Privacy Policy
The Leverage Stack ("we," "our," or "the operator") publishes educational short-form video content about AI tools and personal finance, and operates a publishing tool that connects to TikTok, Instagram, and Facebook to post that content on our own accounts. This policy explains what data our TikTok integration accesses, why, and how it is handled.
1. Who this applies to
This application is a single-operator content-publishing tool. It is not a public service, and it is not designed for use by third-party TikTok users. The only TikTok account connected to this application is our own (@theleveragestack). This policy still discloses, in full, what our TikTok integration accesses and how that data is handled, since our app requests the scopes described below.
2. Data our TikTok integration accesses
Our application authenticates with TikTok using OAuth 2.0 and requests the following scopes, each of which returns specific data:
- user.info.basic — returns the connected account's TikTok open_id, display name, and avatar URL. Used only to confirm which account is authorized and to display it in our internal tooling.
- video.publish / video.upload — allows our application to upload a video file and its caption directly to the connected TikTok account, and returns a publish status and post ID once the upload completes.
We do not request or receive access to any other TikTok user's data. We do not use TikTok data to build advertising profiles, and we do not use TikTok login data for any purpose other than operating our own account.
3. Video content and captions
Video files and captions published through TikTok are content we create ourselves. Rendered video files are stored temporarily in Cloudflare R2 object storage (a cloud hosting provider) so that TikTok's and Meta's APIs can retrieve them at publish time, then removed from the active queue after publishing. No third-party personal data is contained in this content.
4. Data sharing with third parties
We do not sell or trade data. Data is shared only with the service providers necessary to operate the publishing pipeline:
- TikTok (via the TikTok Content Posting API) — to publish our videos.
- Meta Platforms, Inc. (via the Graph API) — to cross-post to Instagram and Facebook.
- Cloudflare, Inc. — to host this website and temporarily store video files for publishing.
- ClickBank — to process affiliate commission tracking for links on this site (see Section 6).
Each of these providers processes data under their own privacy policies and terms of service.
5. Data retention and deletion
OAuth access and refresh tokens are stored in an encrypted repository secret (for automated posting) and, for local development, in an environment file on a private machine. Tokens are refreshed automatically before expiry and are never logged or transmitted anywhere other than the issuing platform's own token endpoint. Rendered videos are deleted from cloud storage shortly after they are published. Any token can be permanently revoked at any time — see our Data Deletion page for instructions.
6. Affiliate links
This site contains affiliate links. When you click one, the destination merchant may set its own cookies to attribute a purchase. We do not receive personal information from these clicks beyond aggregate, anonymized commission reporting from the affiliate networks.
7. Security
Access tokens are never committed to source control, are transmitted only over HTTPS, and are stored using platform-native encrypted secrets management (for cloud-based posting) or a local, non-networked file (for manual operation). Access to these credentials is limited to the account operator.
8. Children's privacy
This site and tool do not knowingly collect data from children under 13, and are not directed at children.
9. TikTok platform compliance
Our use of TikTok's APIs complies with the TikTok Developer Terms of Service and the TikTok Community Guidelines. We only publish content we own and have created ourselves, only to our own connected TikTok account, and we do not use TikTok data for any purpose outside operating that account.
10. Changes to this policy
This policy may be updated at any time to reflect changes in the tool, the scopes it requests, or applicable law. The effective date above reflects the most recent revision. Material changes will be reflected on this page.
11. Contact
For questions about this policy or to request data deletion, contact us at [email protected].