PRIVACY POLICY
Effective date: 29 July 2026
1. WHO WE ARE
Poliora Publisher is a web-based service for preparing and publishing user-selected content to connected TikTok accounts.
The data controller responsible for the processing described in this Privacy Policy is:
Yury Prakopchyk
ul. Hawelańska 4A/11
61-625 Poznań
Poland
Email: yurykierowca@gmail.com
In this Privacy Policy, “Poliora Publisher”, “we”, “us”, and “our” refer to the service operated by the data controller identified above.
2. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy explains how Poliora Publisher collects, uses, stores, protects, and discloses personal data when an authorized user accesses the website, connects a TikTok account, uploads media, prepares a post, uses optional caption-generation tools, publishes content, or contacts us.
The current version of Poliora Publisher does not provide public self-registration, email marketing, third-party advertising, or third-party analytics. This Privacy Policy will be updated before any materially different processing is introduced.
3. DATA WE PROCESS
3.1 Authentication and session data
When an authorized user signs in, we process authentication information required to verify access to the service.
We also use a signed administrative session cookie named “poliora_admin_session”. The cookie is necessary to keep the user signed in and protect restricted areas of the service.
The session cookie:
- is marked HttpOnly;
- is marked Secure in production;
- uses SameSite=Lax;
- is limited to the Poliora Publisher website;
- expires after approximately 12 hours.
3.2 Connected TikTok account data
When a user connects a TikTok account through TikTok OAuth, we may process:
- TikTok account or provider user identifier;
- username or handle, where available;
- display name;
- profile image or avatar URL;
- permissions and scopes granted to Poliora Publisher;
- connection status;
- token expiry information;
- other limited account information returned by TikTok that is necessary to display and operate the connection.
TikTok access and refresh tokens are stored on the server in encrypted form. They are not displayed in the normal user interface and are not returned through ordinary account responses.
3.3 Uploaded media and content data
When a user uploads or selects media, we may process:
- uploaded video or image files;
- original filename and display name;
- file format, MIME type, size, dimensions, duration, and related technical metadata;
- thumbnails and preview files;
- folders and media-library organization data;
- captions and hashtags;
- TikTok visibility selection;
- comment, duet, and stitch preferences;
- scheduling date, time, and timezone;
- other settings selected by the user for the post.
3.4 Publishing and operational data
To submit and track posts, we may process:
- publishing status;
- scheduled and completed timestamps;
- TikTok publish or post identifiers;
- TikTok status responses;
- error codes and error messages;
- retry and processing information;
- limited provider response data;
- application and publishing logs required to diagnose failures and maintain the service.
3.5 Security and technical data
We may temporarily process technical information needed to secure and operate the service, including:
- IP address used as a temporary rate-limiting key for login protection;
- dates and times of requests and operations;
- authentication and session events;
- application errors;
- service and publishing logs.
The login rate limiter currently keeps its temporary IP-based records in server memory for approximately 15 minutes. The checked implementation does not intentionally store IP addresses permanently in the application database.
We do not currently use device fingerprinting, advertising trackers, or third-party analytics cookies.
3.6 Optional AI caption-generation data
When the optional AI caption-generation feature is used, Poliora Publisher may send the following information to OpenAI’s API:
- the user’s caption instruction;
- selected language;
- selected tone;
- generation mode;
- media filename;
- optional context supplied by the user.
This information is used only to generate the requested caption. Users should not include sensitive personal data or confidential information in AI instructions unless it is necessary and lawful to do so.
4. HOW WE COLLECT DATA
We collect data:
- directly from the user when the user signs in, uploads media, enters text, selects publishing settings, or contacts us;
- from TikTok when the user authorizes the connection through TikTok OAuth;
- automatically when the service creates session, security, status, and operational records necessary to function;
- from OpenAI when the optional AI-caption feature returns generated text.
5. PURPOSES AND LEGAL BASES
5.1 Providing the requested service
We process account connection data, uploaded media, captions, publishing settings, scheduling information, tokens, and publishing statuses to perform actions requested by the user and provide Poliora Publisher.
Legal basis: Article 6(1)(b) GDPR — performance of a contract or steps taken at the user’s request.
5.2 Maintaining security and preventing abuse
We process session information, temporary IP-based rate-limit data, authentication events, and relevant technical logs to protect accounts, prevent unauthorized access, and maintain service security.
Legal basis: Article 6(1)(f) GDPR — our legitimate interests in securing and protecting the service.
5.3 Diagnosing errors and maintaining reliability
We process error messages, provider responses, timestamps, status records, and service logs to investigate failed operations and improve reliability.
Legal basis: Article 6(1)(f) GDPR — our legitimate interests in maintaining and troubleshooting the service.
5.4 Complying with legal obligations
We may process or retain limited information where necessary to comply with applicable law, respond to lawful requests, establish or defend legal claims, or protect the rights and safety of users and third parties.
Legal basis: Article 6(1)(c) GDPR and, where applicable, Article 6(1)(f) GDPR.
5.5 Consent-based processing
Where we specifically ask for consent for an optional activity, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time without affecting processing performed before withdrawal.
6. WHO RECEIVES DATA
We do not sell personal data and do not share personal data with advertisers.
Personal data may be disclosed only where necessary to:
- TikTok, when the user connects an account or submits content through TikTok’s services;
- OpenAI, only when the user actively uses the optional AI caption-generation feature;
- hosting, server, network, and infrastructure providers that help us operate and secure Poliora Publisher;
- professional advisers or public authorities where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
Each external provider processes information according to its own terms, privacy documentation, and applicable data-protection obligations.
7. INTERNATIONAL DATA TRANSFERS
TikTok, OpenAI, and infrastructure providers may process data in countries outside Poland or outside the European Economic Area.
Where GDPR requires a transfer mechanism, the relevant provider may rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard recognized by applicable data-protection law.
Users should also review the privacy information provided directly by TikTok and OpenAI for details about their processing locations and safeguards.
8. DATA RETENTION
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Current retention rules include:
- administrative session cookies expire after approximately 12 hours;
- temporary IP-based login rate-limit records remain in server memory for approximately 15 minutes;
- active TikTok connection credentials are kept while the connection is required and may be cleared when the account is disconnected or access is revoked;
- uploaded media is retained until deleted, moved to trash, or no longer required for the publishing workflow;
- eligible unreferenced media placed in trash may be permanently purged after approximately three days when the automatic cleanup worker is active;
- media referenced by publication records may be retained longer to preserve the integrity of publishing history;
- publication records, statuses, errors, and operational logs are retained for as long as needed to provide status information, diagnose failures, maintain service integrity, comply with legal duties, or handle legal claims;
- no fixed automatic deletion period is currently configured for all publication history and operational logs.
When data is no longer required, we will delete it, anonymize it, or restrict its continued processing where reasonably possible.
9. TIKTOK DISCONNECTION AND DATA DELETION
A connected TikTok account may be disconnected through Poliora Publisher where that option is available.
Disconnecting an account stops the active connection and may clear locally stored credentials and permissions used by the connection. Some account metadata, publication records, and status history may remain where necessary to preserve the integrity of previous publishing activity.
A user may also revoke Poliora Publisher’s authorization directly through the user’s TikTok account settings.
To request access, correction, deletion, or removal of connected account data, media, or publication information, contact:
There is currently no automated full-account deletion tool. Requests are handled manually after appropriate identity verification.
Deletion may be limited where retention is required by law, necessary for legal claims, or technically required to preserve records relating to completed publishing operations.
10. COOKIES
Poliora Publisher currently uses only the essential session cookie necessary for authentication and restricted access.
We do not currently use:
- advertising cookies;
- marketing cookies;
- third-party analytics cookies;
- cross-site behavioral tracking cookies.
Because the session cookie is strictly necessary to provide authenticated access, disabling it may prevent the user from signing in or using protected features.
11. DATA SECURITY
We use reasonable technical and organizational measures designed to protect personal data, including:
- HTTPS encryption in transit;
- server-side storage of OAuth credentials;
- encryption of TikTok access and refresh tokens at rest;
- signed, HttpOnly, Secure session cookies in production;
- authentication and login rate limiting;
- restricted administrative access;
- separation of normal user-facing information from internal credentials and technical data.
No system can guarantee absolute security. Users should protect their login credentials and notify us if they suspect unauthorized access.
12. USER RIGHTS UNDER GDPR
Subject to applicable law, users may have the right to:
- obtain confirmation as to whether their personal data is processed;
- request access to their personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive data in a structured, commonly used, machine-readable format where data portability applies;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority;
- seek an effective judicial remedy.
Requests may be sent to yurykierowca@gmail.com.
We may request information reasonably necessary to verify the requester’s identity. We normally respond within the period required by applicable data-protection law.
Users in Poland may lodge a complaint with:
President of the Personal Data Protection Office
Urząd Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A
00-014 Warszawa
Poland
Official website:
https://uodo.gov.pl/
13. AUTOMATED DECISION-MAKING
Poliora Publisher does not currently use personal data to make solely automated decisions that produce legal effects or similarly significant effects concerning a user.
AI caption generation produces optional text suggestions. The user decides whether to use, edit, or discard the generated text and whether to publish any post.
14. CHILDREN
Poliora Publisher is not intended for children under 18 years of age. We do not knowingly collect personal data from children through public registration.
If you believe that a child has provided personal data to Poliora Publisher, contact yurykierowca@gmail.com so that the matter can be investigated and appropriate action taken.
15. THIRD-PARTY SERVICES
Use of TikTok and OpenAI is also subject to the separate terms and privacy policies of those providers.
Poliora Publisher is not responsible for independent processing performed by third-party services outside our control.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy when the service, legal requirements, or data-processing practices change.
The effective date at the top of the page will be updated when material changes are published. Where required by law, users will be informed through the service or another appropriate method.
17. CONTACT
Questions, requests, or complaints concerning this Privacy Policy or personal-data processing may be sent to:
Yury Prakopchyk
ul. Hawelańska 4A/11
61-625 Poznań
Poland
Email: yurykierowca@gmail.com