1. Scope
Effective August 13, 2026, this Privacy Policy applies to the public SİNYAL website and the SİNYAL desktop application. The website is a public documentation site. It does not provide a public SİNYAL account, TikTok connection form, media uploader, or access to the desktop Control Center.
2. Information associated with this website
SİNYAL does not add analytics, advertising trackers, contact forms, or application cookies to this static website. GitHub Pages and the network providers that deliver the site may process routine technical data such as IP address, browser type, device information, requested URL, referrer, timestamp, and security logs under their own policies. SİNYAL does not receive TikTok credentials through this website.
3. TikTok OAuth and account identity
When a creator authorizes SİNYAL through TikTok Login Kit, TikTok returns information associated with the permissions the creator grants. For the current workflow, this may include the account's TikTok identifiers, display name, avatar URL, granted scopes, token type, and authorization expiry information. SİNYAL uses user.info.basic to confirm the identity of the connected authorized account.
4. Tokens and credentials
The desktop application receives and stores the access token and, when provided by TikTok, the refresh token needed to maintain the authorized connection. TikTok client credentials are stored separately in the operator's local application environment. These values are not included in the public website or public source repository and are not intended to be displayed in application logs or public support channels.
5. Local media and content metadata
SİNYAL may process the local media file deliberately selected by the operator, together with its file name, size, caption, privacy selection, creator posting options, queue status, and related workflow metadata. The source file remains in the operator-controlled environment unless the operator confirms a TikTok action. For Direct Post, the selected media and required posting data are then transmitted to TikTok.
6. Publishing and operational records
To perform and troubleshoot an operator-confirmed publishing action, SİNYAL may record the TikTok publish identifier, response status, timestamps, selected settings, validation results, and error details. Upload URLs and credentials are not intended for public display. These records support status checking, duplicate-action protection, and operational troubleshooting.
7. How information is used
SİNYAL uses the information described above to:
- establish, validate, and maintain an authorized TikTok connection;
- show the operator which creator account is connected;
- retrieve creator posting options required before Direct Post;
- prepare, validate, and perform a publishing action confirmed by the operator;
- check the status and outcome of that action;
- protect against invalid, duplicate, or unauthorized workflow actions; and
- maintain, secure, and troubleshoot the desktop application.
8. Third-party services and disclosure
TikTok receives the authorization, account, media, and posting data needed to provide Login Kit and Content Posting API functions. GitHub Pages and network providers process routine website request data needed to deliver and secure this site. SİNYAL does not sell personal data, share it for cross-context behavioral advertising, or disclose TikTok integration data to unrelated public users. Information may also be disclosed when required by applicable law or necessary to protect rights, safety, and security.
9. Storage and retention
TikTok tokens, OAuth session records, content metadata, and operational logs are stored in the operator's local SİNYAL environment, not on this public website. Tokens may be retained while the account remains connected or until they expire, are revoked, or are deleted. OAuth sessions and operational records are retained only as long as reasonably needed for authorization integrity, workflow history, duplicate-action protection, troubleshooting, security, or legal obligations, then may be deleted or anonymized. Local media retention is controlled by the operator's content archive.
10. Security
SİNYAL separates the public documentation website from the desktop application and keeps credentials out of the public repository. The desktop OAuth flow uses a local loopback redirect, an anti-forgery state value, and PKCE session data. Access to the local environment should be restricted to authorized operators, and the host device, backups, and credentials should be protected appropriately. No method of storage or transmission can be guaranteed completely secure.
11. Authorization choices, revocation, and deletion
The creator chooses whether to grant the permissions shown by TikTok and may revoke SİNYAL's access through TikTok's account settings. A request to disconnect an account or delete corresponding local SİNYAL authorization and operational records can be made through the Contact page. The request should identify the relevant authorized account without including tokens, secrets, or unpublished content in a public message. Some limited records may be retained where required for security, legal compliance, or the establishment or defense of legal claims.
12. Policy changes
This policy may be updated to reflect changes to SİNYAL, TikTok APIs, hosting, security practices, or legal requirements. The effective and last-updated dates identify the current version. Material changes will be published on this page before or when they take effect, as appropriate.
13. Contact
Privacy questions, authorization concerns, and deletion requests can be directed through the SİNYAL Contact page. Use a private contact method for account-specific requests and never include TikTok tokens, client secrets, or unpublished media in a public repository issue.