Effective date: 2026-09-27
Controller: BrunoRozendo LTDA ("we", "us")
Contact: [email protected]
This notice describes how u10x-postiz — the TikTok integration of our self-hosted Postiz publishing dashboard at https://postiz.brunorozendo.dev — receives, uses and stores information from TikTok. The application is used only by our own team to publish content to TikTok accounts owned by BrunoRozendo LTDA (brands Anotadíssimo, Notebook Barato Online and U10X). It is not offered to the public.
1. What we receive from TikTok
We receive data exclusively through TikTok's official APIs, and only for TikTok accounts we own and connect ourselves.
| When | What arrives |
|---|---|
| An operator connects one of our TikTok accounts (Login Kit) | The account's app-specific ID (open_id), display name, username and avatar; an access token and a refresh token; the permissions granted |
| Before each post (Content Posting API) | The account's current posting options: allowed privacy levels, whether comments, duets and stitches are allowed, maximum video length |
| After each post | The publish ID TikTok assigns and the processing/publishing status |
| When an operator opens the analytics screen | Aggregate counts for our own account (followers, following, likes, videos) and, for our own public videos, their ID, cover image, title and view/like/comment/share counts |
We do not receive or process data about other TikTok users — no follower lists, viewers, comments or messages.
2. What we use it for
- Showing the connected account in our publishing dashboard.
- Publishing the posts our team schedules, with the privacy and interaction settings the operator chose.
- Showing whether each post was published or failed.
- Showing our own accounts' performance in the dashboard's analytics screen.
We do not sell, rent or share this data. We do not use it for advertising, profiling, or training machine-learning models.
3. Content we send to TikTok
The videos and photos we publish are authored by us and stored on our server. Videos are uploaded by our server directly to TikTok; photos are fetched by TikTok from https://postiz.brunorozendo.dev/uploads/ when a post is sent.
4. Sub-processors
| Who | What they receive | Why |
|---|---|---|
| Cloudflare | Request metadata (source IP, headers) | Network tunnel and infrastructure protection |
| TikTok | The posts we publish | Operation of the platform itself |
The application is self-hosted on our own server in Brazil; there is no other processor.
5. Where the data lives and how long we keep it
On our own server in Brazil, in a PostgreSQL database. Traffic is protected with TLS and dashboard access is restricted to our team.
| Data | Retention |
|---|---|
| Connected-account profile and tokens | While the account stays connected; tokens until they expire or are revoked |
| Post history (publish IDs and status) | As our internal publishing record, until deleted by an operator |
| After an account is disconnected or deletion is requested | Erased within 30 days |
6. Revoking access and your rights
The owner of a connected TikTok account can revoke our access at any time in the TikTok app: Settings and privacy → Security & permissions → Apps and services, then remove u10x-postiz.
Under the LGPD you may request confirmation of processing, access, correction, portability and deletion of your data. Write to [email protected] with the subject "Data deletion request — u10x-postiz"; we respond within 30 days.
7. Incidents
In the event of unauthorised access affecting personal data, we notify TikTok, the ANPD and the affected people within 72 hours of becoming aware.
8. Children
The application is not directed at anyone under 13 and does not collect data from end users.
9. Changes to this policy
Material changes take effect on the effective date shown at the top of this page.
10. Controller
BrunoRozendo LTDA — Brazil
Data officer: Bruno Rozendo
[email protected]