CROSSPOST STUDIO

Privacy Policy

Last updated: September 3, 2026

1. What this policy covers

This Privacy Policy explains how CrossPost Studio handles information when you use the web application and connect a supported social-media account.

2. Information we process

TikTok account information. When you connect TikTok through TikTok's official OAuth flow, CrossPost Studio receives the authorization information and access credentials returned by TikTok. The application uses the basic user information available through the authorized scope to show the connected account and uses the access token to request creator information and initiate video publishing.

Content you submit. The application receives the title, caption, destination selection, and video URL you enter when you initiate a publication. In the current MVP, the video is supplied as a URL; the planned private object-storage upload flow is not part of the current implementation.

Technical information. Hosting and infrastructure providers may process standard technical information such as IP address, request metadata, browser information, and timestamps as part of operating and securing the service.

3. How information is used

  • To authenticate your connected TikTok account.
  • To determine whether your TikTok connection is active.
  • To request TikTok creator information needed for publishing.
  • To initiate publication of the video URL you provide through TikTok's Content Posting API.
  • To operate, secure, troubleshoot, and improve the application.

4. TikTok data

CrossPost Studio uses TikTok's official APIs rather than scraping TikTok. TikTok access credentials are stored in an encrypted, HTTP-only cookie in the current MVP. The application does not intentionally sell TikTok information or use it for advertising. TikTok may independently process information under TikTok's privacy policies and platform rules.

5. Sharing

Information is shared with service providers and third-party platforms only as needed to operate the application and carry out actions you request. For a TikTok publication, the relevant content and authorization are transmitted to TikTok's API. We do not sell personal information.

6. Retention

The current MVP keeps the TikTok OAuth token in the browser's encrypted HTTP-only cookie for the configured cookie lifetime, subject to refresh-token behavior. The current MVP does not maintain a database of your posts or permanently store uploaded video files.

7. Security

OAuth state validation is used to protect the TikTok authorization callback, and TikTok tokens are encrypted before being placed in the HTTP-only cookie. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

8. Your choices

You can stop using the service and disconnect access through the applicable third-party account controls. You can also clear the application's cookies in your browser. Requests about information handled by a third-party platform should also be directed to that platform.

9. Children

CrossPost Studio is not directed to children and should not be used by anyone who is not legally permitted to use the connected third-party services.

10. Changes

We may update this policy as the application or its integrations change. The “Last updated” date above will be changed when material revisions are made.

11. Contact

For privacy questions, use the support contact associated with CrossPost Studio or the developer account through which the application is administered.

← Back to CrossPost Studio · Terms of Service