Privacy Policy
This policy explains what information the First Pass Labs application accesses, why it accesses it, and how that information is handled. It applies to the software operated at firstpasslabs.com and to its use of the TikTok Content Posting API.
Who operates this application
First Pass Labs is the name used by an individual operating this software in the United States. There is no company, no staff, and no third party involved in running it.
Scope: this application has no public users
This is important context for everything below. The application is private tooling. It is not offered to the public, there is no signup, and no one other than the operator can authorize it or use it.
Its only function is to publish video content to TikTok accounts that the operator personally owns and controls. It does not process data belonging to any other person, and it is not designed or licensed to do so.
What information the application accesses
When the operator connects one of their own TikTok accounts, the application receives and stores:
- OAuth access and refresh tokens issued by TikTok, which allow the application to publish on behalf of the connected account.
- Basic account identifiers returned by TikTok, such as the open ID, display name, and avatar URL, used to label which account a post is destined for.
- Creator posting settings returned by TikTok, such as available privacy levels and whether commenting or stitching is permitted, which the application must read in order to submit a valid post.
- Video files and their captions, which are created by the operator and uploaded through the application.
The application does not access private messages, follower lists, viewer information, analytics about other users, or any personal data belonging to people who view the published content.
How that information is used
Solely to publish the operator's own content to the operator's own TikTok accounts, and to confirm that each publish succeeded. There is no other use.
Information is never sold, rented, shared, licensed, or transferred to any third party. It is not used for advertising, profiling, training machine learning models, or analytics of any kind.
How it is stored
Tokens are held in encrypted credential storage, not in source code, configuration files, or version control. They are transmitted only to TikTok's own API endpoints, over HTTPS. Video files are stored locally on the operator's hardware until upload completes.
How long it is kept
Tokens are retained only while the corresponding TikTok account is actively connected. When an account is disconnected, its tokens are deleted from storage. Expired refresh tokens are discarded rather than renewed.
Access can be revoked at any time from TikTok's own account settings, under connected apps. Revoking access there immediately invalidates the tokens held by this application.
Third parties
The application communicates with TikTok's API and with no other external service. There are no analytics providers, no advertising networks, no data brokers, and no subprocessors. Nothing about the operator's activity is reported anywhere.
Children's privacy
This application is not directed to children, does not knowingly collect information from anyone under 13, and has no public users from whom such information could be collected.
Your rights
Because the application has no users other than its operator, it holds no personal information belonging to anyone else. Any person who believes otherwise, or who has a question about how this software behaves, can write to the address below and will receive a response.
Changes to this policy
If the application's behavior changes, this page will be updated and the effective date at the top revised. Material changes will be described rather than quietly substituted.
Contact
Questions about this policy or about the application can go to jason@firstpasslabs.com.