Privacy Policy

Last updated: October 3, 2026

Content Distributor is self-hosted, open-source software for preparing, scheduling, and publishing content to social platforms. This policy describes how the application handles data when you run your own instance. If a third party operates an instance for you, that operator is also responsible for its own data-handling practices.

TikTok application identity

Xingyu Studio is the registered TikTok application used by Content Distributor. These policies cover that integration as well as the Content Distributor workspace; the separate names do not indicate separate permission grants or production approval.

Data we collect

When you register an account, we store your name, email address, and a hashed password. We do not store your plain-text password at any point.

When you connect a social media account via OAuth, we store the platform's access token and (where applicable) refresh token. These tokens are encrypted at rest using AES-256-GCM before being written to the database. The encryption key never leaves your server environment.

When you create or schedule posts, we store the post content, scheduled time, target platforms, and publish status. Any media files you upload are stored in the configured S3-compatible object storage (MinIO by default) on your own infrastructure.

How we use your data

Data is used exclusively to provide the functionality of the application — authenticating you, publishing posts on your behalf, and showing you the status of past and upcoming posts. We do not sell personal data. We transmit content and account identifiers only to the platform APIs and storage services you explicitly configure and authorize, including Instagram, Facebook, TikTok, YouTube, LinkedIn, and X.

OAuth tokens and platform APIs

Connecting a social media account requires you to grant permission through that platform's authorization flow. The application requests only the scopes needed for the selected features. Tokens are stored encrypted and decrypted only when the application must call the authorized platform API. You may revoke platform access at any time from the connected-accounts page or from the platform's own app-permissions settings.

Google and YouTube data

Google's handling of information is described in the Google Privacy Policy.

Content Distributor uses YouTube API Services. It reads your authorized channel identifier and display information to show the publishing destination, sends the video and the title, description, and privacy setting you choose when you confirm an upload, and reads the resulting video identifier and processing status to report delivery. The operator and its configured database, private media storage, and hosting providers process this information only to operate your selected workflow. We do not sell Google user data or share it with advertisers or data brokers.

For YouTube, Content Distributor requests only permission to view the authorized channel identity and to manage videos for that channel. Channel identifiers and display information are used to show the selected destination account. Video-management access is used only when you explicitly submit a video or request its current delivery status. Google user data is not used for advertising, data brokerage, credit decisions, or AI-model training.

TikTok data and publishing choices

Xingyu Studio requests basic profile access to display the creator's identity, Direct Post access to submit content after explicit confirmation, and upload access to deliver content to TikTok's inbox for the creator to finish in TikTok. Profile identifiers, display information, authorization tokens, selected media, captions, privacy and interaction choices, music-use confirmations, commercial disclosures, and delivery identifiers are processed only for the selected workflow. An inbox delivery is not a published video. Sandbox availability does not mean production access has been approved.

Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

Self-hosting note

Because Content Distributor is self-hosted, the operator of the instance (you, or whoever deployed it) has full access to the underlying database, object storage, and server logs. If you are using an instance you did not set up yourself, trust that operator accordingly.

Data retention and deletion

Disconnecting a YouTube account removes its active authorization credentials. You can independently revoke access in Google Account security settings or Google Account connections. Revocation stops future API access but does not erase saved workspace history or videos already uploaded to YouTube. Use the documented data deletion request process for stored workspace records.

Data is retained until you delete it or the instance operator applies a documented retention policy. You can disconnect an authorized platform account to remove its stored credentials. Complete application-account deletion currently requires the installation operator to remove associated database records, media objects, and configured backups. See the public Data Deletion page for request instructions.

Cookies and sessions

We use HTTP-only session cookies for authentication. No tracking cookies, analytics scripts, or third-party pixels are used by the application. The hosting service also receives standard request data, including IP address and browser user agent, for service operation and security.

The YouTube demonstration page embeds a YouTube player. When that player loads, basic browser data is shared with YouTube to show the video and check playability; playing the video can share additional data. Google describes its handling of this information in the Google Privacy Policy linked above.

Contact

Questions about this privacy policy or data handling can be directed to huhuwen09@gmail.com.