Privacy Policy
Effective date: 2026-06-09 · Last updated: 2026-06-09
This Privacy Policy explains what personal data WhatIf Studio (the "Service") collects from users who connect a social account, how that data is used and stored, and the choices users have. WhatIf Studio is a content-creation platform that lets each user produce short-form videos and publish them to their own connected TikTok and YouTube accounts.
1. Summary
When a user connects their TikTok account, we store that user's OAuth tokens and basic profile, and use them only to upload the videos that user creates in WhatIf Studio to that user's own TikTok account.
We do not collect data about TikTok viewers, followers, or commenters. We do not track end users for advertising, do not sell data, and do not display or aggregate other people's TikTok content.
2. Data we collect
For each user of the Service who connects an account, we store:
- OAuth access and refresh tokens for the TikTok (and, separately, YouTube) account the user connects. Used solely to upload videos the user creates in the Service to that user's own account.
- Basic account profile obtained via the
user.info.basic scope — the connected account's open id, display name, and avatar URL — shown in the user's dashboard so the user can confirm which account they are publishing to.
- OAuth scope grants recording which permissions the user granted.
- Content the user creates in the Service — scripts, generated audio/visual assets, and the finished video files the user produces. This is the user's own content, created in the platform.
- Operational logs for each external API call (provider, endpoint, success/error, cost) for reliability and cost tracking. These contain no end-user personal data.
What we do NOT collect
- Personal data about TikTok or YouTube viewers, followers, or comment authors.
- The contents of comments, direct messages, or private interactions on integrated platforms.
- Other users' TikTok posts or analytics — the Service does not use the Display API and does not read content from accounts other than the publishing destination chosen by the connecting user.
- Payment or financial data.
3. How data is used
Data is used exclusively to:
- Upload videos the user created in the Service to that user's own connected TikTok / YouTube account (the
video.upload scope and the Content Posting API upload-to-drafts endpoint).
- Show the user, in their dashboard, which account is connected (the
user.info.basic scope).
- Operate and maintain the Service (reliability, debugging, AI provider cost tracking).
We never post on a user's behalf without that user's explicit action, and we do not use TikTok data for advertising, profiling, or resale.
4. Data storage and security
- Data is stored on infrastructure operated for the Service (PostgreSQL, object storage, Redis).
- Datastores are bound to the host loopback and not exposed publicly; public endpoints sit behind a reverse proxy with HTTPS.
- OAuth tokens are encrypted at rest (AES-256-GCM) with a key supplied via environment configuration.
- Administrative access requires authentication.
5. Third-party data processors
The Service relies on the following third parties, each handling only the data necessary for its function:
- TikTok (ByteDance) — receives the user's video uploads and returns publish/draft confirmations for that user's own account. Subject to TikTok's Privacy Policy.
- YouTube (Google) — receives video uploads for the connecting user's own channel. Subject to the Google Privacy Policy.
- Anthropic, OpenAI — receive text prompts for script generation. No TikTok personal data is included in prompts.
- AutoVideo.app — receives prompts and uploaded media for image, video, and TTS generation.
6. Data retention
- OAuth tokens are kept while the user keeps the account connected. Disconnecting an account from the dashboard deletes the stored tokens.
- Content the user creates is retained until the user deletes it.
- Operational logs are retained for reliability and cost tracking and contain no end-user personal data.
7. Your choices and rights
- Disconnect any connected account from the dashboard at any time, which removes its stored OAuth tokens.
- Revoke the Service's access from TikTok's own account settings at any time, which immediately invalidates the stored tokens.
- Request deletion of your account data by contacting us at the address below.
8. Children
The Service is not directed to children under 13 and does not knowingly collect data from children.
9. International transfers
Third-party processors listed above may process data internationally per their own policies.
10. Changes to this Policy
We may update this Policy. The "Last updated" date reflects the most recent revision.
11. Contact
For privacy questions, requests, or deletion, contact: luu@askkpop.com