Effective date: 2026-08-14. This policy explains how THANKS KAI Creator Studio handles information when independent sellers and creators use the service.
Data we collect: account email, display name, password hash, workspace details, security-session records, media the user uploads, captions and draft settings, preview files, and TikTok publishing-job status.
TikTok data: after a user authorizes Login Kit and the Content Posting API, we receive the TikTok open ID, display name, avatar URL, account publishing options, encrypted access and refresh tokens, and publishing status needed to provide Direct Post and Inbox Draft delivery.
Purposes: we use the data to authenticate users, isolate workspaces, generate user-requested previews, show the connected TikTok identity and available choices, submit posts only after explicit confirmation, report status, prevent abuse, and support account deletion.
Sharing and APIs: for Direct Post, we send the confirmed caption, settings, and tokenized preview-video URL to TikTok. For Inbox Draft, we send only the tokenized preview-video URL and the user completes editing in TikTok. TikTok may retrieve that video through the Content Posting API. We do not sell personal information.
Retention and deletion: account and workspace records remain while the account is active. Expired sessions and OAuth states are pruned. Disconnecting TikTok removes the locally stored encrypted authorization. Account deletion removes workspace records, uploaded assets, previews, drafts, publishing records, sessions, and linked TikTok authorization, while also attempting TikTok revocation. If TikTok does not confirm revocation during account deletion, or revocation of a newly issued but unusable token temporarily fails, the access token may be retained in encrypted form without user or workspace identifiers for up to 24 hours solely for backoff-limited revocation retries. It is then removed from the service store.
Security: passwords use salted scrypt hashes; TikTok tokens use authenticated AES-256-GCM encryption at rest; sessions use Secure, HttpOnly cookies in production; and every resource is checked against its owning workspace. No internet service can guarantee absolute security.
User rights: users can review their workspace information in Creator Studio, disconnect TikTok, delete individual unused assets, or permanently delete the account. Contact us to request access, correction, or deletion assistance.
Children: Creator Studio is intended for users who are legally eligible to operate their account and use TikTok developer features. It is not directed to children, and users must comply with TikTok age and eligibility requirements.
Changes: material policy changes will be reflected on this public page with a new last-updated date.
Contact: thankskai.shop@gmail.com
Last updated: 2026-08-14