Privacy Policy
This policy describes how ScrollShow (https://scrollshow.io) processes your data when you use the site and creator workspace.
1. Controller
Publisher: ScrollShow
Contact: hello@scrollshow.io
Site: scrollshow.io
2. Data we collect
- Account: email, first name, hashed password, HTTP-only session cookie.
- Library / studio: drafts, media you add, scheduled dates.
- TikTok (only if you click “Continue with TikTok”): see section 3.
3. Login Kit and Content Posting
When you connect TikTok, you authorize ScrollShow via official Login Kit. Depending on approved scopes, we process:
- Identity (
user.info.basic/user.info.profile): open_id, avatar, display name, username, bio, profile link. - Stats (
user.info.stats): followers, following, likes, video count. - Post list (
video.list): public metadata and metrics (views, likes, comments, shares). - Publishing (
video.upload/video.publish): sending a photo carousel to the connected account, only after you click Publish. - OAuth tokens: access_token / refresh_token stored server-side, never sent to the browser. No TikTok password.
Purposes: show your profile and stats, list your posts, publish on your request. We do not sell TikTok data. Disconnect / revoke from Settings. Redirect: https://scrollshow.io/tiktok/callback.
4. Location
ScrollShow does not collect GPS location.
5. Retention and rights
Account data is kept while the account exists. TikTok tokens are deleted on disconnect. For access, correction, or deletion: hello@scrollshow.io.
6. Sharing
No sale of data. Hosted on Vercel. TikTok receives only the API calls you trigger (connect, read, publish).