This policy explains what personal data Viranomix collects, why we collect it, how long we keep it, and what you can ask us to do with it. It also describes, in detail, the data we obtain from TikTok accounts through TikTok's official APIs.
We have written this to be read, not to be impenetrable. If anything here is unclear, email anasabouelala@gmail.com and we will explain it in plain language.
Contents
1. Who we are
Viranomix ("we", "us") provides a social media posting and analytics service. We operate physical mobile devices located in the United States and publish our clients' video content from them, then report on how that content performs.
For data protection purposes, the controller is [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. You can reach us at anasabouelala@gmail.com.
2. What we collect
From visitors to this website
- Information you type into our booking form: name, email address, and whatever you tell us about your business.
- The date and time you choose for a call, which creates a calendar event and an invitation email.
- Standard server logs kept by our hosting provider: IP address, browser user agent, pages requested, timestamps.
From clients
- Contact and company details, the plan you are on, and internal notes our team writes about your account.
- The video content you send us to publish.
- API usage records if you use our data API: which endpoint was called, when, from which IP, the response status, and how long it took.
From the social accounts we operate
See section 3 — this is the detailed part.
3. TikTok account data
This section describes our use of TikTok's APIs and is the part most relevant to TikTok's platform review.
How we obtain access
We obtain data about a TikTok account in one of three ways, and each account in our system is tagged with which one applies:
- TikTok Login Kit and Display API (authorised access). The holder of the TikTok account signs in through TikTok's official OAuth flow and grants our application permission. In practice these are accounts operated by Viranomix on behalf of a client, authorised by our own operators on the devices we run. We never ask a client for their TikTok password, and we never access a TikTok account that has not completed this flow.
- Publicly visible profile information. For some accounts we read only the information TikTok displays publicly on a profile page to any visitor — follower count, following count, total likes and number of videos. No authorisation is involved and no private data is accessed.
- Manual entry. A member of our team reads a figure from the TikTok app and types it into our system.
Permissions we request, and why
| Scope | Data | Why we need it |
|---|---|---|
| user.info.basic | Account identifier (open id, union id), avatar, display name | Required to complete sign-in and to tell accounts apart |
| user.info.profile | Username, bio, verified status, profile link | So reports name the right account and link to it |
| user.info.stats | Follower count, following count, total likes, video count | The headline figures in client reports |
| video.list | Per video: views, likes, comments, shares, caption, thumbnail, duration, link, post time | Per-video performance reporting |
Where an account is a TikTok Business Account and has authorised it, we may also retrieve aggregate audience country percentages — for example "94% of viewers were in the United States". This is statistical and aggregated; it never identifies an individual viewer.
What we do with it
We store a dated snapshot of these figures so that performance can be shown over time, and we present them to the client the account is operated for — in a dashboard, in reports, and through our API. That is the entire purpose.
What we never do. We do not sell TikTok data. We do not share it with advertisers, data brokers or any third party beyond the client whose account it is. We do not use it to train machine learning models. We do not post, edit, delete or interact with content through the API — our integration is strictly read-only. We do not access direct messages, private videos, or any viewer's personal information.
Access tokens
When an account authorises our application, TikTok issues us an access token and a refresh token. These are encrypted at rest using AES-256-GCM before being written to our database, and they are never displayed in our interface, never logged, and never transmitted to anyone.
4. Why we process it
- To provide the service you asked for — publishing your content and reporting how it performed. This is processing necessary to perform our contract with you.
- To run and secure the service — rate limiting, abuse prevention, debugging. This is our legitimate interest in keeping the service working.
- To respond to you when you contact us or book a call.
- To meet legal and accounting obligations.
5. Who we share it with
We do not sell personal data, and we do not share it for anyone else's marketing. We use a small number of service providers who process data on our behalf:
| Provider | What for |
|---|---|
| Hostinger | Website and database hosting |
| Google (Calendar & Gmail) | Scheduling calls and sending the invitation |
| TikTok | The API we read performance data from |
We will also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim.
6. How long we keep it
| Data | Kept for |
|---|---|
| Booking enquiries | 24 months from the last contact |
| Client records and correspondence | The life of the relationship, then 24 months |
| TikTok performance snapshots | While we operate the account for you, then deleted within 90 days of the account being retired |
| TikTok access and refresh tokens | Deleted immediately when an account is disconnected or retired |
| API request logs | 60 days, then automatically purged |
| Invoices and accounting records | As long as tax law requires |
7. How we protect it
- All traffic to this site and our API is encrypted in transit over HTTPS.
- TikTok tokens are encrypted at rest with AES-256-GCM.
- API keys are stored only as SHA-256 hashes — we cannot recover a key, only issue a new one.
- Administrative access is password protected, and application files containing credentials are stored outside the public web directory.
- Each client's API key can only reach the accounts explicitly assigned to it, and only the specific metrics enabled for it.
No system is perfectly secure. If a breach affects your personal data and poses a risk to you, we will tell you and the relevant authority without undue delay.
8. Your rights
Depending on where you live, you may have the right to:
- ask what personal data we hold about you and get a copy;
- have inaccurate data corrected;
- have your data deleted;
- object to or restrict how we use it;
- receive your data in a portable format;
- withdraw consent at any time, where we relied on consent;
- complain to your local data protection authority.
Email anasabouelala@gmail.com and we will respond within 30 days. We will not charge you or treat you differently for exercising these rights.
9. Revoking TikTok access and deleting TikTok data
Access can be withdrawn at any time, in two independent ways:
- From TikTok: open the TikTok app, go to
Settings and privacy → Security and permissions → Apps and services, and remove Viranomix. Our access stops immediately. - From us: ask us to disconnect the account, or use the Disconnect control in our admin interface. This deletes the stored tokens immediately.
To have the stored performance history deleted as well, email anasabouelala@gmail.com with the handle. We will delete it within 30 days and confirm when it is done.
10. Cookies
This website does not use advertising or cross-site tracking cookies. We use:
- a session cookie on our admin interface, so a signed-in administrator stays signed in. It is essential and is deleted when the browser closes.
- browser local storage on the client dashboard, only if a client chooses "keep me signed in", to remember their API key on their own device. Nothing is sent to us. Clearing site data removes it.
If we ever add analytics or advertising cookies, we will ask for consent first and update this page.
11. International transfers
We operate devices in the United States and use service providers located in the United States and the European Union, so your data may be processed outside your country. Where required, we rely on appropriate safeguards such as the European Commission's standard contractual clauses.
12. Contact
Questions, requests or complaints: anasabouelala@gmail.com.
We may update this policy. When we do, we will change the date at the top, and if the change is significant we will tell affected clients directly.