Legal
Privacy Policy
This Privacy Policy explains how the operator of The Hacking AI and the TikTok account @thehackingai processes information when the authorized creator uses the web application and its TikTok integration.
1. Data controller and contact
The service is operated by the creator behind @thehackingai. Privacy questions, access requests, deletion requests or objections may be sent by direct message to @thehackingai on TikTok. A dedicated public privacy email will be added before the service is made available to users beyond the operator's controlled testing.
2. Information processed
- Basic TikTok profile information made available through user.info.basic, such as OpenID, display name and avatar.
- OAuth authorization data, including access and refresh tokens, authorization status and granted scopes.
- Videos, captions, privacy choices and publishing metadata selected by the creator.
- Minimum technical and security logs needed to diagnose errors, prevent abuse and protect the integration. OAuth codes, client secrets and complete token values are not intentionally written to logs.
3. Why and on what basis we process data
Data is processed to provide creator-requested TikTok Login, draft upload and publication features; maintain service security; comply with applicable law; and document explicit creator actions. Depending on context, the legal basis under the GDPR is performance of a requested service, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
4. TikTok permissions
The application may request user.info.basic, video.upload and video.publish. The first displays the authorized creator's basic profile, the second uploads approved content as a draft, and the third enables direct publication only after review and explicit confirmation.
5. Sharing and processors
Information is sent to TikTok only as necessary to perform an action selected by the creator. Infrastructure providers may process limited data solely to host and secure the service. We do not sell personal data, share it with data brokers or use it for behavioral advertising.
6. Cookies and tracking
The public information pages do not use advertising cookies, behavioral analytics or cross-site tracking. Essential security state may be used during an OAuth session to prevent request forgery.
7. Retention and security
OAuth credentials are retained only while the integration remains authorized or as needed for security and legal obligations. Draft metadata and operational logs are kept only for the shortest period reasonably necessary. Reasonable technical safeguards include encrypted HTTPS transport, restricted secret storage, access controls, OAuth state validation and suppression of secrets from application logs.
8. Your rights and revocation
Where applicable, you may request access, correction, deletion, restriction, portability or object to processing, and may complain to the competent supervisory authority. You can revoke the application's TikTok access through your TikTok account settings. After revocation or a valid deletion request, associated application-held information will be deleted or anonymized unless retention is legally required.
9. International transfers and children
TikTok and infrastructure providers may process data in other countries under their own terms and applicable safeguards. This service is not directed to children and is intended only for users old enough to authorize TikTok integrations under applicable law and TikTok's terms.
10. Changes
Material changes will be posted on this page with a revised effective date. Continued use after a change is subject to the updated policy and any consent required by law.
This policy describes the private testing configuration. It will be updated if the audience, providers or data practices materially change.