1. Scope and connected services
AutoFlow processes account, workspace, creative-project, billing, and service-operation information to provide its creative tools. This Policy covers information we handle for those services.
We determine how information is used for our own account administration, billing, support, and security. When a workspace customer submits personal information about others and instructs us to process it for a project, that customer is responsible for its collection, instructions, and required notices and permissions; our role depends on the applicable law and service arrangement. If your information appears in a customer project, you may contact that customer or ask us to help route your request.
The TikTok-specific processing described below applies only when the feature is available to you and you choose to authorize it. Availability and the permissions requested will be shown before you connect an account.
2. Account and service information
The table summarizes the information involved in our services, its sources, and its purposes. The information actually processed depends on the features you use; connecting TikTok is optional and its specific processing is explained separately below.
We receive information from you, authorized workspace members, service operations, and platforms you choose to connect. When contacting support, avoid sending passwords, authentication tokens, or unnecessary sensitive information.
| Information category | Source and examples | Purpose |
|---|---|---|
| Account and workspace | You or your administrator: email, optional display name, membership and role; authentication creates a password hash, account status, and session records. | Register and authenticate users, manage access, and deliver verification and service messages. |
| Creative projects | You or workspace members: prompts, scripts, images, audio, video, project settings, review decisions, and generated results. | Execute the creative tasks you request, store projects, and deliver selected outputs. |
| Operational and security records | Service operations: sign-in times, session IP and browser information, task status, and administrative audit events. | Operate the service, troubleshoot, protect accounts, and prevent abuse. |
| Usage and billing | Task and wallet activity: usage, costs, reservations, and wallet transactions. | Calculate charges, settle tasks, reconcile balances, and address billing disputes. |
| Optional TikTok connection | TikTok authorization and submissions: account identity, scopes and credentials, available publishing settings, submission identifiers and status. | Maintain the authorized connection and execute and report the publishing actions you approve. |
| Support and rights requests | You or an authorized representative: contact details, request description, and necessary supporting information. | Respond to questions, verify request authority, and handle complaints and privacy rights. |
3. Creative materials and AI processing
We process the scripts, prompts, product and scene images, portraits, audio, voice samples, videos, and generated outputs that you submit or create, together with project settings and review decisions, to perform your requested tasks.
Images and audio may contain information about identifiable people. Voice cloning and digital-human features require permission to use the relevant likeness and voice. Do not submit these materials without the appropriate authority and any required consent.
Selected inputs may be sent to the AI, voice, media-processing, or compute providers configured for the requested feature. Provider processing is subject to the applicable service arrangements and data-protection requirements. A publishing authorization is not consent to train AI models on TikTok account data. Contact us for information about the providers involved in your task and their processing arrangements.
4. TikTok information and purposes
If you connect TikTok, the enabled permissions may provide an account identifier, display name and avatar, authorization scopes, access and refresh credentials and their expiry, creator publishing eligibility and available settings, and identifiers and status associated with a submission. We use these only to link the account, carry out the publishing action you request, maintain the authorized connection, and show its result.
When you approve a submission, the selected media and associated caption, visibility, interaction, and required disclosure settings are transmitted to TikTok. A temporary retrieval link may be used to let TikTok fetch the selected media from our storage; anyone with access to such a link during its validity may be able to retrieve the file.
Permissions depend on the feature: basic account identification, direct publication, and draft upload are separate capabilities. For the integration described here, we request only the permissions needed for your chosen feature and show them in the authorization flow. We do not need your TikTok password, contacts, private messages, or browsing history to publish your selected work.
We do not sell TikTok account data or use it for advertising profiles or AI-model training. Such data is not sent to generation providers merely because you connected a TikTok account.
5. Reasons for processing and your choices
We process information to perform the service you request, protect and administer it, satisfy applicable legal obligations, and, where required, act on your consent. Where a legal basis is required, the applicable basis depends on the purpose and local law.
Optional account connections and publishing actions require your choice. You may refuse a connection, decline permissions, or withdraw authorization; the related feature may then be unavailable. Withdrawal does not invalidate processing that was lawful before it.
6. Recipients and international processing
Authorized workspace members and administrators may access shared project information within their roles. Hosting, object storage, compute, AI and voice providers, email-delivery providers, and other necessary service providers may process the information needed for their tasks.
TikTok receives information for submissions you authorize and handles it under its own policies. We may disclose information where required by law, to address fraud or security incidents, or in connection with a business transfer with the notices and protections required by law.
The operator is based in China. Depending on the feature, information may be processed where we or the relevant service providers operate, which may be outside your country or region. Where cross-border processing is involved, we will provide the disclosures, obtain consent, and apply safeguards required by applicable law. You may contact us about the processing locations relevant to your use.
7. Cookies and local storage
The public website stores your chosen language in browser local storage under autoflow-website-language; it is not an advertising identifier. The website code does not include advertising trackers or analytics SDKs. Hosting and network services may still generate operational access logs.
The workspace uses an authentication cookie to maintain your session. You can clear site storage or block cookies in your browser, although doing so may reset preferences or prevent sign-in. Any future non-essential tracking will require a separate disclosure and consent where applicable.
8. Retention
We retain information for the purpose for which it was collected, including providing the requested service, resolving outstanding matters, and meeting applicable obligations. Different categories can require different periods. When that purpose ends, information is deleted or anonymized unless a lawful retention exception applies.
The table describes the criteria used to determine retention. The relevant period depends on the data category, service needs, outstanding matters, and applicable legal requirements. You may contact us about retention or deletion for your account. A technical limitation alone does not justify retaining personal information.
| Category | Retention criteria | Effect of ending use |
|---|---|---|
| Account and creative projects | Needed to provide your workspace and requested tasks, subject to a valid deletion request and applicable obligations. | Account closure and project deletion are assessed separately; save needed work before requesting closure. |
| TikTok credentials and connection data | Needed only for the authorized connection and related operations, subject to platform and legal requirements. | Revocation stops future authorized access; credentials and unnecessary connection data are removed when no longer needed. Existing TikTok posts are managed on TikTok. |
| Billing, audit, and security records | Only for applicable financial, legal, dispute-resolution, or security purposes, with retention tied to those purposes. | Closure may not erase records subject to a lawful retention exception; we explain the relevant purpose and limitation when handling your request. |
| Support and rights requests | Needed to handle the request and retain a necessary record of its outcome or applicable obligations. | Any continued retention must have a specific purpose; requesting deletion does not authorize indefinite storage. |
| Backups | Limited to necessary recovery and security purposes, subject to the applicable backup lifecycle and legal requirements. | Removal from active systems and expiry from backups may occur at different times. When handling a deletion request, we explain any backup-related limitation and the applicable deletion arrangement. |
9. Disconnecting, closure, and deletion requests
You can revoke a connected application's access in TikTok's account settings under the security and app-permissions controls. This stops future authorized access; it does not itself delete information already stored by AutoFlow.
To request access, correction, a copy or export where applicable, account closure, or deletion, email the privacy address below with the subject “Privacy request”. Include your account email, the action requested, and the relevant account, project, or connection if known. Do not include passwords or tokens. If you act for someone else, explain your authority; we may seek proportionate verification.
After verification, we explain the action taken or the reason a request cannot be fully met, including any lawful retention exception. If you disagree with the response, reply to the same contact for review; this does not limit your right to approach a competent authority.
Closing AutoFlow, removing a connection, and deleting a TikTok post are separate actions. Manage existing TikTok posts in TikTok. Workspace materials shared with others, lawful record-retention obligations, pending processing, and backup cycles may affect what can be removed and when.
10. Security
The application uses account authentication, workspace access controls, password hashing, and security-oriented logging controls. These measures reduce unauthorized access risks but cannot eliminate them.
Protect your login details and report suspected unauthorized access to the contact below. If an incident affects personal information, we will assess it and provide notifications required by applicable law. This Policy does not claim a security certification or guarantee absolute protection.
11. Your privacy rights
Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a copy of your information, restrict or object to certain processing, withdraw consent, and complain to a competent data-protection authority.
Contact us to exercise a right or ask about an unresolved request. Applicable legal deadlines govern our response. Requesting help does not require you to provide more personal information than is necessary to identify and address the request.
12. Children, updates, and contact
AutoFlow is intended for adults aged 18 or over and does not intentionally solicit personal information from children. Contact us if you believe a child has supplied information so we can assess and take appropriate action.
We will update this Policy when our processing changes, show the effective date, and provide any required notice or consent request. Use the contact details below for privacy questions, data requests, or concerns about unauthorized use.
Operator & contact
- Service operator
- 杭州未来际科技有限公司
- Country / region
- 中国 / China
- Service & privacy contact
- account@weilaiji.com
- Website
- www.weilaiji.com