Privacy Policy
This Privacy Policy explains what information Shorts Factory ("the app") handles and how. Shorts Factory is an independent project developed and operated by Derrick Caluag ("I", "me"). Questions can be sent to derrick.caluag@gmail.com.
1. How the app works
Shorts Factory is a program that produces short educational videos on my computer. Its Publisher, a password-protected page at eunick.duckdns.org/app/ served from the same computer, lets the connected creator choose a finished video, review it and publish it to TikTok through TikTok's Content Posting API. All processing and storage happens on that computer; there is no third-party hosting of app data.
2. Information received from TikTok
When a TikTok account owner authorizes Shorts Factory through TikTok Login Kit, TikTok's authorization page handles the sign-in. Shorts Factory never receives the TikTok username or password. After authorization, TikTok returns the following to the app:
| Data | Purpose | Stored? |
|---|---|---|
| Access token | Authenticates requests to TikTok's Content Posting API to publish videos. | Yes, locally (see section 4). |
| Refresh token | Gets a new access token when the current one expires, so the owner doesn't have to re-authorize every day. | Yes, locally. |
| Open ID (TikTok's app-specific account identifier) | Shown once on screen after authorization to confirm which account was connected. | No. |
| Token expiry time and granted scopes | Part of TikTok's standard token response. | No. |
| Creator info: display name, username, profile photo URL, available privacy options, whether comments/Duet/Stitch are turned off, maximum video length | Requested from TikTok when the Publisher is opened and again just before each post, to show which account the video will be posted to and to offer only the settings TikTok allows. | No. Displayed on the Publisher page only. |
When a video is published, TikTok returns a publish ID and a publishing status (for example, "complete" or a failure reason). The app records the publish ID, status and time in local log files so the same video is not uploaded twice and failures can be retried.
TikTok data the app does not access
Shorts Factory requests only the video.publish permission. Apart from the creator info listed above, it does not request or access the account's follower or following lists, direct messages, comments, likes, watch history, analytics, or existing videos.
3. Information sent to TikTok
When a video is published, the app sends TikTok:
- the video file produced by Shorts Factory;
- the caption and hashtags written for that video;
- the post settings the creator selected: who can view the post; whether comments, Duet and Stitch are allowed; any commercial content disclosure; and whether the video is labeled as AI-generated.
TikTok's handling of this content is governed by TikTok's own Terms of Service and Privacy Policy.
4. Where data is stored and how it is protected
- TikTok access and refresh tokens, and the app's TikTok client credentials, are stored in a configuration file on the local computer that runs Shorts Factory. This file is not uploaded to any website, repository or cloud service.
- Upload logs (video name, platform, date and time, result, publish ID) are stored as local files on the same computer.
- Communication with TikTok uses HTTPS.
- The computer is protected by the operating system's user account controls. No method of storage is perfectly secure, but TikTok data is never stored on a server or shared.
5. How data is used
Data received from TikTok is used only to publish videos to the account that authorized the app and to check whether publishing succeeded. It is not used for advertising, profiling, analytics or any other purpose.
6. Sharing and selling
I do not sell, rent or share TikTok data or tokens with anyone. TikTok data is not sent to any service other than TikTok.
Shorts Factory can also publish the same videos to YouTube, Instagram and Facebook using those platforms' own separate authorizations. TikTok tokens and TikTok data are never sent to those platforms, and data from those platforms is never sent to TikTok.
7. Other information
- No user accounts. Shorts Factory has no sign-up, login system or user database of its own.
- No cookies or analytics. Neither the app nor this website sets cookies or uses analytics or tracking tools.
- Video content. Scripts, narration and visuals are generated by AI models running on the local computer. They are not made from personal information.
- This website. This site is served from a web server I operate at eunick.duckdns.org. The server is not configured to keep access logs, and the site does not set cookies or use analytics. A mirror copy is also hosted on GitHub Pages; if you visit that copy, GitHub may collect technical information such as IP addresses, as described in GitHub's own privacy statement. I do not receive or use that information.
8. Retention and deletion
- Tokens are kept until the TikTok connection is revoked, the tokens are replaced by a new authorization, or they are deleted from the local configuration file. Once revoked in TikTok, stored tokens no longer work.
- Upload logs are kept locally until deleted, so that videos are not uploaded twice.
- To delete TikTok tokens and upload records related to your account, email derrick.caluag@gmail.com. I will delete them and confirm within 30 days.
9. Your choices and rights
- Revoke access: click Disconnect in the Publisher to revoke Shorts Factory's access with TikTok and delete the stored tokens immediately, or remove the app from the apps and services connected to your account in TikTok's settings. The app will then stop being able to post to your account.
- Access or deletion: you can ask what data related to your TikTok account the app holds, or ask for it to be deleted, by emailing me.
- Depending on where you live, you may have additional rights under local data protection laws. Contact me to exercise them.
10. Children
Shorts Factory is not directed at children and does not knowingly process data from anyone under the minimum age required to hold a TikTok account.
11. Changes to this policy
If the way Shorts Factory handles data changes, I will update this page and its effective date before the change takes effect. If the app starts requesting additional TikTok permissions, this policy will be updated to describe them first.
12. Contact
Derrick Caluag
Email: derrick.caluag@gmail.com