenant-scoped and require the creator's authenticated session to retrieve.
- Public media retrieval: Final rendered media used with TikTok's URL-pull flow is reachable at an unlisted public URL so TikTok can retrieve it. Do not submit media you do not want made accessible at that URL.
- Service providers: We use providers including Neon for authentication/data services and Vercel for application hosting and media storage. They process information to provide those services.
- Legal and safety: We may disclose information when required by law or valid legal process, or when reasonably necessary to protect users, the Service, or others.
5. Storage and Retention
OAuth tokens and mutable TikTok workspace state are stored server-side, using configured durable storage in production. Tokens remain until they expire, are replaced, or the connection record is removed or revoked. Slideshow data, rendered media, creator-info snapshots, and publish-attempt records are retained to operate the workspace and preserve the posting/status history; the current Service does not apply a fixed automatic deletion period to those records. Hosting and logging providers may keep operational logs under their own retention schedules.
To request deletion of an ss-content account or associated content and records, contact us at the address below. We will process a verified request subject to legal, security, backup, and operational retention requirements.
6. Disconnecting and Revoking TikTok
The workspace's Revoke TikTokaction calls TikTok's revocation endpoint and clears the stored access and refresh tokens. The separate Removeaction deletes the local connection record and tokens but does not itself revoke authorization at TikTok. You can also revoke ss-content from TikTok's authorized-app settings. Revocation stops future access but does not remove content already delivered to or published on TikTok; manage that content in TikTok.
7. Security
The Service uses HTTPS in production, server-managed sessions, authorization checks on protected workspace and API routes, and server-side storage for TikTok tokens. No internet service can promise absolute security; contact us if you believe your account or connection has been compromised.
8. Creator Choices and Rights
You can choose whether to connect TikTok and whether to start each posting flow. Depending on your jurisdiction, you may also have rights to access, correct, delete, restrict, object to processing of, or obtain a copy of personal information. Contact us to make a verified request.
9. Cookies
We use cookies needed for authentication, sessions, and OAuth security state. ss-content does not currently use third-party advertising cookies.
10. Changes
We may update this policy. We will revise the effective date when we do. Material changes will be communicated as required by applicable law.
11. Contact
Questions or verified privacy/deletion requests: systemsculpt@gmail.com