Privacy Policy
This Privacy Policy explains how Sabotage Poster ("Sabotage Poster", "we", "us") handles information when you use our content scheduling and publishing tool (the "Service"). The Service lets you connect social media accounts that you own or are authorized to manage — such as TikTok, Instagram, and Facebook — and publish or schedule your own content to those accounts.
We designed the Service to do one thing: publish the content you choose to the accounts you connect. We do not sell your information and we do not use your content or audience data for advertising.
1. Information we collect
- Account connection & authorization. When you connect a platform account, that platform's sign-in process gives us an authorization credential (an OAuth access token and refresh token) so we can act on your behalf, along with basic profile information needed to show you which account you are posting to. For TikTok this includes your open ID, display name (nickname), avatar image, and username, and your account's available posting options (allowed privacy levels, comment/duet/stitch availability, and maximum video length).
- Content you choose to publish. The videos, captions, hashtags, cover frame selection, audience choice, interaction settings, and disclosures you enter for a post.
- Operational metadata. Identifiers and status of posts you create through the Service (for example a publish ID and whether a post succeeded, is processing, or failed) and the times you scheduled them — used to run scheduling and to report results and errors back to you.
- Limited technical data. Basic logs needed to operate and secure the Service (such as error messages). We do not use tracking cookies or advertising identifiers.
2. How we use information
- To display the posting screen, including the connected account's name and avatar, so you always know which account a post will go to.
- To publish or schedule the content you submit to the account you selected.
- To report the status of your posts and surface errors.
- To maintain, secure, and troubleshoot the Service.
We do not sell your personal information, use it for advertising or profiling, or post anything without an action you take.
3. TikTok data
Our use and transfer of information received from TikTok APIs adheres to the
TikTok
Developer Terms of Service and applicable TikTok policies. We request only the
permissions the Service needs to function — to read your basic profile so we can show your
account, and to upload and publish the videos you choose
(user.info.basic, video.upload, video.publish). TikTok
information is used solely to provide the posting features you request and is not shared with
any third party other than as described in this Policy.
4. How we share information
- With the platform you post to. When you publish, your content and the settings you chose are sent to the platform you selected (e.g. TikTok) to create the post.
- Service providers. We may use vetted infrastructure providers (such as hosting) strictly to operate the Service, bound by confidentiality and data-protection obligations.
- Legal. We may disclose information if required by law or to protect rights, safety, or the integrity of the Service.
We never sell or rent your data, and we do not share it for others' advertising.
5. Storage, security & retention
Authorization credentials are stored securely and used only to act on your behalf. Access tokens are short-lived and refreshed as needed; we keep your refresh token only for as long as your account remains connected. Content you publish is transmitted to the destination platform and not retained by us beyond what is needed to complete and report the post. We apply reasonable technical and organizational measures to protect information, though no method of transmission or storage is completely secure.
6. Your choices & revoking access
- Disconnect at any time. You can revoke the Service's access from your platform's settings — for TikTok, under Settings → Security & permissions → Manage app permissions — or by contacting us. Revoking access invalidates the credential and stops any further posting.
- Deletion. When you disconnect, or on request, we delete the stored authorization credentials and associated account profile data for that connection. To request deletion of any information we hold, email privacy@sabotage.dev.
- Access & correction. You may ask what information we hold about a connection and request correction or deletion.
7. Children's privacy
The Service is intended for use by adult creators and is not directed to children. We do not knowingly collect information from anyone under the age required by their local law to hold a social media or developer account.
8. International users
The Service may be operated from, and information processed in, the United States or other countries. By using the Service you consent to processing in those locations.
9. Changes to this Policy
We may update this Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice. Continued use after an update constitutes acceptance of the revised Policy.
10. Contact
Questions or requests about this Policy or your data: privacy@sabotage.dev.