Privacy Policy
Last updated: 20 August 2026 · Effective date: 20 August 2026
This policy explains what personal data snanipro processes, why, on what legal basis, how long it is kept, and what rights you have. It covers data obtained through the TikTok API.
1. Who is responsible
snanipro (the "Service") is a self-hosted publishing tool operated privately by an individual based in France (the "Operator", "we"), who is the data controller within the meaning of Article 4(7) of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
The Service is not offered to the public. It has no sign-up, no customer accounts and no third-party users. It connects only to TikTok accounts that the Operator owns and controls. Contact details are on the Contact page.
2. Scope of this policy
This policy applies to the Service, to this website, and to any data obtained from TikTok. It does not apply to TikTok itself: once a video is published, the TikTok privacy policy governs how it handles that content and its viewers.
3. Personal data we process
3.1 Data obtained through the TikTok API
When the Operator authorises the Service on an account he owns, TikTok returns a limited set of data. We process only the following:
| Data | Scope | Purpose |
|---|---|---|
| Access token and refresh token | — | Authenticating publication requests without storing a password |
| Open ID, display name, avatar, profile link | user.info.basic, user.info.profile | Showing which account a video will be published to, so the destination can be verified before publishing |
| Upload identifier and transfer status | video.upload | Transferring the video file to the drafts of the account and confirming the transfer |
We do not request or process the existing videos of the account, its analytics, comments, followers, direct messages, email address, phone number or date of birth.
3.2 Data created by the Operator
Video files, captions and scheduling instructions added by the Operator inside the Service.
3.3 Technical data
Server logs generated automatically when the Service runs, containing timestamps, request paths, HTTP status codes and error messages. These may incidentally include an IP address.
3.4 Website visitors
This website uses no cookies, no analytics, no tracking pixels and no advertising scripts. Nothing is stored in your browser and no profile is built about you. The web server records standard access logs as described in section 3.3.
4. Legal bases for processing
- Consent (Article 6(1)(a) GDPR) — for connecting a TikTok account. Consent is given through the TikTok authorisation screen and can be withdrawn at any time by disconnecting the account.
- Legitimate interests (Article 6(1)(f) GDPR) — for keeping short-lived server logs in order to detect failures, secure the server and diagnose incidents. We have assessed that this does not override the rights of any individual, given that no third-party data is involved.
5. How long data is kept
| Category | Retention period |
|---|---|
| Access and refresh tokens | Until the account is disconnected, access is revoked, or the token expires |
| Account identifier, display name, avatar | Until the account is disconnected |
| Video files and captions | Deleted once published, and in any case within 90 days |
| Publication results and post URLs | 12 months |
| Server logs | 30 days |
When a retention period ends, the data is deleted from the live system. Encrypted backups are rotated on a 30-day cycle, so a deleted item may persist in a backup for up to 30 further days before being overwritten.
6. Sharing and disclosure
We do not sell, rent, trade or share personal data with third parties for their own purposes. There is no advertising, no profiling and no automated decision-making producing legal or similarly significant effects.
Data is transmitted to TikTok only when the Operator publishes content, and only to the extent needed to carry out that publication. The infrastructure provider hosting the server acts as a processor and has no access to application data.
We may disclose data if required by a binding legal obligation, a court order, or a lawful request from a competent authority.
7. International transfers
The server is located in the European Union. Publishing a video necessarily transmits it to TikTok, which may process it outside the European Economic Area under its own safeguards and privacy policy. No other transfer outside the EEA takes place.
8. Security
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR: HTTPS for all traffic, encryption of access tokens at rest, SSH key authentication with passwords disabled, isolation of services in containers with no publicly exposed database port, and least-privilege API scopes. No system can be guaranteed perfectly secure, but access to this one is limited to a single administrator.
9. Data breaches
If a personal data breach occurs, we notify the competent supervisory authority within 72 hours of becoming aware of it, in accordance with Article 33 GDPR, and inform affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
10. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting processing carried out before withdrawal.
To exercise any of these rights, write to cavarrats@gmail.com. We respond within 30 days. You also have the right to lodge a complaint with the French supervisory authority, the CNIL (cnil.fr), or with the authority of your country of residence.
11. Revoking access
Access granted to the Service can be withdrawn at any time, independently of us, from TikTok: Profile, then Settings and privacy, then Security and permissions, then Manage app permissions. Revocation makes the stored token unusable immediately. Disconnecting the account inside the Service additionally deletes it from our storage.
12. Children
The Service is not directed at children and is not available to anyone under 18. We do not knowingly process personal data relating to a child. If you believe the data of a child has reached us, contact us and it will be deleted.
13. Changes to this policy
We may update this policy to reflect changes in the Service or in applicable law. The date at the top of this page always shows the current version. Material changes will be reflected here before they take effect. If the Service is ever opened to users other than the Operator, this policy will be revised beforehand.
14. Contact
Questions about this policy or about how your data is handled: cavarrats@gmail.com.