Privacy policy
Last updated 5 September 2026
socialgen is a small tool operated by David Noé Bänziger. It is not offered as a
service to the public and there is no signup: access is a single API key, which the operator shares
with a handful of friends. Anyone holding that key uses the operator's own installation, so this
policy describes what that installation stores and why - because TikTok's developer platform requires
one, and because the answer should be written down.
Who is responsible
- Controller
- David Noé Bänziger
- Contact
- hello@davidnoe.art
What is stored
- TikTok access and refresh tokens for the operator's own connected accounts.
They are held server-side in private object storage, are never sent to a browser, and are used only
to publish posts and to read back the performance of posts on those same accounts.
- The account's own public profile fields that TikTok returns: open id, display
name, username, avatar URL, and follower, following, like and video counts.
- Public metrics for the operator's own posts: view, like, comment and share
counts, with the post's id, creation time, title, description and cover image URL. Readings are
kept over time so that growth can be measured.
- Content the operator creates: slideshow and video documents, rendered images
and video files, captions, and files the operator uploads.
- A single API key that gates the interface. It is shared directly with a
small number of friends rather than issued per person, so the application does not store personal
accounts, names or email addresses for them - there is nothing to store, because there is no
registration.
What is not stored
- No data about any TikTok user other than the accounts deliberately connected to this
installation by the operator or by someone they gave the key to.
- No viewer, follower or audience data. TikTok does not expose it and socialgen does not seek it.
- No advertising identifiers, no cross-site tracking, no analytics scripts, and no cookies beyond
what is technically required to serve the page.
- No payment data. Nothing is sold.
Why it is stored
Tokens exist to perform the actions the operator explicitly asked for: sending a post to their own
TikTok drafts, and reading back how their own posts performed. Metrics are retained over time because
a single reading cannot show whether a post is still being distributed. Content is stored so it can be
edited, re-rendered and published.
Who it is shared with
No third party. Data is not sold, rented or disclosed. It is processed by the infrastructure
providers that host the application - Cloudflare, for compute and object storage - and is transmitted
to TikTok only as part of requests a key holder initiates. Note that the key is shared rather than
per-person, so everyone holding it can see everything in the installation: it is a tool shared between
people who know each other, not a multi-tenant service, and it should not be used for anything you
would not show them.
Retention and deletion
Tokens are deleted immediately when an account is disconnected. Content and metric history are
kept until deleted. Anyone whose TikTok account is connected can revoke socialgen's access from within
TikTok at any time, which stops all further reading and publishing, and can ask the operator at the
address above to erase anything already stored.
Your rights
If you believe this application holds data about you, write to the contact address above and it
will be located and erased. Under the GDPR you have rights of access, rectification, erasure,
restriction, portability and objection, and a right to complain to a supervisory authority.
Changes
Material changes will be reflected here with a new date at the top of this page.