Xoma Post

Privacy Policy — Xoma Post

Effective date: September 25, 2026

This Privacy Policy explains what information Xoma Post ("the Service") handles, why, and for how long.

1. Information we process

- TikTok account identifier and basic profile data (e.g., open ID, display name): obtained when you log in with TikTok, used solely to identify your account within the dashboard.

- Access token: obtained via TikTok Login Kit, used solely to call the TikTok Content Posting API when you publish a video. Stored encrypted on our server and never shared with anyone other than TikTok.

- Upload metadata (video title/caption you write, upload status, and the video ID returned by TikTok): kept so you can see the history of your publications.

- Your videos: they remain on your own storage. Only the video file you explicitly choose to publish is transmitted, and it is transmitted directly to TikTok.

2. What we do NOT do

- We do not read your TikTok feed, messages, or followers.

- We do not access TikTok analytics or insights.

- We do not sell, rent, or share your data with advertisers or third parties.

- We do not publish anything without an explicit action from you.

3. Storage and retention

- Access tokens are kept until you disconnect your account or revoke access from your TikTok settings.

- Upload history is kept until you delete it.

- You may request deletion of all data associated with your account at any time via support@rzzro.com; we will delete it within 72 hours.

4. Third parties

The only external service involved is TikTok (Login Kit and Content Posting API). Their handling of your data once a video is published is governed by TikTok's own Privacy Policy.

5. Your rights

Depending on your jurisdiction (e.g., GDPR, CCPA), you may have rights to access, correct, export, or delete your personal data. To exercise them, contact support@rzzro.com.

6. Security

Access tokens are stored encrypted; all traffic runs over HTTPS; server access is restricted to the operator.

7. Contact

support@rzzro.com