
Privacy Policy
1. Information collected
When you authenticate with Telegram, THEZIESS METHOD stores the Telegram account identifier and the profile fields supplied by Telegram, such as display name, username and profile photo URL. It also stores account login timestamps, subscription records, payment-reference records and compression activity metadata used by the application.
When you connect TikTok, the service requests only user.info.basic and video.upload. It stores the TikTok app-specific open_id, display name, avatar URL, granted scopes, token expiry times and encrypted OAuth tokens.
2. Purpose of TikTok upload permission
The video.upload permission is used only after you select a successfully processed video, review its details, confirm that you own or may upload the content and press the upload button. The video is sent to TikTok Inbox/Draft so you can finish the post in the TikTok app. The service does not use this permission for automatic bulk posting.
3. Video processing and storage
Videos are processed locally in your browser. THEZIESS METHOD does not save the video binary in PostgreSQL or permanent application server storage. For TikTok upload, the browser sends the clean video artifact directly to the short-lived official TikTok upload URL. Vercel Functions receive metadata only, such as filename, MIME type and byte size.
Local IndexedDB history may contain downloaded output and, when available, a clean TikTok-compatible artifact on your own device. Clearing browser data or using the in-app history deletion controls removes those local records.
4. Token protection
TikTok access and refresh tokens remain server-side. They are encrypted in PostgreSQL with AES-256-GCM using a server-only encryption key. Tokens, client secrets, authorization codes, encryption keys and TikTok upload URLs are not intentionally written to frontend storage or application logs.
5. Operational upload records
The service stores upload metadata including the owner key, TikTok publish identifier, filename, byte size, MIME type, processing status, safe TikTok error code, timestamps and completion time. It does not store the uploaded video. These records may be retained for operational support, abuse prevention and troubleshooting until manually deleted or no longer needed.
6. Retention, deletion and disconnect
Your TikTok connection remains stored until you disconnect it, the token expires without renewal, or the administrator deletes the account data. “Disconnect TikTok” attempts official token revocation and deletes the stored connection record. You may request deletion of associated operational metadata through the support contact below.
7. Sharing and third parties
Account and upload requests are shared only with the services needed to operate the feature: Telegram for authentication, TikTok for OAuth/profile/upload processing, Vercel for hosting and the configured PostgreSQL provider for application records. TikTok’s handling of information is governed by TikTok’s own policies.
8. Security and limitations
The service uses signed HttpOnly session cookies, OAuth state validation, PKCE, same-origin checks and encrypted token storage. No internet service can guarantee absolute security. Report suspected unauthorized access through the support channel.
9. Contact
For privacy questions, connection revocation or account-data deletion, contact the THEZIESS METHOD administrator through @TheZiess_OfficialBot on Telegram.