Privacy Policy
Last updated 29 August 2026. This policy explains what Goldikun Planner collects, why, and how long we keep it.
Controller: Goldikun, operating goldikun.cc. Contact: [email protected].
1. Data we process
- Account. Sign-in credentials or session cookies for the planner operator (username and password hash, session token).
- Queue and media. Files you upload, crop data, captions, first comments, schedule times, platform, and publish status.
- TikTok (Login Kit,
user.info.basic). After you authorize the app:open_id, display name, and avatar URL, plus OAuth access and refresh tokens. We use these only to show which TikTok account is connected and to call TikTok APIs you approved. - TikTok (Content Posting API,
video.publish). Media URLs, captions, and publish status for posts you queued, so we can create and check posts on the authorized account. - Other publishers. Buffer channel identifiers and API results when Instagram (or another Buffer-connected channel) is used. Temporary public object URLs on Bunny.net so a publisher can fetch the file.
- Technical logs. Standard web logs (IP address, user agent, time, path) on this legal site and on the application hosts, used for security and debugging.
We do not sell personal data. We do not use TikTok profile data to build advertising audiences or to contact TikTok users who did not connect an account.
2. Why we process it
We process this data to operate the scheduler you asked for: authenticate the operator, store the queue, connect third-party accounts, publish when items are due, and keep an audit trail of success or error. Legal bases (GDPR, where it applies) are performance of a contract with you and, for logs and security, legitimate interests.
3. Sharing
We share data only with processors needed to run the product:
- TikTok (TikTok Inc. / TikTok Technology Limited and affiliates) when you use Login Kit or Content Posting API;
- Buffer when you publish through a Buffer channel;
- Bunny.net when a file must be fetched from a public URL;
- infrastructure providers that host goldikun.cc (server, DNS, TLS).
Those parties process data under their own terms. We do not share your TikTok token with Buffer or Bunny.
4. Retention
Queue rows and media stay until you delete them or we remove them after an account closure request. TikTok tokens are kept while the account stays connected and are deleted when you disconnect or revoke the app in TikTok. Server logs are rotated on a short cycle (typically weeks). CDN copies of media are deleted after a successful or failed publish when the workflow supports cleanup.
5. Your rights
Depending on where you live, you may request access, correction, deletion, or a copy of your data, or object to certain processing. Email [email protected]. You can also revoke TikTok access in your TikTok app settings; we will stop calling TikTok for that account once tokens are revoked or deleted.
If you are in the EEA or UK, you may lodge a complaint with your supervisory authority. In Hungary that is the National Authority for Data Protection and Freedom of Information (NAIH).
6. Cookies
The planner uses a session cookie to keep an operator signed in. This public legal site does not set advertising cookies and does not use third-party analytics.
7. Children
The service is not directed at anyone under 18. We do not knowingly collect data from children.
8. Changes
We will update this page when our practices change. The “Last updated” date will change. If we expand TikTok scopes, we will describe the new data here before we use it.