Privacy Policy

Last updated: March 26, 2026 · Effective: March 26, 2026
This Privacy Policy complies with the General Data Protection Regulation (GDPR - EU 2016/679), the French Data Protection Act (Loi Informatique et Libertes), and TikTok Developer Privacy Requirements.

1. Data Controller Identity

AI Content System is the data controller for personal data processed through this Service. Operating name: AI Content System. Country of establishment: France. Contact email: privacy@aicontentsystem.org. Data Protection Officer: dpo@aicontentsystem.org.

2. Scope of This Policy

This Privacy Policy applies to all personal data collected, processed, and stored by AI Content System through our website at aicontentsystem.org, our integration with TikTok via the TikTok for Developers API, our automated content processing pipeline, and any communications you have with us.

3. Data We Collect

3.1 TikTok Account Data

When you connect your TikTok account, we collect the following data via the official TikTok API:

Data TypeAPI ScopePurposeRetention
TikTok Open ID (unique identifier)user.info.basicAccount identificationDuration of service use
Display nameuser.info.basicAccount displayDuration of service use
Avatar URLuser.info.basicAccount displayDuration of service use
Access tokenAll scopesAPI authenticationUntil revoked or expired
Published video IDsvideo.upload, video.publishContent tracking90 days

3.2 Content Source Data

We collect publicly available metadata from YouTube including video IDs, titles, license information, channel IDs, and engagement metrics for compliance verification and trend detection. No personally identifiable information of content creators is stored.

3.3 Technical and Analytics Data

We collect server logs including IP addresses retained for 30 days then anonymized, error logs for system debugging retained for 14 days, and performance metrics for published content.

4. Legal Basis for Processing Under GDPR

Processing ActivityLegal Basis (GDPR Article)
TikTok account authentication and publishingArt. 6(1)(b) - Performance of contract
Analytics and performance trackingArt. 6(1)(f) - Legitimate interests
Security loggingArt. 6(1)(f) - Legitimate interests
Responding to communicationsArt. 6(1)(f) - Legitimate interests

5. TikTok Data Handling - Special Requirements

In strict compliance with TikTok Developer Platform Policies:

6. Data Sharing and Third Parties

RecipientData SharedPurposeSafeguards
TikTok via APIVideo files, captions, hashtagsContent publishingTikTok Developer Agreement
Anthropic Claude APIVideo transcripts with no PIIContent generationAnthropic Privacy Policy
Google YouTube APISearch queries, video IDsContent discoveryGoogle Privacy Policy
WordPress.comGenerated blog contentBlog publicationAutomattic Privacy Policy
GitHub PagesStatic website filesWebsite hostingGitHub Privacy Policy

We do not sell personal data. We do not share personal data with data brokers or advertising networks under any circumstances.

7. International Data Transfers

Where we transfer data outside the European Economic Area, we ensure appropriate safeguards are in place including Standard Contractual Clauses approved by the European Commission and adequacy decisions where applicable.

8. Data Security Measures

We implement the following technical and organizational measures to protect personal data: all data transmitted over HTTPS and TLS 1.3, API keys and access tokens encrypted at rest with AES-256, access to personal data limited to authorized personnel only, regular security audits of our systems, and an incident response plan with 72-hour breach notification to the supervisory authority as required by GDPR Article 33.

9. Data Retention Schedule

Data CategoryRetention Period
TikTok account identifiersDuration of service use plus 30 days
TikTok access tokensUntil revoked, expired, or account deletion
Published content metadata90 days
Server access logs30 days then anonymized
Error logs14 days
Email communications2 years from last communication

10. Your Rights Under GDPR

To exercise any of these rights, contact privacy@aicontentsystem.org. We will respond within 30 days as required by GDPR.

11. Right to Lodge a Complaint

You have the right to lodge a complaint with the French supervisory authority: Commission Nationale de l'Informatique et des Libertes (CNIL), website www.cnil.fr, address 3 Place de Fontenoy TSA 80715 75334 PARIS CEDEX 07, telephone plus 33 1 53 73 22 22.

12. Cookies and Tracking

Our website uses only strictly necessary cookies required for basic functionality. We do not use advertising cookies, tracking cookies, or third-party analytics cookies without your explicit consent. We use Google Consent Management Platform to manage cookie consent for European visitors in compliance with the ePrivacy Directive and GDPR.

13. Children's Privacy

Our Service is not directed to children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will delete that data immediately and notify the appropriate authorities if required.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date and where required by law by obtaining renewed consent. The current version is always available at aicontentsystem.org/privacy.html.

15. Contact Us

Privacy requests: privacy@aicontentsystem.org. Data Protection Officer: dpo@aicontentsystem.org. Legal inquiries: legal@aicontentsystem.org. Response time: within 30 days for GDPR requests and within 48 hours for general inquiries.