Trust and security
Protecting connected accounts and content
Clipflow limits access to authorized workspaces and uses connected-platform credentials only to perform actions approved by the account owner.
Credential handling
Clipflow does not ask users to provide their TikTok or other social-platform password. OAuth-enabled platforms issue access and refresh tokens directly. Tokens are stored as operational secrets, are not displayed publicly, and are not sold or used for advertising.
Access control
Workspaces are restricted to authorized administrators. Publishing actions require an approved post and a configured destination. Administrative API access is protected separately from public website pages.
Data minimization
Clipflow processes the media, metadata, identifiers, and credentials needed to deliver the requested publishing workflow. It does not use connected-account information to build advertising profiles.
Transport and infrastructure
Public web traffic is protected with HTTPS. Application, database, queue, and object-storage components are separated by function. Infrastructure providers process data only as needed to host and operate the service.
Media retention
Processed media in object storage is scheduled for automatic deletion after two days. Publication records and platform responses may be retained for reporting, troubleshooting, security, and audit purposes until no longer required or the workspace is deleted.
Reporting a concern
Security or privacy concerns should be sent to anton.sinitsyn.as@gmail.com with the subject "Clipflow Security". Please do not include passwords, access tokens, or other secrets in email.