Privacy Policy
Data accessed through TikTok
When you connect a TikTok account, NEXUS requests only the scopes you approve on TikTok's own consent screen. Depending on what's approved, that can include:
| Data | Scope it comes from |
|---|---|
| Open ID, display name, avatar | user.info.basic |
| Public profile fields (bio, verification status, profile links) | user.info.profile |
| Follower / following / likes / video counts | user.info.stats |
| The account's own public video list | video.list |
| Ability to upload a draft or publish, on your instruction | video.upload |
| Ability to publish directly, only after human approval | video.publish |
NEXUS does not request more than these scopes, and does not access anything TikTok's API doesn't return for them. Where a metric isn't returned by the API, NEXUS records it as unavailable rather than estimating it.
How access tokens are stored
The OAuth access and refresh tokens issued when you connect an account are held only in an in-memory credential store, for the lifetime of the running process.
Revoking authorization for an account — from TikTok or from within NEXUS — deletes its token from that store immediately.
What's stored in the database
Alongside token references, NEXUS stores what it needs to operate the content pipeline: campaign and content drafts, quality-check and approval records, scheduling and delivery status, measured performance metrics for published posts, and an audit log of actions taken. This data is used to run the account you connected and to inform that account's own future content decisions — it is not pooled with, or used to influence, any other account's data.
Sharing
Data is not sold, and is not shared with third parties beyond what's strictly required to operate the pipeline you've authorized — for example, sending a script to a content-generation provider you've configured, or publishing approved content to TikTok itself through its official API.
Retention and deletion
Content and performance records are kept for as long as the account stays connected, so that account-specific learning stays accurate over time. Revoking an account's authorization stops all future data access immediately; ask at the contact below to have that account's stored records deleted.
Your controls
- Revoke NEXUS's access at any time from your TikTok account settings, or by asking the operator to revoke it
- Every piece of content requires human approval before it can publish — nothing goes out automatically
- Ask the contact below what data is held for your account, or to have it deleted
Contact
Questions about this policy, or requests about your data, can be sent to naufalkausar@gmail.com.