Insight Social Publisher – Privacy Policy
Dedicated Privacy Policy for the Insight Social Publisher application by Insight (insight396.com)
1. Introduction & Scope
This Privacy Policy details the privacy practices and data protection standards governing the Insight Social Publisher application ("Application"), operated by Insight via the website domain (insight396.com).
Insight Social Publisher is a specialized software integration tool designed to connect authorized social media accounts, specifically including TikTok, to enable authenticated content publishing and media management directly from the Insight platform. This policy applies specifically to account authorizations, media uploads, and data handling performed through the Insight Social Publisher application.
2. What Insight Social Publisher Is
Insight Social Publisher enables authorized administrative users of the Insight website to connect their TikTok creator accounts securely and publish approved video content and captions to their TikTok profile via TikTok's official developer interfaces (TikTok Login Kit and TikTok Content Posting API).
3. TikTok Scopes & Permissions Used
The Insight Social Publisher application requests only the minimum necessary permissions required to authenticate the creator and carry out publishing actions:
user.info.basic: Used solely to verify account identity and retrieve non-sensitive profile identifiers (the publicdisplay_nameand the TikTok unique identifieropen_id) so the connected creator account can be identified in the publishing interface.video.publish: Used solely to initialize, upload, set publication metadata, and finalize video posts to the authorized TikTok account, as well as fetch publication processing status.
4. Information Accessed, Processed, and Handled
We do not claim that the application collects "no data," because operating a publishing integration requires processing specific authentication tokens and operational metadata. The information handled includes:
- Account Identifiers: TikTok
open_idand publicdisplay_name, received upon successful OAuth authorization to confirm the active creator profile. - OAuth Access Tokens: Short-lived authorization tokens provided by TikTok through the standard OAuth 2.0 flow to execute authorized API calls on the creator's behalf.
- Publishing Metadata: Post descriptions/captions, creator privacy selections (e.g.,
SELF_ONLYduring review/testing), media URLs, and transient publish status query identifiers.
5. Token Storage, Handling & Security
Insight Social Publisher enforces strict architectural safeguards regarding OAuth credentials:
- Server-Side Session Only: Access tokens exist exclusively in the temporary server-side PHP session memory for the duration of the active administrative session.
- Never Written to Database: Access tokens are never stored in the website's database, never written to persistent storage, and never recorded in system log files.
- Isolated Keys: Access tokens are stored under an isolated session key separate from UI display metadata, preventing accidental rendering in client-facing HTML or JavaScript.
6. No Sale or Commercial Transfer of Personal Data
Insight Social Publisher and Insight (insight396.com) unequivocally state that:
- We do not sell, rent, lease, monetize, or trade any personal data, profile information, or authentication credentials to third parties or data brokers.
- Data is never shared with third parties except as strictly necessary to communicate with TikTok's official API endpoints to execute the explicit publishing actions requested by the user.
7. Limited Use Purpose
All information and credentials processed by Insight Social Publisher are utilized strictly and exclusively for operating the social publishing integration—specifically, verifying the connected account, initiating authorized video uploads, and monitoring post delivery status on TikTok.
8. Data Retention Principles
- OAuth Tokens: Discarded immediately upon administrator logout, manual disconnection, or session expiration.
- Publishing Status IDs: Retained only for the brief duration necessary to query TikTok's status endpoint and confirm whether the upload succeeded.
9. How Users Can Disconnect & Revoke Access
Users maintain complete autonomy over their connected TikTok accounts and may disconnect or revoke permissions at any time through either of the following mechanisms:
- Within Insight: Navigate to the TikTok Integration panel at
/admin/integrations/tiktokand click the disconnect action. This immediately flushes all tokens and connection records from the active session. - Within TikTok: In the TikTok mobile application or website, navigate to Profile > Settings and Privacy > Security & Permissions > Manage App Permissions > select Insight Social Publisher > click "Remove access" to immediately revoke the application's authorization.
10. Data Deletion Requests & User Rights
Users have the right to request deletion of any records or metadata associated with their use of Insight Social Publisher. To submit a data deletion request or privacy inquiry, contact us at coachsahl@gmail.com or via our Contact Us page. Requests are handled promptly and confirmed without undue delay.
11. Security Practices
We maintain pragmatic, modern security practices to protect all operations:
- Strict HTTPS/TLS encryption for all data in transit between users, our servers, and TikTok API endpoints.
- Cryptographically secure, single-use, time-limited OAuth
stateparameters to defend against Cross-Site Request Forgery (CSRF). - Mandatory SSL certificate verification on all outbound cURL connections to TikTok's API servers.
- Restricted administrative access controls ensuring only authorized site administrators can access the publishing tools.
12. Third-Party Platform Relationship & Disclaimer
Insight Social Publisher is an independent software tool created and maintained by Insight (insight396.com). It is not affiliated with, endorsed by, or sponsored by TikTok Inc., ByteDance Ltd., or their respective subsidiaries. TikTok and related logos are trademarks of ByteDance Ltd.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to accommodate technical improvements, regulatory obligations, or platform API updates. Any revisions will be published on this URL with an updated "Last Updated" date.
14. Contact Information
For any questions, requests, or privacy inquiries concerning Insight Social Publisher, please contact:
- Operator: Insight (https://insight396.com)
- Email: coachsahl@gmail.com
- Contact Page: https://insight396.com/contact