Legal
Privacy Policy
This Privacy Policy explains how the operator of The Hacking AI, its TikTok integration and its Instagram Graph API integration processes information when the authorized creator uses the web application.
1. Data controller and contact
The service is operated by the creator behind @thehackingai. Privacy questions, access requests, deletion requests or objections may be sent by direct message to @thehackingai on TikTok. A dedicated public privacy email will be added before the service is made available to users beyond the operator's controlled testing.
2. Information processed
- Basic TikTok profile information made available through user.info.basic, such as OpenID, display name and avatar.
- OAuth authorization data, including access and refresh tokens, authorization status and granted scopes.
- Videos, captions, privacy choices and publishing metadata selected by the creator.
- Minimum technical and security logs needed to diagnose errors, prevent abuse and protect the integration. OAuth codes, client secrets and complete token values are not intentionally written to logs.
3. Why and on what basis we process data
Data is processed to provide creator-requested TikTok Login and Direct Post features; display current creator posting controls; transfer and publish only creator-approved content and metadata; maintain service security; comply with applicable law; and document explicit creator actions. Depending on context, the legal basis under the GDPR is performance of a requested service, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
4. TikTok permissions
The application requests user.info.basic and video.publish. The first displays the authorized creator's basic profile. The second retrieves current creator posting options and posts a creator-selected video with the reviewed caption, privacy, interaction and disclosure settings only after explicit confirmation.
5. Sharing and processors
Information is sent to TikTok only as necessary to perform an action selected by the creator. Infrastructure providers may process limited data solely to host and secure the service. We do not sell personal data, share it with data brokers or use it for behavioral advertising.
6. Cookies and tracking
The public information pages do not use advertising cookies, behavioral analytics or cross-site tracking. Essential security state may be used during an OAuth session to prevent request forgery.
7. Retention and security
OAuth credentials are retained only while the integration remains authorized or as needed for security and legal obligations. Publishing metadata and operational logs are kept only for the shortest period reasonably necessary. Reasonable technical safeguards include encrypted HTTPS transport, restricted secret storage, access controls, OAuth state validation and suppression of secrets from application logs.
8. Your rights and revocation
Where applicable, you may request access, correction, deletion, restriction, portability or object to processing, and may complain to the competent supervisory authority. You can revoke the application's TikTok access through your TikTok account settings. After revocation or a valid deletion request, associated application-held information will be deleted or anonymized unless retention is legally required.
9. International transfers and children
TikTok and infrastructure providers may process data in other countries under their own terms and applicable safeguards. This service is not directed to children and is intended only for users old enough to authorize TikTok integrations under applicable law and TikTok's terms.
10. Changes
Material changes will be posted on this page with a revised effective date. Continued use after a change is subject to the updated policy and any consent required by law.
This policy describes the private testing configuration. It will be updated if the audience, providers or data practices materially change.
YouTube API Services
The Hacking AI uses YouTube API Services to connect only the creator-authorized YouTube channel, verify its stable channel ID, upload approved videos and read their processing and privacy status. The application requests youtube.upload and youtube.readonly. It processes the authorized channel ID, title and handle; encrypted OAuth access and refresh tokens; granted scopes; uploaded video files; titles, descriptions, tags, audience and synthetic-media declarations; video IDs; and processing status.
YouTube data is used only to provide the publishing workflow requested by the channel owner. It is not sold, used for advertising or shared with unrelated third parties. Encrypted authorization data is retained only while the integration remains connected and may be deleted when access is revoked or upon a deletion request. Infrastructure providers process the minimum data required to host and secure the service.
Use of this integration is also subject to the YouTube Terms of Service and the Google Privacy Policy. The creator can revoke the application at any time from Google Account third-party connections. After revocation, a deletion request may be sent using the contact method in Section 1.