Minimal TikTok access
Loopcraft requests user.info.basic to identify the connected creator and video.publish to send only videos the creator explicitly approves.
Trust
Loopcraft limits what it asks from TikTok, protects the authorization data required to operate the service and gives creators direct ways to disconnect or delete their information.
Loopcraft requests user.info.basic to identify the connected creator and video.publish to send only videos the creator explicitly approves.
Authentication happens on TikTok. Loopcraft receives OAuth tokens, never the creator's TikTok password.
OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. Browser sessions use random opaque values whose SHA-256 hashes are stored server-side.
Accounts, media, publishing settings and post records are tied to the authenticated creator space.
The public service and provider callbacks use HTTPS/TLS. Provider media access is limited to controlled publishing URLs.
Creators can disconnect TikTok or permanently delete their Loopcraft account, tokens, posts, uploaded videos and preview images.
Detailed policies