This notice describes the current YennayApps Social Publisher workflow. It does not publish secrets, credentials or internal infrastructure details.
1. About YennayApps Social Publisher
YennayApps Social Publisher is an authenticated operator service that helps authorised users review prepared social content and send approved media to connected TikTok accounts through TikTok's Content Posting API.
The public product information is hosted on yennayapps.com. The authenticated operator application at publisher.yennayapps.com is a separate private workspace.
For the current production TikTok workflow, approved content is sent to the creator's TikTok draft workflow for completion in the TikTok application. A draft upload is not a published TikTok post.
2. TikTok connection and profile information
When an authorised operator connects TikTok using TikTok OAuth/Login, YennayApps may receive and process information needed to establish and verify the connection, including:
- TikTok open_id and other platform-provided account identifiers;
- TikTok username or profile identity used to verify the intended configured destination;
- display name and avatar/profile image where TikTok provides them;
- OAuth access and refresh tokens and their expiry information;
- the permissions/scopes authorised for the connection; and
- connection status, validation results and non-sensitive error information.
The current production permission model is based on user.info.basic, user.info.profile and video.upload.
user.info.basic supports basic account identity. user.info.profile supports additional authorised profile identity used to verify the intended destination. video.upload is used to send approved content to the creator's TikTok draft workflow.
3. Draft and media information
To provide the requested publishing workflow, the service may process source content, prepared captions, images, videos, thumbnails, platform-specific output packages, selected destination details, draft/media metadata, upload state, platform response identifiers and operational history.
Media used for TikTok draft delivery may be transferred to TikTok using the Content Posting API. Machine-facing media transport infrastructure is not a public product surface and is not published as a browsing destination.
4. Why this information is processed
YennayApps processes the information above to:
- connect an authorised TikTok account through OAuth;
- show and verify which TikTok account has been connected;
- allow an operator to select the intended configured destination;
- prepare and display media and captions for review;
- send operator-approved content to the authorised TikTok draft workflow;
- show connection, upload and result information to the operator;
- protect account access and prevent accidental or unauthorised actions; and
- diagnose failures and maintain operational records needed to support the service.
5. Storage and security
OAuth credentials, including access and refresh tokens, are stored server-side and protected as sensitive connection information. They are not intentionally exposed on the public YennayApps website, in public page source, or to unauthorised users.
The current application contract uses protected persistent connection storage and encryption for stored OAuth token material. Client secrets, signing secrets and other application credentials are kept outside the public website.
No internet-connected service can guarantee absolute security. Operators should protect their own YennayApps and TikTok credentials and report suspected unauthorised access promptly.
6. Sharing, third parties and advertising
Information is shared with TikTok when required to perform the account connection, identity lookup and operator-requested draft upload. TikTok operates under its own terms, developer requirements and privacy notices.
Service providers may process limited information where needed to host, secure, monitor or operate YennayApps. Any such processing remains subject to the applicable service arrangement and data-protection obligations.
YennayApps Social Publisher user data is not sold to advertisers. OAuth tokens are not made available to advertisers.
7. Retention principles
Information is retained only for as long as reasonably needed for the service, security, troubleshooting, audit and applicable legal obligations. Different categories may have different operational lifecycles.
Connected-account credentials are needed only while a connection remains usable. Draft media, operational records and diagnostic information should not be retained indefinitely without an operational or legal reason.
A final category-by-category fixed retention schedule is still an owner/legal governance item. This notice therefore does not invent unsupported fixed periods.
8. Disconnecting and revoking TikTok access
Connected TikTok accounts are managed in the authenticated Publisher application under Publishing > Connections. An authorised operator can disconnect the stored TikTok connection there. Reconnecting requires TikTok OAuth again.
Where TikTok provides an application-access control, a TikTok user can also revoke YennayApps authorisation through TikTok. Revoking authorisation may cause the related publishing functions to stop working.
The local YennayApps disconnect operation removes the stored connection record. The reviewed application authority does not establish that this local action independently performs provider-side token revocation, so platform-side revocation should be used where a user wants to revoke TikTok authorisation itself.
9. Deletion and data requests
For stored connection removal, use the authenticated disconnect action. For broader deletion or access requests involving YennayApps-held account-related data, use the public support form and choose the data-deletion request type, alongside the published data deletion guidance.
Deleting YennayApps-held connection data does not delete the user's TikTok account or content already held by TikTok.
10. Support and contact
The public YennayApps Social Publisher Support page provides an externally reachable support form without operator login. Accepted requests are stored in the YennayApps support case workflow and return a public reference for future communication.
Email is required for the current support-team reply path and as a durable acknowledgement fallback. WhatsApp may also be offered for the automated receipt acknowledgement when the server-side provider and approved acknowledgement template are configured. Support-team replies currently use email. Do not submit passwords, access tokens, refresh tokens, client secrets, signing secrets, cookies or one-time authentication codes through the support form.
11. Changes to this notice
This Privacy Policy may be updated when the product, TikTok permissions, confirmed retention practices or support arrangements change. The date above will be updated for material revisions.