Legal

Privacy Policy

Learn how Social WorkGPT collects, uses, and protects your information.

Last Updated: August 2026

1. Introduction

Social WorkGPT ("we", "us", or "our") operates the web application available at https://social.workgpt.ai. Our service allows creators to connect their TikTok account through the official TikTok OAuth 2.0 authorization flow and publish videos directly to their own TikTok profile using the official TikTok Content Posting API.

We value your privacy and are committed to protecting your personal information. This Privacy Policy explains what information we collect, why we collect it, how we store and use it, and the choices available to you. It applies to every visitor and registered user of our website and application.

By connecting your TikTok account and using our service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not authorize the application or use the service.

2. Information We Collect

We collect only the information necessary to authenticate you and publish content on your behalf. We do not sell personal information, and we do not collect data that is unrelated to the operation of the service.

2.1 TikTok basic profile information

  • Open ID — the unique identifier TikTok assigns to your account for our application.
  • Display name — the public nickname shown on your TikTok profile.
  • Avatar URL — the link to your public profile picture.
  • Granted permissions — the list of scopes you approved during authorization.

2.2 OAuth access tokens

  • Access token — a short-lived credential used to call the TikTok API on your behalf.
  • Refresh token — used to obtain a new access token when the current one expires.
  • Expiration timestamps — used to determine when a token must be refreshed.

We never receive, request, or store your TikTok password. Authentication is handled entirely by TikTok on its own domain.

2.3 Uploaded video metadata

  • Video title or caption that you enter before publishing.
  • Privacy level you select for each post.
  • Source information — the original file name and size, or the public video URL you provide.
  • Publish identifier and status returned by TikTok, including any failure reason.

2.4 Application usage logs

  • Timestamps of authorization, publishing, and status-check events.
  • Error messages and diagnostic codes returned by the TikTok API.

2.5 Browser information

  • IP address, browser type and version, and operating system, recorded in standard server logs.
  • Referring page and request timestamps, used for security monitoring and troubleshooting.

3. How We Use Your Information

We use the information described above strictly for the following purposes:

  • Authenticate users — to verify your identity through TikTok OAuth and maintain your session.
  • Publish videos to TikTok — to submit the content, caption, and privacy setting you choose to the official TikTok Content Posting API.
  • Improve our services — to understand which features are used and to diagnose recurring errors.
  • Provide customer support — to investigate and resolve issues you report to us.
  • Maintain platform security — to detect abuse, prevent unauthorized access, and protect the integrity of the service.

We do not use your information for advertising, profiling, or automated decision-making, and we do not sell, rent, or trade your personal information to any third party.

4. Data Storage

OAuth tokens are stored securely on our server using industry best practices and are never shared with unauthorized parties. Specifically:

  • All communication between your browser, our server, and TikTok is encrypted in transit using HTTPS/TLS.
  • Tokens are held exclusively in server-side storage with restricted file-system permissions. They are never exposed to client-side code, never embedded in page markup, and never included in URLs.
  • Tokens are excluded from application logs and from any diagnostic output.
  • Access to the server and its datastore is limited to authorized personnel who require it to operate the service.

4.1 Retention

We retain your tokens only for as long as your account remains connected. When you disconnect your account, or when you ask us to delete your data, the associated tokens are removed. Video files that you upload are retained solely to let you review what was published from your account and are deleted when you delete the corresponding record or your account.

4.2 Revoking access

You may revoke our application's access at any time from your TikTok account settings, under the connected or authorized applications section. Revoking access immediately invalidates the tokens we hold, and our application will no longer be able to act on your behalf.

5. Third-Party Services

Our application communicates with the official TikTok API operated by TikTok Pte. Ltd. and its affiliates. This includes the TikTok OAuth authorization endpoints, the User Info API, and the Content Posting API used to publish your videos.

When you authorize our application, you are redirected to a page hosted by TikTok, where you enter your credentials and approve the requested permissions. We never see your login details. Any information you submit on that page is governed by TikTok's own privacy policy, which we encourage you to review at tiktok.com/legal/privacy-policy.

We do not integrate advertising networks, analytics trackers, or third-party marketing tools into this application.

6. User Rights

You remain in control of the information associated with your use of our service. You may request any of the following at any time:

  • Data deletion — removal of the profile information, publishing history, and uploaded video files we hold for you.
  • Account deletion — permanent removal of your account and all associated records from our systems.
  • Removal of stored access tokens — deletion of the OAuth access and refresh tokens we hold, which immediately ends our application's ability to act on your behalf.

You may also request a copy of the personal information we hold about you, or ask us to correct information that is inaccurate. To exercise any of these rights, contact us using the details below. We respond to verified requests within 30 days.

7. Contact

If you have questions about this Privacy Policy, or if you would like to exercise any of the rights described above, please contact us:

Email
dev2@innocom.vn
Website
https://social.workgpt.ai
Response time
Within 30 days of a verified request
← Back to Home Read our Terms of Service →