XtoClaw Creator is a web service for independent creators to connect their TikTok account, upload original videos, choose post settings, publish, and view processing status. This policy explains what data the service processes and the choices available to you.
Data we process
- Connected-account data: TikTok open ID, display name, avatar URL, available creator settings, authorized scopes, and encrypted access and refresh tokens.
- Uploaded media: video files you choose to upload, file metadata, and a short-lived storage location used so TikTok can retrieve the file after you consent to publish.
- Publishing records: caption, privacy and interaction choices, disclosure settings, consent confirmation, publish identifiers, processing status, and failure reason.
- Support data: the email address, request category, message, browser user-agent, and timestamp you submit through the support form.
- Technical data: basic security and rate-limit information such as IP-derived request identity, request time, and service logs. Rate-limit identities are hashed.
How we use data
We process this data only to authenticate the connected account, render current creator controls, transfer media you expressly choose to publish, show delivery status, protect the service, respond to support and privacy requests, and comply with legal or platform obligations.
TikTok data and authorization
TikTok authorization tokens remain server-side and are encrypted at rest. We do not sell TikTok data, use it to profile you, or share it with unrelated advertisers. When you disconnect in the workspace, the service attempts to revoke access with TikTok, deletes the locally stored authorization tokens, and marks the connection disconnected.
Media retention
Uploaded media is scheduled for deletion after 24 hours. It may be removed sooner after the posting workflow finishes. Publishing records and security logs may be retained longer when needed to provide status history, prevent abuse, resolve support issues, or meet legal obligations.
Service providers
Cloudflare hosts the website, Worker API, database, rate-limit storage, and temporary media storage. TikTok processes authorization and publishing requests under its own terms and privacy policy. No payment processor is active during the free review-access period.
Local browser storage
The review workspace stores the reviewer access code in session storage so it is cleared when the browser session ends. The local video preview is created in your browser and is not transmitted until you press the upload action.
Your choices
- Do not upload a file or publish a post unless you are ready to send it.
- Disconnect the linked TikTok account from the workspace at any time.
- Request access, correction, or deletion of your support, account, and publishing data.
- Contact us about a security or privacy concern.
Contact and deletion requests
Use the public support and data-request form. Choose “Privacy request” or “Delete my data” so the request is routed correctly. We may ask for reasonable verification before disclosing or deleting account-linked information.
Changes
We may update this policy when the product or legal requirements change. The effective date above will be updated, and material changes will be disclosed on this page.