Data & security
snanipro runs on a single private server controlled by its operator. There is no shared platform, no analytics vendor and no advertising network involved.
What is stored
| Data | Purpose | Retention |
|---|---|---|
| OAuth access and refresh tokens | Publishing to the connected account without a password | Until the account is disconnected or the token expires |
| Account name, identifier and avatar | Showing which account a video will be published to | Until the account is disconnected |
| Video files and captions added by the operator | Queuing and publishing the post | Deleted once published, and in any case within 90 days |
| Publication result and post URL | Knowing whether a publication succeeded and finding it again | 12 months |
| Server logs | Diagnosing failures | 30 days |
What is never collected
- Passwords for any connected platform. Authorisation always goes through TikTok's own OAuth screen.
- The content of the connected account: existing videos, comments, followers, messages and analytics are not read.
- Data belonging to anyone other than the operator. There is no public sign-up and no third-party user base.
- Biometric data, precise location, contacts, or any special category of personal data.
Where the data lives
Everything is hosted on a single dedicated server in the European Union, operated by its owner. Nothing is copied to a third-party analytics, marketing or profiling service, and no personal data is sold, rented or shared.
How it is protected
- All traffic is served over HTTPS with certificates renewed automatically.
- Administrative access requires an SSH key; password login is disabled.
- Access tokens are stored encrypted at rest.
- Services run in isolated containers with no publicly exposed database port.
- Only the three scopes needed to publish are requested, following the principle of least privilege.
Deletion
Disconnecting an account inside snanipro deletes its tokens and details immediately. Revoking access from TikTok's own settings makes the stored token unusable at once. A full deletion of everything held can be requested at any time at the address on the Contact page, and is carried out within 30 days.
Incidents
If a security incident affecting personal data occurs, the operator notifies the competent supervisory authority within 72 hours of becoming aware of it, in line with Article 33 of the GDPR, and informs any affected person without undue delay.
The formal version of these commitments is in the Privacy Policy.