Privacy Policy
Last updated: December 6, 2025
1. Introduction
Janex AutoTok ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
2. Information We Collect
2.1 Information from TikTok
When you authenticate with TikTok through our Service using OAuth 2.0, we receive the following information from TikTok's API:
- TikTok Open ID: A unique identifier for your TikTok account, used to associate videos with your account
- TikTok Union ID: A cross-application identifier (if available), used for account management
- Display Name: Your TikTok display name, shown in our Service dashboard
- Avatar URL: URL to your TikTok profile picture, displayed in our Service
- Access Tokens: Encrypted tokens that allow our Service to make API calls on your behalf
- Refresh Tokens: Encrypted tokens used to obtain new access tokens when they expire
- Token Expiration Information: Timestamps indicating when tokens expire and need to be refreshed
- Granted Permissions (Scopes): The specific API permissions you granted (user.info.basic, video.upload, video.publish)
This information is collected through TikTok's official OAuth 2.0 authorization flow and is necessary for the Service to function. We do not collect your TikTok password or any other authentication credentials.
2.2 Content You Upload
When you upload videos through our Service, we collect and store:
- Video Files: Video files (MP4, MOV, WebM, MPEG, 3GP, AVI) are stored on our servers until successfully published to TikTok
- Video Metadata: File names, file sizes, upload timestamps, and modification dates
- Video Captions: Text captions you provide for your videos (up to 150 characters)
- Publication Settings: Privacy settings, comment settings, and other publication preferences
- Scheduled Upload Times: Future dates and times when videos are scheduled for publication
- Upload Status: Information about upload progress, publication status, and any errors
- TikTok Publish IDs: Unique identifiers returned by TikTok's API for tracking publication status
Video files are stored securely on our servers and are automatically deleted after successful publication to TikTok, or upon your request. We do not modify your video content except as necessary to comply with TikTok's API requirements.
2.3 AI Video Generation Data (Vadoo)
When you use AI video generation features, we collect and store:
- Text Prompts: The text input you provide for video generation, which may be optimized before sending to Vadoo
- Generation Parameters: Settings such as language, voice, theme, style, duration, aspect ratio, and custom instructions
- Vadoo Video IDs: Unique identifiers returned by Vadoo's API for tracking generation status
- Generated Video Files: Video files created by Vadoo, stored on our servers until published or deleted
- Generation Status: Status information (pending, processing, completed, failed) and error messages
- Generation Timestamps: When generation was initiated, completed, or failed
- Scheduled Generation Times: Future dates and times when videos should be automatically generated
- Auto-Upload Settings: Whether generated videos should be automatically uploaded to TikTok
Your text prompts and parameters are transmitted to Vadoo's API for processing. Vadoo's use of this data is governed by Vadoo's own Privacy Policy and Terms of Service. Generated videos are stored securely on our servers and can be automatically deleted after publication or upon your request.
2.4 Caption Templates
When you create caption templates, we collect and store:
- Template Names: Names you assign to your caption templates
- Template Content: The caption text, including variable placeholders
- Template Categories: Categories you assign for organizing templates
- Template Variables: Variable names and placeholders defined in templates
- Default Template Settings: Which templates are marked as default for quick access
- Template Usage: When and how templates are applied to videos
Caption templates are stored securely and associated with your account. You can edit or delete templates at any time through the Service dashboard.
2.5 Video Performance Analytics
We collect and store video performance metrics synced from TikTok's API:
- Views: Number of video views
- Likes: Number of likes received
- Comments: Number of comments
- Shares: Number of shares
- Engagement Rate: Calculated engagement rate based on views and interactions
- TikTok Video IDs: Unique identifiers for videos on TikTok's platform
- Sync Timestamps: When performance data was last synced from TikTok
Performance metrics are periodically synced from TikTok's API. Data accuracy depends on TikTok's reporting and API availability. We are not responsible for the accuracy of metrics provided by TikTok.
2.6 Account Generation Configuration
When you configure automated daily video generation, we collect and store:
- Prompt Templates: Text templates used for generating video prompts
- Generation Schedules: Daily schedules specifying when videos should be generated (count and times)
- Upload Modes: Whether generated videos should be automatically uploaded or require manual review
- Vadoo Parameters: Default generation parameters (language, voice, theme, style, etc.) for automated generation
- Enable/Disable Status: Whether automated generation is enabled for each account
Generation configurations are stored securely and allow you to automate video creation according to your preferences. You can modify or disable these settings at any time.
2.7 Account Health Data
We collect and store account health monitoring data:
- Health Check Results: Results from automated health checks of your TikTok accounts
- Token Status: Whether access tokens are valid and functioning
- API Connection Status: Whether accounts can successfully connect to TikTok's API
- Health Check Timestamps: When health checks were performed
Account health data helps ensure your accounts remain connected and functional. This data is used for service operation and troubleshooting.
2.8 Activity Logs
We maintain comprehensive activity logs that include:
- Action Types: Types of actions performed (upload, generation, deletion, configuration changes, etc.)
- Entity Information: Information about entities involved (video IDs, account IDs, template IDs, etc.)
- Action Details: Detailed information about actions performed, stored as JSON data
- IP Addresses: IP addresses from which actions were performed (for security and fraud prevention)
- User Agents: Browser and device information
- Timestamps: When actions were performed
Activity logs are maintained for security, troubleshooting, and service improvement purposes. IP addresses and user agents are collected automatically for security and fraud prevention.
2.9 User Preferences
We store your user preferences and settings:
- Email Notification Preferences: Whether you want to receive email notifications
- Default Vadoo Settings: Default language, voice, and theme preferences for video generation
- Account Settings: Other user-configurable settings and preferences
2.10 Usage Data
We automatically collect information about how you use the Service, including:
- Account Activity: When you connect or disconnect TikTok accounts
- Upload Activities: Video upload attempts, successful uploads, and failed uploads
- Generation Activities: AI video generation requests, successful generations, and failures
- Scheduled Operations: Scheduled uploads and generations that are executed automatically
- Status Checks: API calls made to check video publication status and generation status
- Analytics Syncs: When performance metrics are synced from TikTok's API
- Error Logs: Technical error information for troubleshooting and service improvement
- API Usage: Number and frequency of API calls made on your behalf (TikTok and Vadoo APIs)
- Session Information: Login sessions and authentication events
This usage data helps us improve the Service, troubleshoot issues, and ensure proper API usage compliance.
2.11 Technical Information
We may collect technical information automatically, including:
- IP addresses (for security and fraud prevention)
- Browser type and version
- Device information
- Request timestamps and response codes
3. How We Use Your Information
We use the information we collect solely for the following purposes:
3.1 Service Provision
- Account Management: To identify your TikTok account and display your profile information in our dashboard
- API Authentication: To authenticate with TikTok's API and maintain your connection
- Video Upload: To upload your videos to TikTok's servers and publish them to your account
- Scheduled Uploads: To schedule videos for future publication at specified dates and times
- AI Video Generation: To generate videos using Vadoo's AI service based on your text prompts and parameters
- Automated Daily Generation: To automatically generate videos according to your configured schedules and settings
- Caption Templates: To store and apply your caption templates when uploading or scheduling videos
- Performance Analytics: To sync and display video performance metrics (views, likes, comments, shares, engagement rates) from TikTok
- Account Health Monitoring: To perform automated health checks and monitor the status of your TikTok accounts
- Status Monitoring: To track upload progress, generation status, and notify you of completion or errors
- Token Management: To automatically refresh access tokens and maintain service continuity
- Activity Logging: To maintain comprehensive logs of your activities for security and troubleshooting
3.2 Service Improvement
- Analyze usage patterns to improve Service functionality
- Identify and fix technical issues and errors
- Optimize API usage and performance
- Develop new features and capabilities
3.3 Communication and Support
- Respond to your inquiries and support requests
- Send service-related notifications (upload status, errors, etc.)
- Notify you of important changes to the Service or these policies
3.4 Legal and Security
- Comply with legal obligations and respond to legal requests
- Detect and prevent fraud, abuse, or security threats
- Enforce our Terms of Service
- Protect the rights, property, or safety of our users or others
We do not use your information for advertising, marketing to third parties, or any purpose other than providing and improving the Service.
4. Technical Implementation and Security
4.1 OAuth 2.0 Authentication Flow
Our Service uses TikTok's official OAuth 2.0 authorization flow:
- You initiate authentication through our Service
- You are redirected to TikTok's authorization server
- You grant permissions (scopes) to our Service
- TikTok redirects you back with an authorization code
- We exchange the authorization code for access and refresh tokens
- We retrieve your basic user information using the access token
- Tokens are securely stored in our encrypted database
4.2 Token Management
We implement secure token management:
- Encrypted Storage: Access tokens and refresh tokens are encrypted at rest using industry-standard encryption
- Automatic Refresh: Access tokens are automatically refreshed before expiration using refresh tokens
- Secure Transmission: Tokens are only transmitted over HTTPS encrypted connections
- Token Revocation: Tokens are immediately invalidated upon account disconnection or deletion
4.3 Data Encryption
We implement multiple layers of encryption:
- In Transit: All API communications with TikTok use HTTPS/TLS 1.2 or higher encryption
- At Rest: Sensitive data (tokens, user identifiers) are encrypted in our database
- Video Files: Video files are stored on secure servers with restricted access
4.4 Access Controls
We restrict access to your data:
- Only authorized personnel with a legitimate need can access user data
- Access is logged and monitored for security purposes
- Multi-factor authentication is required for administrative access
- Regular security audits and access reviews are conducted
4.5 Security Measures
We implement comprehensive security measures:
- Regular security updates and patches
- Intrusion detection and monitoring systems
- Secure coding practices and code reviews
- Regular security assessments and penetration testing
- Incident response procedures
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security. If you become aware of any security vulnerability, please contact us immediately at support@janex.md.
5. API Integration and Data Sharing
5.1 TikTok API Integration
Our Service integrates with TikTok's API and shares data as necessary to provide the Service:
- User Information API: We call TikTok's user.info endpoint to retrieve your display name and avatar
- Video Upload API: We send your video files and metadata to TikTok's upload endpoint
- Video Publish API: We send publication requests with your captions and settings to TikTok
- Status API: We query TikTok's status endpoint to check upload and publication progress
- Analytics API: We query TikTok's video.query endpoint to retrieve performance metrics (views, likes, comments, shares)
All data shared with TikTok is subject to TikTok's Privacy Policy and Terms of Service. We only share the minimum data necessary for each API operation.
5.2 Vadoo AI Video Generation API
Our Service integrates with Vadoo, a third-party AI video generation service, to provide text-to-video functionality. When you use AI video generation features:
- Text Prompts: Your text prompts (which may be optimized before transmission) are sent to Vadoo's API for video generation
- Generation Parameters: Your selected parameters (language, voice, theme, style, duration, aspect ratio, custom instructions) are transmitted to Vadoo
- Generation Requests: We send video generation requests to Vadoo's API on your behalf
- Generated Videos: Vadoo returns generated video files to our Service, which we store on our servers
Vadoo is an independent third-party service provider. Vadoo's use of your data (text prompts and parameters) is governed by Vadoo's own Privacy Policy and Terms of Service. We are not responsible for Vadoo's data practices or any issues arising from Vadoo's services. We only share the minimum data necessary for video generation.
5.3 Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- With TikTok: We share necessary information with TikTok's API to provide the Service, as required by TikTok's API Terms of Use. This includes video files, captions, and publication settings.
- With Vadoo: We share your text prompts and generation parameters with Vadoo's API to generate videos. Vadoo's use of this data is subject to Vadoo's Privacy Policy and Terms of Service.
- Service Providers: We may share information with third-party service providers who assist us in operating the Service (e.g., hosting providers, cloud storage providers). These providers are contractually obligated to protect your data and use it only for service provision.
- Legal Requirements: We may disclose information if required by law, court order, or government regulation, or in response to valid legal requests from law enforcement.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
- Protection of Rights: We may disclose information to protect our rights, property, or safety, or that of our users or others, including to prevent fraud or abuse.
5.4 Third-Party Services
Our Service uses third-party services for:
- Vadoo: AI video generation service for text-to-video functionality
- TikTok: Video publishing and analytics via TikTok's official API
- Cloud Hosting: Infrastructure and hosting providers for our Service
- Database Management: Database and storage providers
- Security Monitoring: Security monitoring and threat detection services
All third-party service providers are carefully selected and required to maintain appropriate security and privacy standards. We do not share your data with third parties for marketing or advertising purposes. Each third-party service provider's use of your data is subject to their own Privacy Policy and Terms of Service.
6. Your Rights and Choices
You have the following rights regarding your personal information, which you can exercise at any time:
6.1 Right to Access
You can access your account information, including:
- Your TikTok account information (display name, avatar) through the Service dashboard
- Your video upload history, generation history, and status
- Your AI-generated videos and generation parameters
- Your caption templates and their configurations
- Your scheduled uploads and generation schedules
- Your video performance metrics and analytics
- Your account generation configurations
- Your activity logs and account health data
- Your account settings and preferences
You can request a copy of all personal data we hold about you by contacting us at support@janex.md.
6.2 Right to Deletion
You can delete your data at any time:
- Video Content: Delete individual videos (uploaded or AI-generated) or all videos through the Service dashboard
- Caption Templates: Delete individual templates or all templates through the Service dashboard
- Generation Configurations: Delete or disable automated generation configurations
- Scheduled Operations: Cancel scheduled uploads and generations
- Account Data: Request complete account deletion by contacting us
- Automatic Deletion: Videos (uploaded and AI-generated) are automatically deleted after successful publication to TikTok
Upon deletion request, we will delete your data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements). Some data may be retained according to the retention periods specified in Section 9.
6.3 Right to Revoke Access
You can revoke our access to your TikTok account at any time:
- Through your TikTok account settings (Settings → Privacy → Connected Apps)
- By disconnecting your account through our Service dashboard
- By contacting us to request disconnection
Upon revocation, we will immediately stop making API calls on your behalf and delete stored tokens. Videos already published to TikTok will remain on TikTok's platform.
6.4 Right to Data Portability
You can request a copy of your data in a structured, machine-readable format. Contact us at support@janex.md to request your data export.
6.5 Right to Rectification
You can update your account information through the Service dashboard. If you need to correct inaccurate data, please contact us.
6.6 Right to Object
You can object to certain processing of your data. However, note that most data processing is necessary for Service provision. Contact us to discuss your concerns.
6.7 Exercising Your Rights
To exercise any of these rights, please contact us at support@janex.md. We will respond to your request within 30 days. We may require verification of your identity before processing certain requests.
7. Data Processing and Storage
7.1 Data Storage Location
Your data is stored on secure servers. The specific location may vary depending on our hosting infrastructure, but we ensure that all data storage complies with applicable data protection laws. By using the Service, you consent to the transfer and storage of your data in these locations.
7.2 Data Processing
We process your data for the following purposes and legal bases:
- Service Provision: Processing necessary to provide the Service you requested (contractual necessity)
- API Operations: Processing required to upload videos and interact with TikTok's API (contractual necessity)
- Security: Processing to ensure Service security and prevent fraud (legitimate interest)
- Service Improvement: Processing to analyze usage and improve the Service (legitimate interest)
- Legal Compliance: Processing required to comply with legal obligations
7.3 Backup and Recovery
We maintain regular backups of our systems for disaster recovery purposes. Backups may contain copies of your data and are retained according to our retention policy. Backups are encrypted and stored securely.
8. Cookies and Tracking
We use session cookies to maintain your authentication state. These cookies are essential for the Service to function and are automatically deleted when you close your browser. We do not use tracking cookies or third-party analytics without your consent.
8.1 Types of Cookies
- Session Cookies: Temporary cookies that expire when you close your browser, used to maintain your login session
- Security Cookies: Used to verify your identity and prevent unauthorized access
You can control cookies through your browser settings, but disabling cookies may affect Service functionality.
9. Data Retention
We retain your information only for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
9.1 Retention Periods
- Account Information: Retained while your account is active and for 30 days after account deletion
- Access Tokens: Retained while your account is connected, automatically deleted upon disconnection
- Video Files (Uploaded): Retained until successfully published to TikTok, then automatically deleted within 24 hours
- AI-Generated Video Files: Retained until successfully published to TikTok or deleted by you, then automatically deleted within 24 hours
- Video Generation Data: Text prompts, parameters, and generation status retained for 90 days after generation completion
- Caption Templates: Retained while your account is active, deleted within 30 days after account deletion
- Scheduled Upload Times: Retained until upload is completed or cancelled, then deleted within 30 days
- Video Performance Metrics: Retained while your account is active, synced periodically from TikTok's API
- Account Generation Configurations: Retained while your account is active, deleted within 30 days after account deletion
- Account Health Data: Retained for 90 days for troubleshooting and service improvement
- Activity Logs: Retained for 90 days for security, troubleshooting, and service improvement
- Upload History: Retained for 90 days after upload completion for troubleshooting purposes
- Generation History: Retained for 90 days after generation completion for troubleshooting purposes
- User Preferences: Retained while your account is active, deleted within 30 days after account deletion
- Error Logs: Retained for 30 days for service improvement
9.2 Deletion Procedures
When you delete your account or content:
- Video files (uploaded and AI-generated) are immediately removed from our servers
- Access tokens are revoked and deleted
- Caption templates are deleted
- Generation configurations are deleted
- Scheduled uploads and generations are cancelled
- Account information is deleted within 30 days
- Activity logs and performance metrics are deleted according to retention periods
- Backup copies are deleted within 90 days
9.3 Exceptions
We may retain certain data longer if:
- Required by law or legal process
- Necessary to resolve disputes or enforce agreements
- Necessary for legitimate business interests (e.g., fraud prevention, security)
- Necessary for troubleshooting ongoing issues or service improvements
In such cases, data will be retained only for the minimum period necessary and will be deleted as soon as legally permissible.
10. Children's Privacy
Our Service is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using the Service, you consent to the transfer of your information to these countries.
12. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Investigate the breach immediately and take steps to contain it
- Notify affected users within 72 hours of becoming aware of the breach, where feasible
- Notify relevant data protection authorities as required by applicable law
- Provide information about the nature of the breach and steps taken to address it
- Recommend steps you can take to protect yourself
Notifications will be sent to the email address associated with your account or through the Service dashboard.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Updating the "Last updated" date at the top of this page
- Providing notice through the Service dashboard
- Sending an email notification for significant changes
Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Service and may delete your account.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: support@janex.md
For data protection inquiries, data subject requests, or to exercise your privacy rights, please contact us at the same email address. We will respond to your inquiry within 30 days.
13.1 Data Protection Officer
For users in the European Economic Area (EEA), you have the right to lodge a complaint with your local data protection authority if you believe we have not adequately addressed your privacy concerns.