PostVideoPostVideo

PostVideo Privacy Policy

Last updated: October 4, 2026

This Privacy Policy explains how PostVideo ("we", "us" or the "Service", available at https://postvideo.ai) collects, uses, stores and protects information you provide or that is generated while you use the Service, and the rights you have over that information. By using the Service you confirm that you have read and agree to this Policy.

1. Scope

This Policy applies to the PostVideo web application reached through https://postvideo.ai and its subdomains, and to the server-side services that support it.

The Service is provided to business and team customers. Your account is created by the platform administrator or by an admin of your organization; organization admins can view and manage the accounts and data of members within their organization.

2. Information we collect

• Account information: sign-in email, display name, organization and role, provided by an administrator when the account is created.

• TikTok account information: when you authorize a TikTok account we receive, through the official TikTok API, its public identifier (open_id), display name, avatar, and access and refresh tokens used to publish videos and read publishing results on your behalf.

• Google Drive information: what we receive when your organization connects Google Drive is described in section 3.

• Content you provide: video files, titles, descriptions, tags, publishing settings, and prompts you enter for the AI copy feature.

• Video statistics: public view, like, comment and share counts for published videos, obtained from the official TikTok API or from third-party public data services.

• Usage and security logs: sign-in times, audit records of administrative actions (for example who changed a permission and when), background job runs and error messages. Audit records never contain passwords or tokens.

• Payment information: online card payments are processed by Stripe. We do not receive or store your full card number; Stripe processes payment data under its own privacy policy. Bank transfer is also supported.

• Account Partner payout information: Account Partners are paid by bank transfer. We store the payout bank account details they submit (account holder name, bank and account number) in order to pay them.

3. Google user data (Google Drive)

PostVideo uses Google OAuth 2.0 to access your Google Drive and requests a single scope:

• https://www.googleapis.com/auth/drive.readonly: view files and folders in your Drive. We use it only to list video files (metadata such as name, size, MIME type, modified time, thumbnail and duration) and, when you choose to import a specific video, to download the content of that file.

Our use of Google data is limited to (1) showing you a list of video files to choose from inside PostVideo and (2) after you explicitly click "Import", copying the selected video into the private storage PostVideo provides for your organization so it can later be published to TikTok. We do not read or copy files you have not selected, and we never modify or delete anything in your Drive.

We do not use Google user data for advertising, profiling, or transfer or sale to any third party, and we do not allow humans to read this data except with your explicit consent, for security investigations or abuse handling, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations.

PostVideo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google access and refresh tokens are stored encrypted in our database and can be read only by server-side code; the browser never receives them. A background job refreshes tokens automatically before they expire.

You can click "Disconnect Google Drive" on the Videos page at any time: we immediately delete the stored tokens and ask Google to revoke them. You can also revoke PostVideo's access directly at https://myaccount.google.com/permissions. Copies of videos you already imported are not deleted automatically when you disconnect; you can delete them from the Videos page.

4. How we use information

• To provide the Service: maintain TikTok and Google Drive authorizations, store and process the videos you upload or import, publish to TikTok according to your settings, and collect and display video statistics.

• To keep the Service secure: authenticate users, enforce permissions, detect unusual access and abuse, and audit administrative actions.

• To operate and improve the Service: monitor background jobs, troubleshoot problems, and measure API usage to control costs.

• To communicate with you: show in-app notices about expiring authorizations, failed tasks and other items that need your attention.

We never show you or anyone else advertising based on your data.

5. Sharing and processors

We do not sell your personal information. We share it only in the following cases:

• TikTok: when you create a publishing task, the video, title, description and settings you chose are submitted through the official TikTok API to the TikTok account you authorized.

• Google: Google APIs are called to complete Google Drive authorization, listing and import.

• Payment processor: online payments are processed by Stripe under its own privacy policy.

• Infrastructure providers: the database, file storage and server-side functions are provided by Supabase, and the web application is hosted on Vercel. They process data only on our instructions as data processors.

• Public data services: to collect public statistics for published videos we submit the public link of the video to a third-party data service; no account credentials or private information are sent.

• AI service: when you use the AI copy feature, the prompt and video titles you enter are sent to the AI provider (Google Gemini) to generate text. We never send your Google Drive data or tokens to it.

• Legal requirements: when disclosure is required by law, regulation or a competent authority.

6. Storage, security and retention

Data is stored in cloud databases and object storage provided by Supabase. Protective measures include row-level security policies that isolate data per organization, encrypted storage of third-party tokens readable only by server-side code, private storage buckets accessed through time-limited signed links, platform secrets kept in server-side secret management and never shipped to the browser, and audit records for critical actions.

Retention: account and organization data is kept for the duration of the service relationship; TikTok and Google tokens are deleted when you disconnect or your account is deleted; video files and publishing records are deleted when you remove them or the organization ends its service; background job logs are kept for 14 days; database backups are kept for at most 30 days.

No method of transmission or storage is completely secure. If a security incident affects your rights we will notify you as required by law.

7. Your rights

At any time you can view and update your profile in the app, disconnect TikTok or Google Drive, delete videos and publishing tasks you created, and, through your organization admin or by contacting us directly, request access to, correction, export or deletion of your personal information, or closure of your account.

We respond to verified requests within a reasonable period, normally no more than 30 days, except where the law requires us to retain information.

8. Cookies and local storage

The Service uses browser local storage to keep your sign-in session, language preference and a small amount of interface state (for example dismissed notices). We do not use third-party advertising or tracking cookies.

9. Minors

The Service is intended for business and team users and not for individuals under 18. We do not knowingly collect personal information from minors and will delete it promptly if we become aware of it.

10. International transfers

The cloud infrastructure used by the Service may be located outside your country or region. We take the measures required by applicable law so that your data receives equivalent protection when processed across borders.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced in the app or through your organization admin. The updated Policy takes effect when published, and the date at the top shows the latest revision.

Questions about this Policy, or requests to exercise your data rights: contact support@postvideo.ai.