FIRST PASS LABS

Privacy Policy

First Pass Labs · Effective August 9, 2026

This policy explains what information the First Pass Labs application accesses, why it accesses it, and how that information is handled. It applies to the software operated at firstpasslabs.com and to its use of the TikTok Content Posting API.

Who operates this application

First Pass Labs is the name used by an individual operating this software in the United States. There is no company, no staff, and no third party involved in running it.

Scope: this application has no public users

This is important context for everything below. The application is private tooling. It is not offered to the public, there is no signup, and no one other than the operator can authorize it or use it.

Its only function is to publish video content to TikTok accounts that the operator personally owns and controls. It does not process data belonging to any other person, and it is not designed or licensed to do so.

What information the application accesses

When the operator connects one of their own TikTok accounts, the application receives and stores:

The application does not access private messages, follower lists, viewer information, analytics about other users, or any personal data belonging to people who view the published content.

How that information is used

Solely to publish the operator's own content to the operator's own TikTok accounts, and to confirm that each publish succeeded. There is no other use.

Information is never sold, rented, shared, licensed, or transferred to any third party. It is not used for advertising, profiling, training machine learning models, or analytics of any kind.

How it is stored

Tokens are held in encrypted credential storage, not in source code, configuration files, or version control. They are transmitted only to TikTok's own API endpoints, over HTTPS. Video files are stored locally on the operator's hardware until upload completes.

How long it is kept

Tokens are retained only while the corresponding TikTok account is actively connected. When an account is disconnected, its tokens are deleted from storage. Expired refresh tokens are discarded rather than renewed.

Access can be revoked at any time from TikTok's own account settings, under connected apps. Revoking access there immediately invalidates the tokens held by this application.

Third parties

The application communicates with TikTok's API and with no other external service. There are no analytics providers, no advertising networks, no data brokers, and no subprocessors. Nothing about the operator's activity is reported anywhere.

Children's privacy

This application is not directed to children, does not knowingly collect information from anyone under 13, and has no public users from whom such information could be collected.

Your rights

Because the application has no users other than its operator, it holds no personal information belonging to anyone else. Any person who believes otherwise, or who has a question about how this software behaves, can write to the address below and will receive a response.

Changes to this policy

If the application's behavior changes, this page will be updated and the effective date at the top revised. Material changes will be described rather than quietly substituted.

Contact

Questions about this policy or about the application can go to jason@firstpasslabs.com.