Legal
Privacy Policy
Effective date: 12 August 2026
This Privacy Policy explains how PrayPages ("we", "us", "our") collects, uses, stores, and shares information when you use PrayPages Console (the "Service"), including when the Service connects to TikTok via TikTok for Developers products (Login Kit and the Content Posting API).
Effective date: 12 August 2026. Contact: praypages@gmail.com.
1. Who this policy covers
This policy applies to (a) authorized administrators who sign in to the Service, (b) TikTok account holders who authorize the Service to access their TikTok account, and (c) visitors who view our public website pages (including this Privacy Policy and our Terms of Service).
The Service is not directed to children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children.
2. Information we collect
Account & authentication data. Administrator email addresses used to sign in; session cookies required to keep an admin signed in.
TikTok authorization data. When an operator connects TikTok, we receive and store OAuth tokens (access token, refresh token), open_id, granted scopes, token expiry times, and basic profile fields TikTok returns under user.info.basic (such as display name / avatar URL when provided). We use these solely to call TikTok APIs on that operator's behalf.
Publishing & content data. Story metadata imported from allowlisted charity sources (for example names, ages, medical need descriptions, photo URLs, and source page URLs already published by those charities); operator-edited captions, prayers, hashtags, approval decisions, republishing-permission flags, schedule times, publish status, TikTok publish/post identifiers, and audit logs of admin actions.
Technical data. Server logs (timestamps, request paths, error messages), and operational configuration needed to run the Service (for example storage paths and API credentials held as server environment variables).
We do not sell personal data. We do not sell, rent, or trade personal information.
3. How we use information
- Operate the review queue and human-approval workflow before any TikTok post.
- Authenticate administrators and enforce access control to the console.
- Connect to TikTok, query creator info, publish photo posts (or inbox drafts), poll publish status, and list existing posts to reduce duplicate prayers.
- Store media needed for TikTok PULL_FROM_URL publishing on our servers.
- Maintain security, audit trails, debugging, and abuse prevention.
- Comply with law and TikTok platform requirements.
4. TikTok data & developer obligations
TikTok data obtained through TikTok APIs is used only to provide the features the operator authorized (publishing and related creator/post checks). We do not use TikTok data to build unrelated advertising profiles, and we do not disclose TikTok user data to unrelated third parties except as required to operate the Service infrastructure or as required by law.
Operators remain responsible for complying with TikTok's Terms of Service, Community Guidelines, Content Sharing Guidelines, Music Usage Confirmation, and Branded Content Policy when content is posted to TikTok.
Scopes we may request include user.info.basic, video.publish, video.upload, and video.list. Operators can revoke access at any time in TikTok's account settings and/or by disconnecting TikTok inside the Service.
5. Charity / beneficiary content
Stories and photographs concern real medical beneficiaries and are sourced from pages the charities have already made public. We process this content to enable human review and authorized republishing. Operators must confirm they have rights to republish before approval. We do not scrape non-allowlisted websites.
6. Processors & subprocessors
We use service providers that process data only to host or operate the Service, such as:
- Cloud hosting and object/volume storage for the application, database, and media.
- TikTok (as an independent controller/processor of posts on its platform).
- Optional AI providers (for example Gemini) when configured, used to draft captions, prayers, or hashtags from story context supplied by the operator/workflow.
- Optional web-fetch assist providers (for example ScrapingBee) used only against allowlisted charity domains when direct fetches are blocked by bot protection.
These providers process data under their own terms and only as needed for the functions above.
7. Cookies & local storage
We use essential session cookies (or equivalent) to keep administrators signed in. We do not use third-party advertising cookies on the public website.
8. Retention
We retain account, story, media, token, and audit data for as long as needed to operate the Service, fulfill publishing history, resolve disputes, and meet legal obligations. TikTok tokens are refreshed while a connection remains active and are deleted or invalidated when an operator disconnects TikTok or when tokens expire and cannot be refreshed. Operators may request deletion of Service-stored data by contacting us.
9. Security
We apply administrative and technical measures appropriate to the Service, including HTTPS in production, server-side storage of secrets and tokens (never exposed to the browser), admin authentication, and host allowlists for outbound fetches. No method of transmission or storage is 100% secure.
10. International transfers
The Service may be hosted in data centers outside your country. By using the Service you understand that information may be processed in the United States or other locations where our providers operate.
11. Your rights & choices
- Disconnect TikTok from the Service to stop further API access with stored tokens.
- Revoke the app in TikTok's connected-apps settings.
- Request access, correction, or deletion of personal data we hold about you by emailing praypages@gmail.com.
- Stop using the Service and ask us to close an administrator account.
If you are in the EEA/UK, you may also have rights to object to processing, restrict processing, or lodge a complaint with a supervisory authority.
12. Changes
We may update this Privacy Policy. The "Effective date" at the top will change when we do. Continued use of the Service after an update constitutes acceptance of the revised policy where permitted by law.
13. Contact
PrayPages
Email: praypages@gmail.com
