Privacy Policy
Last updated: September 21, 2026
This Privacy Policy explains how the VideoFlow service ("VideoFlow", "we", "us") handles data while processing video links received via WhatsApp or Telegram and publishing results to TikTok and YouTube through the official publisher APIs.
1. Information VideoFlow processes
The Service processes:
- Video links and instructions you submit via connected channels (WhatsApp or Telegram).
- Video content downloaded from the submitted links for processing and editing.
- Job records describing each processing run, its source, status, and publish results.
- Authorization credentials associated with accounts you connect via OAuth (for example your TikTok account).
2. TikTok data
When you authorize VideoFlow with TikTok through the standard OAuth flow, the Service may receive and process data necessary to publish to your account, including which TikTok account (creator) is connected, basic creator profile information, and publishing capabilities of that account. The scopes requested are limited to those needed for the product to function.
3. OAuth authorization
Connecting a TikTok or YouTube account uses the platform's official OAuth authorization. Authorization is performed in your browser with the platform, and the resulting access tokens are used solely to fulfill publishing and status requests you triggered through the Service. You can revoke access at any time from the connected platform's settings.
Why user.info.basic is used: to identify the connected creator and confirm which account content will be published to, so posts appear on the expected account.
Why video.publish is used: to upload and publish the vertical videos you create with the Service to your TikTok account, as you direct.
4. Access credentials and tokens
OAuth access and refresh tokens are encrypted at rest before they are stored, using an encryption key provided through the Service's configuration. Tokens are never returned to clients or exposed through the public API. API responses are kept to sanitized status and metadata. Because of security best practices, if a token is lost or revoked the Service may require you to re-authorize.
5. Data storage
Job records, publish results, and encrypted connection/token data are stored in the database used by your deployment (PostgreSQL or SQLite). Processed videos are stored according to the storage driver configured for the deployment (local disk or an S3/R2/GCS-compatible bucket). Infrastructure differs per deployment, and the operator of your deployment is the controller of that data.
6. Retention
The Service keeps job and publish records while they are needed to operate and report on publishing. Specific retention limits are configured by the deployment operator; no fixed retention period is stated by the software itself. You may request the deletion of your data through the contact channel of the deployment you use.
7. Data sharing
VideoFlow shares your content and resulting video with the platforms you choose (TikTok and YouTube) for the purpose of publishing, as directed by you. It does not sell or rent your personal data. Data may be disclosed only where required by law or for the legitimate operation of the Service.
8. Security
VideoFlow applies technical safeguards including SSRF protection before downloading any link, an allowlist of permitted content hosts in production, webhook signature verification, encryption of stored OAuth tokens, and sanitization of API responses so that secrets are never exposed. You are responsible for keeping your own account credentials secure.
9. Your rights
You may revoke third-party authorizations at any time, request deletion of your data, and ask for information about what the Service holds about you. Contact the operator of the deployment you use to exercise these rights.
10. Contact
For privacy-related questions, contact the operator of the VideoFlow deployment you are using via its designated support channel.