Privacy Policy
Effective date: August 2, 2026 · Last updated: August 2, 2026
This Privacy Policy explains how Hughes IT, LLC (“Hughes IT,” “we,” “us,” or “our”) handles information in connection with AutoPost (the “Service”), an internal content scheduling and analytics application.
AutoPost is a private, internal-use tool. It is used only with TikTok accounts owned and operated by Hughes IT, LLC. It has no public signup, it does not collect data from members of the public, and it does not sell, rent, or share personal information with third parties for their own purposes.
1. Information we collect
a. TikTok account data (via TikTok's official APIs)
When a TikTok account is connected through TikTok's OAuth consent flow, the Service may access the following, limited to the scopes approved on that consent screen:
| Data | Why it is accessed |
|---|---|
| OAuth access and refresh tokens | To authenticate API calls on behalf of the connected account without storing a TikTok password. |
| Basic profile information (open ID, display name, avatar URL, username) | To identify which connected account a scheduled post or metric belongs to. |
| Video list and video metadata (video ID, title/caption, cover image, creation time, privacy setting) | To match published posts back to the items scheduled in the Service. |
| Video performance metrics (views, likes, comments, shares) | To report how published content performed so posting decisions can be compared over time. |
| Publishing status responses | To confirm whether an upload succeeded, and to surface an error if it did not. |
We do not access TikTok direct messages, follower contact details, payment information, or any account not owned by Hughes IT, LLC.
b. Content submitted for publishing
Video files, captions, hashtags, scheduling times, and related settings that are entered into the Service in order to be published.
c. Operational data
Application and web server logs, which may include IP address, timestamp, request path, user agent, and error details. These are generated in the normal course of running the Service and are used for security and troubleshooting.
2. How we use information
- To schedule and publish content to the connected TikTok accounts.
- To retrieve and display performance metrics for that published content.
- To maintain an internal record of what was published and when.
- To diagnose errors, maintain security, and keep the Service running.
- To comply with legal obligations and with TikTok's developer terms and policies.
We do not use this information for advertising or profiling, we do not sell or rent it, and we do not use it to train machine learning or AI models.
3. Legal basis
Where the EU/UK GDPR applies, we process this information on the basis of consent (given through TikTok's authorization screen, and withdrawable at any time) and our legitimate interest in operating and securing an internal business tool.
4. How information is shared
We share information only as follows:
- TikTok — content and API requests are transmitted to TikTok in order to publish and retrieve data. TikTok's handling of that data is governed by TikTok's Privacy Policy.
- Infrastructure providers — the servers and services that host the Service, acting on our instructions.
- Legal requirements — where disclosure is required by law, regulation, or valid legal process, or to protect our rights, safety, or property.
We do not otherwise disclose information to third parties.
5. Storage and security
Data is stored on servers operated by or for Hughes IT, LLC in the United States. Access tokens are stored in encrypted form, access to the Service and its data is restricted to authorized Hughes IT personnel, and all traffic to this site and to TikTok's APIs is transmitted over TLS. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
6. Retention
- Access and refresh tokens — kept only while the account remains connected; deleted when authorization is revoked or the connection is removed.
- Profile, video, and metric data — retained while needed for reporting, and deleted within 30 days of an account being disconnected.
- Submitted video files — deleted after the post is successfully published or the scheduled item is cancelled.
- Server logs — retained for up to 90 days, then rotated out.
7. Revoking access and deleting data
Authorization can be withdrawn at any time from TikTok, under Settings and privacy → Security and permissions → Manage app permissions. Revoking access immediately ends the Service's ability to read from or post to that account.
To request deletion of data already held by the Service, email blake@hughesit.us. We will action verified requests within 30 days.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to withdraw consent, and to object to or restrict certain processing. We do not discriminate against anyone for exercising these rights. Requests can be sent to blake@hughesit.us.
9. Children
The Service is an internal business tool and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn we have done so, we will delete it.
10. International users
The Service is operated from the United States. If you access it from elsewhere, your information will be transferred to and processed in the United States, where data protection law may differ from that of your jurisdiction.
11. Changes to this policy
We may update this Privacy Policy from time to time. The revised version will be posted on this page with an updated “Last updated” date, and material changes will be communicated to authorized users of the Service.
12. Contact
Hughes IT, LLC
Email: blake@hughesit.us
Web: hughesit.us