Privacy Policy
Last updated: October 6, 2026
1. Introduction
EasyDrop ("we," "our," or "the Service") is a video publishing tool that enables users to upload content to TikTok, Instagram, and YouTube via each platform's official API (the TikTok Content Posting API, the Instagram Graph API, and YouTube API Services). This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
2. Lawful Basis for Processing
We process your personal data on the following lawful bases:
- Consent: When you create an account and link your social accounts (TikTok, Instagram, YouTube), you explicitly consent to data processing as described in this policy.
- Contractual necessity: Processing is necessary to provide the video upload service you requested.
- Legitimate interest: Maintaining security, preventing fraud, and improving the Service.
3. Information We Collect
We collect the following categories of information:
a) Account Information
- Email address and hashed password for app authentication
- If you sign in with TikTok: your TikTok Open ID, display name and avatar URL identify your EasyDrop account instead of an email address. No password and no email are collected, and no TikTok access token is kept for signing in.
b) TikTok Account Data
- TikTok display name and avatar URL (via user.info.basic scope)
- TikTok Open ID (unique account identifier)
- OAuth access tokens and refresh tokens (for publishing on your behalf)
- Authorized scopes (user.info.basic, video.publish, video.list)
We access TikTok data only through the official TikTok API with scopes you explicitly authorize during the OAuth flow.
b2) Instagram & Meta Account Data
- Instagram Business/Creator account id, username, and profile picture (via
instagram_basic) - The id and name of the Facebook Page linked to your Instagram account, and a Page access token used to publish (via
pages_show_list,pages_read_engagement) - Long-lived OAuth access tokens, used solely to publish content you explicitly submit (via
instagram_content_publish) - Profile-level counters of your Instagram account — follower, following, and media counts — refreshed daily to show your account statistics (via
instagram_basic)
We access Instagram and Facebook data only through Meta's official Graph API, with the permissions you grant during the Facebook login flow. We do not read your Instagram media, the identities of your followers, comments, or direct messages. We use this data only to display which account you are posting to, to show your account statistics, and to publish the videos you choose.
b3) YouTube & Google Account Data
- YouTube channel id, title, handle, and avatar (via the
youtube.readonlyscope, read once when you connect the channel) - OAuth access and refresh tokens, used solely to upload the videos you explicitly submit (via the
youtube.uploadscope)
Google Drive. If you choose videos with the “Choose from Google Drive” button, we request the drive.file scope, which gives EasyDrop access only to the files you select in Google's file picker — never to the rest of your Drive. We read only the contents and basic details (name, type, size) of the videos you select, copy them into our storage so they can be published, and handle that copy exactly like a video you upload from your device. We keep the Google Drive file ID of a video you publish together with its post record, only to show you which videos you have already published; it is deleted with that record or with your account. The Google access token is kept in your browser's memory for the session and sent to our server only to download the files you picked; it is never stored on our servers.
Google Drive folder links. If you paste a link to a Google Drive folder that its owner has shared with “Anyone with the link”, EasyDrop reads that folder with its own Google API key, without asking you to sign in to Google. We read only the names, types, sizes, thumbnails and durations of the folder's items to show them to you, and copy into our storage only the videos you select; they are then handled exactly like a video you upload from your device. Thumbnails are loaded by your browser directly from Google. We keep the Google Drive file ID of a video you publish together with its post record, only to show you which videos you have already published; it is deleted with that record or with your account. No Google account data is involved.
EasyDrop uses YouTube API Services. We access YouTube data only through Google's official APIs with the scopes you explicitly authorize on the Google consent screen. We do not read your videos, subscribers, comments, or watch history. See section 9c below for how this data is handled and how to revoke access.
c) Video Content
- Video files you upload for publishing
- Publishing preferences for each platform: caption/description; TikTok privacy level and interaction settings (comments, duets, stitches); YouTube title, visibility, made-for-kids declaration, and optional category and tags
- Branded content and commercial disclosure settings
d) User-Provided API Credentials (Optional)
- TikTok Developer App client_key and client_secret, if you choose to provide your own
These credentials are stored encrypted in our backend and used only to authenticate API requests on your behalf. We never share them with third parties.
e) API Usage Data
- API request logs: endpoint, method, status code, response time
- IP address and User-Agent (from API requests)
- API key identifiers and last-used timestamps
f) Telegram (Optional)
- Every time you open our Telegram mini app, Telegram sends it your Telegram user ID, first and last name, username, language, a link to your profile photo, your Premium status, and the chat you opened it from. This happens whether or not you have linked Telegram to your EasyDrop account. We only store your Telegram user ID and username, and only once you link your account. We send nothing to Telegram.
g) Mobile App (Optional)
- If you sign in with Apple, Apple sends us a stable Apple user identifier, and the email address you chose to share (which may be an Apple private-relay address) and your name the first time.
- If you allow notifications, we store a push token for your device and a random identifier for the app installation, so we can tell you when a scheduled post was published or failed. Notifications name only the platform (for example "Instagram"), never your account.
h) Automatically Collected
- We use PostHog (PostHog Inc., USA) for privacy-focused product analytics. It stores a random identifier in your browser's localStorage and does not use advertising cookies or tracking pixels. We never send it your social-media account identifiers or access tokens. See PostHog's privacy policy at posthog.com/privacy
4. How We Use Your Information
We use your information for the limited purpose of enabling and providing the video publishing service across the platforms you connect (TikTok, Instagram, YouTube):
- Authenticating you within the application
- Publishing video content to your linked accounts as you direct
- Refreshing OAuth tokens to maintain your platform connections
- Displaying upload history and status
- Processing API requests when you use the programmatic upload API
- Monitoring API usage for security and abuse prevention
We do NOT use your TikTok, Instagram, or YouTube data to: analyze or profile user behavior, serve targeted advertising, build user profiles for marketing, monetize or sell your data, or perform any processing beyond what is necessary to provide this Service.
5. Data Storage and Security
Your data is stored using Convex, a SOC 2 Type II compliant cloud backend provider. Convex acts as our data processor and stores data in secure, encrypted infrastructure.
- OAuth tokens are encrypted at rest in the Convex database
- We never store your TikTok, Instagram, or Google password — platform authentication is handled entirely via each platform's OAuth
- User-provided API credentials (client_secret) are stored encrypted and never exposed in logs or API responses
- API keys are stored as SHA-256 hashes — the plaintext key is shown once at creation and never retrievable again
- Video files are stored temporarily for the purpose of uploading to the platforms you selected and may be deleted after successful publishing
We maintain appropriate technical and administrative controls in accordance with industry standards to ensure the security and confidentiality of your data and protect against unauthorized access, disclosure, or destruction.
6. Data Sharing
We share your data with the following parties and for the stated purposes:
- TikTok (ByteDance): Video content, titles, and publishing settings are transmitted to TikTok via the Content Posting API when you initiate an upload. This is governed by TikTok's Privacy Policy.
- Meta (Instagram & Facebook): When you initiate an Instagram upload, your video and caption are transmitted to Meta via the Instagram Graph API to create and publish the post. This is governed by Meta's Privacy Policy.
- Google (YouTube): When you initiate a YouTube upload, your video, title, description, and publishing settings are transmitted to YouTube via the YouTube Data API. This is governed by the Google Privacy Policy.
- Convex: Our backend infrastructure provider stores and processes data on our behalf as a data processor.
- Netlify: Our web hosting provider serves the application and the OAuth callback endpoints as a data processor.
- Cloudflare R2: Uploaded video files are stored in Cloudflare R2 object storage as a data processor, and deleted after successful publishing.
- Expo (650 Industries, Inc., USA): Delivers push notifications to the mobile app on our behalf as a data processor. It receives your device's push token and the notification text, which names the platform but contains no account names or other social-media data.
We do NOT sell, rent, or trade your personal information to any third party. We do NOT disclose your data for cross-context behavioral advertising. We do NOT share TikTok, Instagram, Facebook, or YouTube user data with data brokers or advertising networks.
7. Data Retention
- Account data: Retained for as long as your account is active. Deleted within 30 days of account deletion request.
- OAuth tokens: Stored until you disconnect the linked account (TikTok, Instagram, or YouTube) or your tokens expire and cannot be refreshed. Disconnecting deletes the stored tokens immediately; if you revoke access on the platform's side instead, stored Google/YouTube data is deleted within 7 days.
- Video files: Stored temporarily for upload processing. You may delete uploaded videos at any time.
- API request logs: Retained for 90 days for security and debugging purposes, then automatically deleted.
- User-provided API credentials: Deleted immediately when you click "Use Default Keys" or delete your account.
- Telegram link: Deleted immediately when you unlink Telegram in Settings or delete your account.
- Push tokens: Deleted when you sign out of the mobile app or delete your account.
- TikTok posting-limit record: A one-way fingerprint of a TikTok account that published, or attempted to publish, in the last 24 hours is kept to respect TikTok's limit on how many accounts can post through the Service. Deleted within 25 hours of the account's last attempt.
8. Your Rights
All Users
- Disconnect your linked accounts (TikTok, Instagram, YouTube) at any time, immediately revoking our access
- Delete your account and all associated data
- Request a copy of all data we store about you
- Revoke or delete API keys at any time
GDPR Rights (EU/EEA Users)
- Right of access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data ("right to be forgotten")
- Right to restrict processing: Request limitation of data processing
- Right to data portability: Receive your data in a machine-readable format
- Right to object: Object to data processing based on legitimate interest
- Right to withdraw consent: Withdraw consent at any time without affecting prior processing
CCPA/CPRA Rights (California Users)
- Right to know: What personal information we collect, use, and disclose
- Right to delete: Request deletion of your personal information
- Right to opt-out: Opt out of the sale or sharing of personal information (we do not sell your data)
- Right to non-discrimination: Exercise your rights without discriminatory treatment
To exercise any of these rights, contact us at support@seocreativestudio.com. We will respond within 30 days.
9. TikTok Data Usage
We access TikTok data only through the official TikTok API with scopes you explicitly authorize. Our use of TikTok data is governed by the TikTok Developer Terms of Service and the TikTok Privacy Policy.
We do not analyze, profile, or monetize your TikTok data beyond what is necessary to provide the video upload functionality of this Service.
9b. Instagram & Meta Data Usage
We access Instagram and Facebook data only through Meta's official Graph API with the permissions you explicitly grant. Our use of this data complies with the Meta Platform Terms and Developer Policies.
We use Instagram and Facebook data solely to (a) identify and display the account you are publishing to and (b) publish the videos you explicitly submit. We do not analyze, profile, or monetize this data, and we do not access media, audience, comments, or messages. You can revoke our access at any time by disconnecting the account here or in your Facebook Business Integrations settings.
9c. YouTube API Services & Google Data Usage
EasyDrop uses YouTube API Services to publish videos to the YouTube channels you connect. By connecting a YouTube channel and using this functionality, you also agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
For YouTube, we use Google user data solely to (a) identify and display the channel you are publishing to (channel id, title, handle, avatar) and (b) upload the videos you explicitly submit, with the title, description, visibility, and audience settings you chose. We store OAuth tokens and the channel profile fields listed in section 3(b3) for as long as the channel stays connected, refresh them through Google's API, and do not share them with any third party beyond the processors listed in section 6. We do not analyze, profile, or monetize this data.
For Google Drive, Google user data is used solely to copy the video files you pick into EasyDrop so they can be published to the accounts you choose. EasyDrop's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke EasyDrop's access at any time by disconnecting the channel on the Accounts page (stored tokens are deleted immediately) or via the Google security settings page. Google Drive access can likewise be revoked at any time on that Google permissions page. After a revocation on Google's side, we delete the stored Google user data within 7 days.
10. Children's Privacy
This Service is not intended for children under the age of 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we discover that we have collected data from a child, we will delete it promptly.
11. International Data Transfers
Your data may be processed in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a new "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
The data controller for this Service is SEO Creative Studio LLP, a limited liability partnership registered in England and Wales (Companies House no. OC460920).
For privacy-related questions, data access requests, or complaints, contact us at: