Privacy Policy

Last updated: September 21, 2026

This Privacy Policy explains how the VideoFlow service ("VideoFlow", "we", "us") handles data while processing video links received via WhatsApp or Telegram and publishing results to TikTok and YouTube through the official publisher APIs.

1. Information VideoFlow processes

The Service processes:

2. TikTok data

When you authorize VideoFlow with TikTok through the standard OAuth flow, the Service may receive and process data necessary to publish to your account, including which TikTok account (creator) is connected, basic creator profile information, and publishing capabilities of that account. The scopes requested are limited to those needed for the product to function.

3. OAuth authorization

Connecting a TikTok or YouTube account uses the platform's official OAuth authorization. Authorization is performed in your browser with the platform, and the resulting access tokens are used solely to fulfill publishing and status requests you triggered through the Service. You can revoke access at any time from the connected platform's settings.

Why user.info.basic is used: to identify the connected creator and confirm which account content will be published to, so posts appear on the expected account.

Why video.publish is used: to upload and publish the vertical videos you create with the Service to your TikTok account, as you direct.

4. Access credentials and tokens

OAuth access and refresh tokens are encrypted at rest before they are stored, using an encryption key provided through the Service's configuration. Tokens are never returned to clients or exposed through the public API. API responses are kept to sanitized status and metadata. Because of security best practices, if a token is lost or revoked the Service may require you to re-authorize.

5. Data storage

Job records, publish results, and encrypted connection/token data are stored in the database used by your deployment (PostgreSQL or SQLite). Processed videos are stored according to the storage driver configured for the deployment (local disk or an S3/R2/GCS-compatible bucket). Infrastructure differs per deployment, and the operator of your deployment is the controller of that data.

6. Retention

The Service keeps job and publish records while they are needed to operate and report on publishing. Specific retention limits are configured by the deployment operator; no fixed retention period is stated by the software itself. You may request the deletion of your data through the contact channel of the deployment you use.

7. Data sharing

VideoFlow shares your content and resulting video with the platforms you choose (TikTok and YouTube) for the purpose of publishing, as directed by you. It does not sell or rent your personal data. Data may be disclosed only where required by law or for the legitimate operation of the Service.

8. Security

VideoFlow applies technical safeguards including SSRF protection before downloading any link, an allowlist of permitted content hosts in production, webhook signature verification, encryption of stored OAuth tokens, and sanitization of API responses so that secrets are never exposed. You are responsible for keeping your own account credentials secure.

9. Your rights

You may revoke third-party authorizations at any time, request deletion of your data, and ask for information about what the Service holds about you. Contact the operator of the deployment you use to exercise these rights.

10. Contact

For privacy-related questions, contact the operator of the VideoFlow deployment you are using via its designated support channel.