Login with TikTok
Privacy Policy

Last updated: December 4, 2024

1. Introduction

Flowctory ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website and services (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the Service.

This Privacy Policy should be read alongside our Terms of Service.

2. Information We Collect

2.1 Account Information from TikTok

When you connect your TikTok account to Flowctory, we receive and store the following information from TikTok:

  • TikTok Open ID: A unique identifier for your TikTok account (not your username)
  • Display Name: Your TikTok display name
  • Avatar URL: The URL of your TikTok profile picture

2.2 Authentication Tokens

We store OAuth access tokens and refresh tokens required to communicate with TikTok's API on your behalf. These tokens allow us to upload content to your TikTok account without storing your TikTok password.

2.3 Video Content

When you upload a video through the Service, the video file is temporarily stored on our servers solely for the purpose of transferring it to TikTok. Videos are automatically deleted from our servers after successful upload to TikTok or within 24 hours, whichever occurs first.

2.4 Post Metadata

We store information about your posts, including:

  • Video captions and descriptions
  • Privacy settings you select (public, friends, private)
  • Scheduled posting times
  • Upload timestamps
  • Post status (pending, processing, published, failed)
  • TikTok publish IDs for successful posts

2.5 Technical and Usage Data

We automatically collect certain technical information when you use the Service:

  • IP address
  • Browser type and version
  • Device information
  • Access timestamps
  • Error logs and diagnostic data

We do not use third-party analytics services or tracking tools.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Authenticate you with TikTok's services
  • Upload and schedule video content to TikTok on your behalf
  • Display your posting history and status within the application
  • Troubleshoot issues with failed uploads
  • Communicate with you about the Service (service announcements, security alerts)
  • Detect, prevent, and address technical issues, fraud, or abuse
  • Comply with legal obligations

We do not use your personal information for advertising purposes or sell it to third parties.

5. How We Share Your Information

We share your information only in the following circumstances:

5.1 TikTok

Your video content and associated metadata are transmitted to TikTok through their Content Posting API. TikTok's handling of your data is governed by TikTok's Privacy Policy.

5.2 Service Providers

We use trusted third-party service providers to help operate the Service:

  • Hosting Provider: Our servers are hosted on infrastructure that may have access to server logs and technical data necessary to provide hosting services.
  • Database Provider: We use PostgreSQL for data storage. All data is encrypted at rest.

These providers are contractually obligated to protect your information and may only use it to provide services to us.

5.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal requests by public authorities (e.g., court orders, subpoenas).

5.4 Business Transfers

If Flowctory is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

5.5 No Sale of Personal Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

6. Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:

Data TypeRetention Period
Account data (TikTok profile info)Until you revoke access or delete your account
OAuth tokensUntil revoked or expired; deleted when you sign out
Video filesDeleted within 24 hours of upload
Post metadata90 days after posting
Server logs30 days

7. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

7.1 Right of Access

You have the right to request a copy of the personal data we hold about you.

7.2 Right to Rectification

You have the right to request correction of any inaccurate personal data we hold about you.

7.3 Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

7.4 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

7.5 Right to Object

You have the right to object to the processing of your personal data based on our legitimate interests.

7.6 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances.

7.7 Right to Withdraw Consent

Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing based on consent before its withdrawal.

7.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. In France, the supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr.

7.9 Exercising Your Rights

To exercise any of these rights, please contact us at contact@flowctory.com. We will respond to your request within 30 days.

8. California Privacy Rights (CCPA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

8.1 Right to Know

You have the right to request that we disclose:

  • The categories of personal information we have collected about you
  • The categories of sources from which we collected the information
  • The business or commercial purpose for collecting the information
  • The categories of third parties with whom we share the information
  • The specific pieces of personal information we have collected about you

8.2 Right to Delete

You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions.

8.3 Right to Opt-Out of Sale

You have the right to opt-out of the sale of your personal information. However, Flowctory does not sell personal information.

8.4 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, or provide you with a different level of service for exercising your rights.

8.5 Exercising Your Rights

To exercise your CCPA rights, please contact us at contact@flowctory.com. We will verify your identity before processing your request.

9. International Data Transfers

Flowctory is based in France (European Union). If you access the Service from outside the EU, please be aware that your information may be transferred to, stored, and processed in the EU.

When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Transfers to countries with an EU adequacy decision
  • Standard Contractual Clauses approved by the European Commission
  • Other legally recognized transfer mechanisms

TikTok, as a third-party service, may transfer your data internationally according to their own privacy policy.

10. Cookies

We use minimal cookies to operate the Service:

10.1 Session Cookie

We use a single, essential session cookie to maintain your authentication state. This cookie:

  • Is HTTP-only and secure (in production)
  • Expires after 7 days
  • Contains only a signed JWT with your user ID
  • Is strictly necessary for the Service to function

10.2 No Tracking Cookies

We do not use tracking cookies, advertising cookies, or third-party analytics.

10.3 Cookie Preferences

Since we only use strictly necessary cookies, cookie consent is not required under GDPR. However, you can configure your browser to reject cookies, but this will prevent you from using the Service.

11. Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in Transit: All communications use HTTPS/TLS encryption
  • Encryption at Rest: Sensitive data is encrypted in our database
  • Secure Authentication: OAuth tokens are securely stored and managed
  • Access Controls: Limited access to personal data on a need-to-know basis
  • Regular Updates: Infrastructure and dependencies are regularly updated

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately.

12. Children's Privacy

The Service is not intended for children under the age of 16 in the European Union or 13 in other jurisdictions. We do not knowingly collect personal information from children under these ages.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at contact@flowctory.com. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information.

13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. When we make changes:

  • We will update the "Last updated" date at the top of this policy
  • For material changes, we will provide notice through the Service or via email
  • We will obtain your consent where required by applicable law

We encourage you to review this Privacy Policy periodically to stay informed about our data practices.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Flowctory
Cancale, France
Email: contact@flowctory.com

Data Protection Authority

If you are in the EU and have concerns about our data practices, you may contact the French data protection authority (CNIL) at www.cnil.fr.