1. Scope and core principles
- A user connects an account through the platform's OAuth or login flow. SellerOS does not ask for or store Google, YouTube, Facebook, Instagram, or TikTok passwords.
- Only the permissions required for account identification, user-confirmed publishing, result tracking, security, and support are requested and used.
- Platform user data is not sold, transferred to data brokers or competing sellers, used for unrelated advertising profiles, or used to train unrelated public AI models.
2. Google and YouTube
- openid, email, and profile identify the Google account that completed authorization. youtube.readonly identifies the authorized channel and reads the status or available metrics needed to show the publishing result.
- youtube.upload sends only the user-selected video and the title, description, tags, visibility, audience, and other settings the user reviews to the authorized YouTube channel.
- SellerOS does not use these permissions to read viewing history or unrelated private content. Retained YouTube Authorized Data is refreshed or revalidated at least every 30 days, and verified deletion requests are completed within 7 calendar days.
3. Meta and Instagram
- instagram_business_basic identifies the connected Instagram professional account and reads the account ID, username, account type, and basic profile information required for publishing.
- instagram_business_content_publish creates the user-confirmed Reel container, checks processing, publishes it to the authorized professional account, and reads the media ID, status, public link, and available insights.
- These permissions are not used to read direct messages, build follower profiles, or manage advertising. Account eligibility, permissions, content decisions, and API limits remain controlled by Meta and Instagram.
4. TikTok
- user.info.basic identifies the connected TikTok account using the platform identifiers, display name, and avatar returned by TikTok.
- video.publish is used only where TikTok and the authorized account permit Direct Post, after the user reviews the video, editable caption, target account, privacy, interaction, music, and commercial-content disclosure settings and explicitly confirms the post.
- SellerOS does not use these permissions to read direct messages or contacts, build user profiles, or bypass TikTok regional availability. TikTok OAuth and publishing are unavailable from mainland China IP addresses.
5. Storage, revocation, and deletion
- OAuth access and refresh tokens are encrypted at rest and excluded from ordinary pages, routine logs, AI prompts, and exports. SellerOS retains only the connection, publishing, status, security, and audit data needed for the service.
- A user can disconnect an account in SellerOS or revoke access in the platform's own settings. Revocation stops new API activity within that authorization scope; a task already completed remains part of the platform and audit history.
- Verified deletion requests remove or de-identify platform connections, incomplete publishing jobs, and related personal data, except for the minimum records that must be retained for security, legal, financial, or dispute purposes.
- Questions or verified requests may be sent to support@c2345.com. Do not send passwords, access tokens, refresh tokens, or other secrets.