Privacy
Privacy Policy
Last updated: August 25, 2026
1. Scope
This Privacy Policy explains how Wesley handles information when an authorized creator uses the desktop application or visits the Wesley website.
2. Information processed
- TikTok authorization data: access token, refresh token, authorized scopes, token expiry, and TikTok Open ID.
- Creator profile data: display name, username, avatar URL, current privacy options, interaction permissions, and maximum posting duration returned by TikTok.
- Creator-selected media: one local video selected for upload, its file name, size, media type, and SHA-256 checksum.
- Post metadata: caption, hashtags, privacy level, comment/Duet/Stitch settings, commercial content status, AI-generated content disclosure, publish ID, status, and public post ID when TikTok returns one.
- Technical data: local application status and security events needed to diagnose an operation. The review build does not include advertising or behavioral analytics.
3. How information is used
Information is used only to authenticate the creator, display current TikTok posting choices, validate the creator's selected settings, transfer the selected video to TikTok, retrieve publication status, prevent duplicate posting, and support security or troubleshooting.
4. Sharing
Wesley sends creator-authorized account data, video bytes, and post metadata to TikTok through TikTok's official APIs. We do not sell personal data and do not share it with advertising networks. TikTok processes information under its own terms and privacy policies.
5. Retention
In the review build, OAuth tokens are stored only in server memory and are removed when the application stops or the creator disconnects. A temporary local copy of a selected video is deleted after transfer or disconnect. Publication identifiers and redacted operational evidence may be retained locally when the creator requests an audit trail. Public TikTok posts remain subject to the creator's TikTok settings and TikTok's retention practices.
6. Security
Wesley binds its local service to the loopback interface, uses OAuth state and Desktop PKCE, keeps Client Secrets and refresh tokens outside browser JavaScript, redacts credentials from logs, restricts request sizes, and requires explicit consent immediately before transmission.
7. Creator choices
Creators may deny requested scopes, cancel before upload, disconnect the application, revoke TikTok access, change TikTok privacy settings, or remove published content through TikTok. To request access to or deletion of any locally retained support record, contact us.
8. Children's privacy
Wesley is not directed to children and must not be used by anyone who is not eligible to use TikTok or to enter a binding agreement in their jurisdiction.
9. International processing
TikTok and its service providers may process information in multiple countries. TikTok's own privacy terms govern its processing. Wesley minimizes local data and does not add independent cross-border analytics services.
10. Changes and contact
Material changes will be posted here with a revised date. Privacy questions or rights requests may be sent to lihuixx78@gmail.com.