ForgeOS / legal

Privacy Policy

How this workspace handles TikTok authorization and content-preparation data.

Last updated September 25, 2026

1. Who runs ForgeOS

ForgeOS is operated by the owner of the workspace where the app runs. The operator’s legal name and public privacy-contact address have not been provided for this page. If you received access to the private guide, contact the workspace operator through the channel by which they granted you access for privacy questions.

2. Data involved

  • When an operator configures TikTok, ForgeOS stores a developer-app client key and encrypted client secret.
  • If you authorize a TikTok account, ForgeOS receives an account identifier (open ID), granted scopes including basic user information and, if authorized, video publishing, plus access and refresh tokens and their expiry times. It checks TikTok creator information, including available post privacy levels, to determine private-test readiness.
  • For content preparation it stores the supplied topic, generated hook, script, caption, AI-generated flag, commercial classification, rendered-media references, review state, and, if a post is ever made, publish status and related performance observations.
  • The private guide uses a session cookie to keep the operator signed in. The public pages do not require TikTok authorization or a guide session.

3. What the data is for

ForgeOS uses this data to authenticate the operator, complete TikTok OAuth, refresh authorized tokens, prepare and render videos, show review and account-readiness status, and maintain a record of content decisions. A connected TikTok account is not used to post merely because it was connected. The guide’s posting action is currently disabled. If publishing is later enabled, a prepared video requires explicit review and approval, followed by a separate operator-initiated posting action, and the private-test path is limited to SELF_ONLY.

4. Other services

Replit hosts the app and its PostgreSQL data. OpenAI is used to generate text for content planning and video scripts; topic and relevant prompt context may be sent to it. Creatomate is used to render video assets; render-plan content and media inputs are sent to it when rendering is requested. TikTok receives OAuth requests, creator-info queries, and, only if an authorized posting action is enabled and taken, the video-post payload and AI-generated and commercial-content disclosures. These providers handle data under their own terms and policies. This page does not claim that content sent to external providers can be deleted by ForgeOS.

5. Storage and security

ForgeOS stores TikTok OAuth access and refresh tokens encrypted server-side in its database. A developer-app secret entered through the private guide is also encrypted at rest. Tokens and secrets are not displayed on the public pages. The private guide requires a session and verifies mutation requests. ForgeOS does not currently implement an automatic deletion deadline for its stored TikTok and content records; they remain until removed by the workspace operator. External providers may retain their own records under their policies.

6. Revocation and deletion

You can revoke ForgeOS’s TikTok authorization in your TikTok account’s connected-app settings. Revocation stops future authorized TikTok access once it takes effect; it does not automatically erase records already stored in ForgeOS. There is currently no public self-service disconnect or deletion button. To request access to, correction of, or deletion of ForgeOS-stored credentials or content, contact the workspace operator who granted you access. The operator must handle local deletion separately from TikTok revocation; any provider-held data is governed by that provider’s policies. No specific deletion timeframe is promised here.

7. Changes

Changes to this policy will appear at this URL with a revised date. For questions about use of the app, see the Terms of Service. No public privacy-contact address has been configured for this app.