Privacy Policy
Last updated: September 28, 2026
This policy explains what data Stanley's Cross-posting Tool ("the Service") processes, why, and how you control it.
1. Data we collect
- Google sign-in: your email address, name and profile picture (scopes
openid email profile). We do not get access to your YouTube account, Gmail or any other Google data. - YouTube channels you link: the channel's public ID, name and handle. We read your channel's public description only to check the verification code.
- Videos: public metadata (title, description, tags, thumbnail) and the video files of new uploads on your linked channels, used to prepare posts.
- TikTok: when you connect TikTok, we receive an access token, a refresh token, your TikTok open ID,
display name and avatar (scope
user.info.basic). We use thevideo.publishscope only to publish videos you have reviewed and confirmed. When you open a post page we fetch your TikTok nickname and posting options. - Posts and settings: the captions and settings you choose, and the status and IDs of posts.
- Optional: a Discord webhook URL if you want notifications.
- Security logs: sign-ins, connected accounts and posts, and standard web server logs (IP address, time, page).
2. How we use it
Only to provide the Service: to verify channel ownership, prepare your videos, show them to you for review, publish the posts you confirm, show your history and notify you. We do not sell your data, use it for advertising, or share it with anyone except the service providers below and the platforms you connect.
3. Service providers
- Anthropic (Claude API): video titles, descriptions, tags and your channel name are sent to write suggested captions. No account data or tokens are sent.
- Discord: only if you add a webhook — notifications are sent to it.
4. Storage, security and retention
- Data is stored on a virtual server we rent from Contabo. All traffic uses HTTPS. Platform tokens are stored encrypted.
- Video files are deleted once every post for them is finished, skipped or expired — at most 7 days after they were prepared.
- Tokens are deleted when you disconnect an account. Everything is deleted when you delete your account.
- Security logs are kept for up to 12 months.
5. Your rights and choices
You can disconnect accounts and delete your account and all its data yourself on the Account page. You can also revoke our access in TikTok's or Google's own settings. Under the GDPR you have the right to access, correct, export and delete your data and to object to processing; contact us to exercise them. You may also complain to your data protection authority (in Denmark: Datatilsynet).
6. Contact
Privacy questions or requests: stanley.mov@gmail.com.